heroui-react

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/get_theme.mjs

The code is a straightforward remote-theme fetcher with a robust fallback to a local theme. No malware, backdoors, or data exfiltration beyond normal logging of API responses. The main risk is exposure of API data through logs; implement log sanitization or redaction in production and consider signing/validating API payloads if needed. Overall security risk is low to moderate depending on log handling in production.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 14, 2026, 12:58 PM
Package URL
pkg:socket/skills-sh/heroui-inc%2Fheroui%2Fheroui-react%2F@1986f65c42955f562c64802fb650e1046695f761