security-nextjs

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/scan.sh

The script is a defensive static analysis tool for Next.js projects. It does not engage in data exfiltration or obfuscation; its purpose is to surface configuration and code patterns that could lead to security issues. While the tool itself appears safe, the detected risks depend on repository content; the most significant concerns are exposed secrets, unauthenticated server/actions, potentially insufficient middleware coverage, and missing security headers.

Confidence: 85%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:57 PM
Package URL
pkg:socket/skills-sh/igorwarzocha%2Fopencode-workflows%2Fsecurity-nextjs%2F@d96f188c55edd4de0854d6aedabff6e9fcec0609