django-celery-expert

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/production-deployment.md

No malicious behavior is evident. The material is legitimate Celery deployment documentation. Security concerns include shell command interpolation from EnvironmentFile values, publicly exposed Redis in one Compose example, unauthenticated Flower exposure, mutable image tags, unverified dependency installation, and broad operational shutdown commands. These require hardening before production use but do not indicate malware.

Confidence: 98%Severity: 58%
AnomalyLOW
references/monitoring-observability.md

The code is legitimate Celery monitoring and alerting guidance and shows no clear malware or intentional sabotage. Its principal risks are insecure example deployment settings, possible exposure of broker and Flower interfaces, plaintext credential examples, and leakage of sensitive task data through logs and external alert payloads. Use environment or secret-manager configuration, TLS and authentication, network restrictions, payload redaction, and correct the heartbeat age calculation.

Confidence: 97%Severity: 63%
Audit Metadata
Analyzed At
Sep 14, 2026, 03:27 PM
Package URL
pkg:socket/skills-sh/vintasoftware%2Fdjango-ai-plugins%2Fdjango-celery-expert%2F@5a718f03c80bd74c6e8b1c014c2608bb1b29d795ad7917b43aa38de094c4ae62
Security Audit — socket — django-celery-expert