The code assigns a static secret/token directly in source files rather than using environment variables or a secure secret manager.
Line 3: JWT_SECR***************************************hub"
Anyone with access to the source repository or compiled bundle can extract this secret and gain unauthorized access to backend services or APIs.
Extract the secret to an environment variable (`process.env.API_KEY` or `os.getenv('API_KEY')`) and ensure secrets are listed in `.gitignore`.
// Secure alternative using environment variables:
const apiKey = process.env.API_KEY || os.environ.get('API_KEY');
The code assigns a static secret/token directly in source files rather than using environment variables or a secure secret manager.
Line 18: GOOGLE_MAPS_API_*****************************************8Ws"
Anyone with access to the source repository or compiled bundle can extract this secret and gain unauthorized access to backend services or APIs.
Extract the secret to an environment variable (`process.env.API_KEY` or `os.getenv('API_KEY')`) and ensure secrets are listed in `.gitignore`.
// Secure alternative using environment variables:
const apiKey = process.env.API_KEY || os.environ.get('API_KEY');
The code assigns a static secret/token directly in source files rather than using environment variables or a secure secret manager.
Line 6: const consumerSecr**********************************************9ed';
Anyone with access to the source repository or compiled bundle can extract this secret and gain unauthorized access to backend services or APIs.
Extract the secret to an environment variable (`process.env.API_KEY` or `os.getenv('API_KEY')`) and ensure secrets are listed in `.gitignore`.
// Secure alternative using environment variables:
const apiKey = process.env.API_KEY || os.environ.get('API_KEY');
Untrusted input is directly combined into a raw SQL query string without parameterization.
Line 787: this.logger.log(`Synced stock update for product ${product.id} to WooCommerce (New: ${newStock})`);
An attacker can craft malicious inputs containing SQL syntax to bypass authentication, dump databases, or modify records.
Use parameterized queries / prepared statements (e.g., `db.query('SELECT * FROM users WHERE id = $1', [userId])` or ORM safe methods).
// Parameterized query example:
const result = await db.query('SELECT * FROM users WHERE id = $1', [userId]);
Untrusted input is directly combined into a raw SQL query string without parameterization.
Line 702: console.warn(`[WooCommerce Webhook] Failed to delete webhook ${w.id}:`, deleteErr.message);
An attacker can craft malicious inputs containing SQL syntax to bypass authentication, dump databases, or modify records.
Use parameterized queries / prepared statements (e.g., `db.query('SELECT * FROM users WHERE id = $1', [userId])` or ORM safe methods).
// Parameterized query example:
const result = await db.query('SELECT * FROM users WHERE id = $1', [userId]);
The code ignores SSL certificate validation errors during HTTPS communication.
Line 54: rejectUnauthorized: false,
Disabling certificate checks allows Man-In-The-Middle (MITM) attackers on the network to intercept, decrypt, and alter traffic.
Enable certificate verification (`rejectUnauthorized: true` or `verify=True`) and install trusted CA certificates.
The code injects raw HTML strings directly into the DOM.
Line 146: btn.innerHTML = 'sync Searching...';
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 163: btn.innerHTML = 'check_circle Results Sent!';
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 350: btn.innerHTML = 'sync Adding...';
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 369: btn.innerHTML = 'check_circle Added to Cart!';
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 332: btn.innerHTML = 'sync Adding...';
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 350: btn.innerHTML = 'check_circle Added to Basket';
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 357: btn.innerHTML = originalContent;
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code injects raw HTML strings directly into the DOM.
Line 363: btn.innerHTML = originalContent;
If user-provided data reaches this sink, malicious JavaScript can execute in the victim's browser, stealing cookies, session tokens, or performing unauthorized actions.
Use safe DOM properties such as `textContent` or `innerText`, or sanitize HTML using a trusted library like `DOMPurify` before rendering.
// DOMPurify sanitization:
import DOMPurify from 'dompurify';
element.innerHTML = DOMPurify.sanitize(userControlledString);
The code assigns a static secret/token directly in source files rather than using environment variables or a secure secret manager.
Line 2: NEXT_PUBLIC_GOOGLE_MAPS_API_*****************************************8Ws"
Anyone with access to the source repository or compiled bundle can extract this secret and gain unauthorized access to backend services or APIs.
Extract the secret to an environment variable (`process.env.API_KEY` or `os.getenv('API_KEY')`) and ensure secrets are listed in `.gitignore`.
// Secure alternative using environment variables:
const apiKey = process.env.API_KEY || os.environ.get('API_KEY');