shadcn-flutter

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
guides/web_preloader.md

The excerpt itself contains no direct malicious code, but it recommends integrating a preloader by executing a remotely hosted JavaScript file from a CDN using an unpinned @latest reference and without integrity verification. This creates a significant supply-chain/remote-code-execution attack surface at page load. Risk level depends entirely on the actual contents of the referenced standard.js, which is not included here; review/pin to a specific immutable version and add integrity verification where possible.

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
Apr 18, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/sunarya-thito%2Fshadcn_flutter%2Fshadcn-flutter%2F@704d2c414ce48e55a0c1b8bc32dcf218975b8018