browser
Fail
Audited by Socket on Feb 14, 2026
1 alert found:
Obfuscated FileObfuscated Fileeval.js
HIGHObfuscated FileHIGH
eval.js
This script intentionally exposes a powerful remote-eval capability into the first open browser page. The file itself shows no signs of obfuscation or embedded malicious payloads, but its functionality is inherently dangerous: untrusted input results in code execution within the page context, allowing data access and exfiltration or actions as the page. Treat this as a dangerous tool to be used only in trusted, controlled environments; otherwise restrict access or replace with safer, narrowly-scoped interfaces.
Confidence: 98%
Audit Metadata