🚀 Big News: Socket Acquires Coana to Bring Reachability Analysis to Every Appsec Team.Learn more

ligolang

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

ligolang

A high-level language which compiles to Michelson

0.69.0-macos-intel.d63c34412535fadfd98859dd8dad630fe08e90c2
latest
78

Supply Chain Security

100

Vulnerability

71

Quality

80

Maintenance

100

License

Shell access

Supply chain risk

This module accesses the system shell. Accessing the system shell increases the risk of executing arbitrary code.

Found 1 instance in 1 package

Uses eval

Supply chain risk

Package uses dynamic code execution (e.g., eval()), which is a dangerous practice. This can prevent the code from running in certain environments and increases the risk that the code may contain exploits or malicious behavior.

Found 1 instance in 1 package

Install scripts

Supply chain risk

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Found 1 instance in 1 package

Version published
Weekly downloads
4.8K
-4.37%
Maintainers
4
Weekly downloads
 
Created
The README file is missing

FAQs

Package last updated on 06 Jul 2023

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts