pump-analyzer-solana

Warn

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instructions direct users to clone a repository from github.com/happyboy4ty25/pump-analyzer. This account is not verified and does not match the author "Aradotso" or the associated "ara.so" domain, representing a potential supply chain risk from an untrusted source.\n- [COMMAND_EXECUTION]: The JavaScript code in js/main.js utilizes innerHTML to render token data and incorporates an onclick event handler that directly interpolates the token.mint variable. This pattern is susceptible to DOM-based Cross-Site Scripting (XSS) if the third-party WebSocket provides malicious payloads in the mint field.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 28, 2026, 12:40 AM