Is "@salesforce/pwa-kit-react-sdk" on n8n Safe to Install?

mobify · n8n · v3.17.0

A library that supports the isomorphic React rendering pipeline for Commerce Cloud Managed Runtime apps

Risk Assessment

Analyzed
43.58
out of 100
MEDIUM

20 security findings detected across all analyzers

Severity Breakdown

0
Critical
0
High
1
Medium
19
Low
0
Info

Finding Categories

1
Network

About This Extension

A library that supports the isomorphic React rendering pipeline for Commerce Cloud Managed Runtime apps

Detailed Findings

20 total

Security Analysis Summary

Security Analysis Overview

@salesforce/pwa-kit-react-sdk is a n8n extension published by mobify. Version 3.17.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 43.58/100 (MEDIUM risk) based on 20 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 1 finding(s)
  • Low: 19 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

@salesforce/pwa-kit-react-sdk is published by mobify on the n8n marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions