upstash-redis-js

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
patterns/session-management.md

The fragment is a readable Redis session-management example and does not show malware, data theft, persistence, or suspicious external communication. It contains a critical authentication risk if the included verifyCredentials placeholder is used as real logic, plus replay risk for remember-me tokens, insufficient input validation for Redis key components, stale multi-device indexes, and non-atomic updates. The authentication helper must be replaced before production use.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:26 PM
Package URL
pkg:socket/skills-sh/upstash%2Fskills%2Fupstash-redis-js%2F@2a1e047e77f8df33c86d9a2770e1ec9f2c86afb5661215d6be3f57bfe6a65867
Security Audit — socket — upstash-redis-js