budge

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
references/INSTALL.md

This code is not overtly malicious by itself; it is integration logic that loads and executes an opaque third-party IIFE from https://www.budge.design/budge.iife.js across multiple frameworks and activates it based on DOM-inserted JSON configuration (data-budge). The dominant concern is supply-chain risk: remote script execution without SRI/version pinning/sandboxing, combined with MutationObserver-based auto-activation, gives the third party meaningful opportunity to track or manipulate the page if the CDN asset is compromised.

Confidence: 62%Severity: 68%
Audit Metadata
Analyzed At
May 6, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/millionco%2Fskills%2Fbudge%2F@b263f5eabfed368229a38d0cbd1b97eb3422851e