gdpr-data-handling
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/details.md
LOWAnomalyLOW
references/details.md
No evidence of intentional malware or supply-chain sabotage is present. The code implements legitimate GDPR-related functionality, but the DSAR examples have significant security design gaps because authentication, authorization, and verification enforcement are not shown before reading or deleting personal data. Error-detail exposure, broad retention mutations, and unprotected personal metadata also require review before production use.
Confidence: 94%Severity: 62%
Audit Metadata