sell
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalytemplates/unified.html
LOWAnomalyLOW
templates/unified.html
No clear evidence of intentional malware/backdoor behavior in this fragment. However, there are significant security risks: (1) potential DOM XSS via dangerouslySetInnerHTML using APP_TAGLINE, and (2) increased token leakage risk from placing an OIDC bearer token in the WebSocket URL query string. Additional moderate risk comes from reliance on runtime configuration/globals and broad window-level state exposure, but those are not direct malware indicators.
Confidence: 62%Severity: 62%
Audit Metadata