pump-analyzer-solana
Warn
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation instructions direct users to clone a repository from
github.com/happyboy4ty25/pump-analyzer. This account is not verified and does not match the author "Aradotso" or the associated "ara.so" domain, representing a potential supply chain risk from an untrusted source.\n- [COMMAND_EXECUTION]: The JavaScript code injs/main.jsutilizesinnerHTMLto render token data and incorporates anonclickevent handler that directly interpolates thetoken.mintvariable. This pattern is susceptible to DOM-based Cross-Site Scripting (XSS) if the third-party WebSocket provides malicious payloads in themintfield.
Audit Metadata