wix-base44-headless

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Security
SecurityMEDIUM
templates/storefront/TEMPLATE.md

The fragment is an orchestration wrapper that dynamically reads and executes an internal seed module from a fixed absolute path using new Function, then invokes setupStore with an authorization token to perform Wix storefront seeding. While the wrapper itself shows no explicit data theft/exfiltration, the dynamic code execution mechanism substantially increases supply-chain risk: any tampering of the seed-store.js artifact would be executed with the current Node process’s privileges and could perform unauthorized actions against Wix or access local/network resources. Treat as high review priority and verify integrity/contents of the loaded seed-store.js and its outbound behaviors.

Confidence: 62%Severity: 74%
Audit Metadata
Analyzed At
Aug 8, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/wix%2Fskills%2Fwix-base44-headless%2F@c78cbf128979be8f5fe2104ff31d3caf3acd297115ea95efdfbc78372d2b4c7b
Security Audit — socket — wix-base44-headless