What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-v6wh-96g9-6wx3 applies
Minor caution · low confidence
A security warning was found for a tool used to build this plugin. Since the tool is only used during development and is not included in the final plugin file that users load, it is unlikely to affect users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the lockfile. The project ships as a single bundled JS file loaded into RisuAI; build-time dev dependencies such as Vite, SvelteKit, PostCSS, or Terser do not ship in the final plugin bundle. Their vulnerabilities affect the development server or build process on the developer's machine, not the runtime environment of end users. Without the specific package name (removed by the scanner), the exact version and runtime reachability cannot be confirmed, but the project structure strongly suggests this is a build-tool advisory with no runtime path to user harm.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6wh-96g9-6wx3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-phwv-c562-gvmh applies
Minor caution · low confidence
A security warning was found for a development tool used to create this plugin. The tool is not part of the final plugin that users install, so the warning is unlikely to matter for end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-phwv-c562-gvmh to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency. The plugin is compiled to a static JS bundle; build-framework and dev-tool vulnerabilities do not propagate into the shipped artifact. The scanner removed package details, preventing exact version confirmation, but the dependency tree shown is dominated by build-time packages whose vulnerable code paths are not present at runtime.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-phwv-c562-gvmh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-vw5p-8cq8-m7mv applies
Minor caution · low confidence
Although this warning is rated high severity, it most likely affects a development server tool that is not included in the final plugin file. Users who load the built plugin are not exposed to this issue.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-vw5p-8cq8-m7mv to a dependency declared by this repository.
Contextual assessment: This high-severity advisory most likely corresponds to a Vite or SvelteKit dev-server vulnerability. These frameworks are listed as devDependencies and are used only during the build process. The final artifact is a static JS bundle with no dev server component. The vulnerable code path requires a running development server, which is not present in the shipped plugin. Runtime reachability in the user's environment is not established.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build tool to a patched version to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-vw5p-8cq8-m7mv
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-xxjr-mmjv-4gpg applies
Minor caution · low confidence
A security warning was found for a dependency. Based on how this plugin is built and packaged, the affected code is unlikely to be part of what users actually load.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xxjr-mmjv-4gpg to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the lockfile. The project's production dependencies are flatpickr, lodash, lucide-svelte, and svelte, all at recent fixed or current versions. The remaining dependencies are build-time tools. Without the specific package name from the scanner, exact runtime reachability cannot be confirmed, but the project structure indicates the vulnerable code is unlikely to ship in the final bundle.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xxjr-mmjv-4gpg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-g2pg-6438-jwpf applies
Minor caution · low confidence
This high-severity warning most likely affects a build tool that only runs during development. The final plugin file that users install does not include this tool, so users are not exposed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-g2pg-6438-jwpf to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely corresponds to a Vite dev-server or build-tool vulnerability. Vite is declared as a devDependency and is used only to compile the Svelte project into a static JS bundle. The vulnerable code paths involve the development server or file-serving behavior that does not exist in the shipped plugin. No runtime reachability to end users is established.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build tool to a patched version to keep the development environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-g2pg-6438-jwpf
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-hgv7-v322-mmgr applies
Minor caution · low confidence
A security warning was found for a dependency used during development. The affected code is unlikely to be part of the final plugin that users load.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hgv7-v322-mmgr to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency. The plugin is built into a single static JS file and loaded into RisuAI. Build-time and dev-tool vulnerabilities do not ship in the final artifact. The scanner removed package details, preventing exact identification, but the dependency tree and project structure indicate no runtime path to user harm.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hgv7-v322-mmgr
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f23m-r3pf-42rh applies
Minor caution · low confidence
A security warning was found for a dependency. The plugin handles usage data from the user's own API calls, limiting the potential for exploitation. The issue is unlikely to cause harm to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f23m-r3pf-42rh to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency. If it corresponds to a production dependency such as svelte, the plugin's attack surface is limited: it displays usage statistics, model names, and provider names from the user's own API calls rather than arbitrary untrusted content. If it corresponds to a dev dependency, the vulnerable code does not ship in the final bundle. Either way, concrete user harm is not established from the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f23m-r3pf-42rh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rcqx-6q8c-2c42 applies
Minor caution · low confidence
A security warning was found for a dependency. Based on how this plugin is built, the affected code is unlikely to be part of what users actually load.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rcqx-6q8c-2c42 to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency. The project compiles to a static JS bundle for RisuAI. Dev-tool and build-framework vulnerabilities do not propagate into the shipped artifact. Without the specific package name from the scanner, exact runtime reachability cannot be confirmed, but the project structure indicates the vulnerable code is unlikely to reach end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rcqx-6q8c-2c42
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4w7w-66w2-5vf9 applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a dependency declared in this lockfile. The project's production dependencies are flatpickr, lodash, lucide-svelte, and svelte, all at generally patched versions. The remaining dependencies are dev-only build tooling (vite, esbuild, postcss, tailwindcss, terser, etc.). This project builds to a single static JS artifact loaded in the RisuAI browser environment; it does not run a Node server or dev server in production. Most medium-severity advisories in this dependency set relate to build-time tooling whose vulnerable code paths (e.g., dev-server request handling) are not present in the shipped bundle. Without exact package-to-advisory mapping, runtime reachability in the final artifact cannot be confirmed, but the project structure strongly limits end-user exposure.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4w7w-66w2-5vf9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-m56q-vw4c-c2cp applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-m56q-vw4c-c2cp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a dependency in this lockfile. The project builds to a static browser-loaded JS file; dev dependencies do not ship in the final artifact. The advisory most likely targets build-time tooling whose vulnerable code paths are not reachable in the shipped bundle. Runtime reachability for end users is not demonstrated by the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-m56q-vw4c-c2cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue rated high. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in this lockfile. The project's high-severity advisories in this dependency set most commonly correspond to vite or esbuild, both dev-only build tools. Their known vulnerabilities typically involve the development server (DOM clobbering, local file exposure, DNS rebinding, template XSS). This project produces a static JS bundle loaded in the RisuAI browser environment and does not operate a dev server in production, so the vulnerable code paths have no runtime reachability in the shipped artifact. Without exact package-to-advisory mapping, a production-dependency match cannot be fully excluded, but the project structure and dependency versions make it unlikely.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue rated high. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in this lockfile. The project's high-severity advisories in this dependency set most commonly correspond to vite or esbuild, both dev-only build tools whose vulnerabilities involve the development server. This project produces a static JS bundle and does not run a dev server in production, so the vulnerable code paths have no runtime reachability in the shipped artifact. Exact package-to-advisory mapping is not supplied, but the project structure and dependency versions make a production-dependency match unlikely.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-j62c-4x62-9r35 applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue rated high. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-j62c-4x62-9r35 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in this lockfile. The project's high-severity advisories in this dependency set most commonly correspond to vite or esbuild, both dev-only build tools whose vulnerabilities involve the development server. This project produces a static JS bundle and does not run a dev server in production, so the vulnerable code paths have no runtime reachability in the shipped artifact. Exact package-to-advisory mapping is not supplied, but the project structure and dependency versions make a production-dependency match unlikely.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-j62c-4x62-9r35
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-29g2-3rmr-qm68 applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-29g2-3rmr-qm68 to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a medium-severity advisory against a dependency in this lockfile. The project builds to a static browser-loaded JS file; dev dependencies do not ship in the final artifact. The advisory most likely targets build-time tooling whose vulnerable code paths are not reachable in the shipped bundle. Runtime reachability for end users is not demonstrated by the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-29g2-3rmr-qm68
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-28wg-ghj8-5hjv applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue rated high. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in this lockfile. The project's high-severity advisories in this dependency set most commonly correspond to vite or esbuild, both dev-only build tools whose vulnerabilities involve the development server. This project produces a static JS bundle and does not run a dev server in production, so the vulnerable code paths have no runtime reachability in the shipped artifact. Exact package-to-advisory mapping is not supplied, but the project structure and dependency versions make a production-dependency match unlikely.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-28wg-ghj8-5hjv
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A build tool used to create this plugin has a known security issue rated high. Because the tool only runs during development and the final plugin is a single file loaded in the browser, the issue is unlikely to affect people who use the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: OSV-Scanner matched a high-severity advisory against a dependency in this lockfile. The project's high-severity advisories in this dependency set most commonly correspond to vite or esbuild, both dev-only build tools whose vulnerabilities involve the development server. This project produces a static JS bundle and does not run a dev server in production, so the vulnerable code paths have no runtime reachability in the shipped artifact. Exact package-to-advisory mapping is not supplied, but the project structure and dependency versions make a production-dependency match unlikely.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dev dependency to a patched version when convenient; this does not affect the shipped artifact.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-6g55-p6wh-862q applies
Minor caution · medium confidence
A security issue was found in a build tool used during development. This tool is not included in the final plugin that users install, so it does not affect people who use the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a Vite dev-server vulnerability. Vite is declared as a dev dependency (^5.0.0) and is used only during the build process. The project builds to a static JS artifact loaded as a RisuAI plugin; Vite is not shipped to end users. The vulnerable dev-server code has no runtime reachability in the deployed plugin. The advisory only affects developers running the Vite dev server locally.
Impact: low · Exploitability: unlikely
Developer action: Update Vite to the latest patched 5.x release to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2crg-3p73-43xp applies
Minor caution · medium confidence
A security issue was found in a build tool's development server. Since the tool is only used during development and is not part of the final plugin, users of the extension are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2crg-3p73-43xp to a dependency declared by this repository.
Contextual assessment: This advisory corresponds to a Vite dev-server vulnerability (server.fs.deny bypass). Vite is a dev dependency used only for building. The shipped artifact is a static JS file that does not include Vite. The vulnerable code has no runtime reachability in the deployed plugin.
Impact: low · Exploitability: unlikely
Developer action: Update Vite to the latest patched 5.x release to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2crg-3p73-43xp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-33hq-fvwr-56pm applies
Minor caution · low confidence
A minor security issue was found in a development or build tool. The final plugin that users install does not include this tool, so the issue is unlikely to affect users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-33hq-fvwr-56pm to a dependency declared by this repository.
Contextual assessment: This low-severity advisory likely corresponds to a Vite or related build-tool dependency. The project builds to a static JS artifact; build-tool dependencies are not shipped to end users. Without the exact package mapping, runtime reachability in the deployed plugin cannot be confirmed, but the project structure indicates the vulnerable code is build-time only.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-33hq-fvwr-56pm
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-67mh-4wv8-2f99 applies
Minor caution · low confidence
A security issue was found in a build tool. Since the tool is only used during development and is not part of the final plugin, users of the extension are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory likely corresponds to a Vite or related build-tool dependency. The project builds to a static JS artifact loaded as a RisuAI plugin; build-tool dependencies are not included in the shipped output. The vulnerable code has no runtime reachability for end users of the plugin.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-67mh-4wv8-2f99
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r5fr-rjxr-66jc applies
Minor caution · low confidence
A security issue was found in a build tool that helps create the plugin. This tool is not included in the final plugin that users install, so it does not affect users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r5fr-rjxr-66jc to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely corresponds to esbuild or a related build-tool dependency. The lockfile shows esbuild 0.21.5 as a dev-only, optional dependency used by Vite during building. The shipped plugin is a static JS file that does not include esbuild. The vulnerable code has no runtime reachability in the deployed artifact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r5fr-rjxr-66jc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · low confidence
A security issue was found in a build tool. The tool is not part of the final plugin that users install, so it does not affect users of the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: This high-severity advisory likely corresponds to esbuild or a related build-tool dependency. esbuild is declared as a dev-only, optional dependency in the lockfile and is used solely during the build process. The shipped plugin is a static JS artifact that does not include esbuild. The vulnerable code has no runtime reachability for end users.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build dependency to a patched version to protect the development environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f7gr-6p89-r883 applies
Minor caution · low confidence
A security issue was found in a framework used by the plugin. If it is a build-time framework, it is not included in the final plugin. If it is a runtime framework, the plugin only displays the user's own data, making it hard for an attacker to exploit the issue.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f7gr-6p89-r883 to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory may correspond to a SvelteKit or Svelte dependency. If it is SvelteKit, it is a dev dependency not shipped in the built artifact. If it is Svelte (a production dependency), Svelte compiles templates to vanilla JavaScript at build time, and the specific vulnerable runtime patterns may not be present in the compiled output. The plugin renders the user's own API usage data (model names, costs, tokens) rather than untrusted external input, limiting attacker control over rendered content.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f7gr-6p89-r883
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mwv9-gp5h-frr4 applies
Minor caution · low confidence
A minor security issue was found in a framework used by the plugin. The plugin only displays the user's own usage data, making it difficult for anyone to exploit this issue against the user.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mwv9-gp5h-frr4 to a dependency declared by this repository.
Contextual assessment: This low-severity advisory may correspond to a Svelte or related framework dependency. If it is a Svelte runtime vulnerability, Svelte compiles to vanilla JavaScript at build time and the vulnerable patterns may not be present in the compiled output. The plugin processes the user's own API usage data rather than untrusted external input, limiting the attack surface. If it is a dev-only dependency, it is not shipped at all.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mwv9-gp5h-frr4
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · low confidence
A security notice was found for one of the tools or libraries used by this plugin. Since the plugin runs inside a browser and mainly works with its own usage data, the practical risk is low, but updating the affected dependency is still good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in this Svelte/Vite browser extension project. The project bundles production dependencies (flatpickr, lodash, svelte, lucide-svelte) into a single JS file via Vite; devDependencies are build-time only and do not ship. Without the specific package identity it is not possible to confirm runtime reachability, but the extension runs in a browser context processing locally generated usage data, limiting attacker-controlled input paths to the vulnerable code.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mw96-cpmx-2vgc applies
Minor caution · low confidence
A serious security notice was found for a dependency, but it most likely affects a build tool that is not included in the final plugin file. The risk to end users is low, but the dependency should still be updated.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched. This project's dependency tree includes numerous build-time devDependencies (vite, terser, postcss, tailwindcss, esbuild variants) that are not included in the shipped bundle. High-severity advisories in the Node.js build-tool ecosystem frequently target these dev-only packages. The production bundle is a single client-side JS file with no server-side processing of untrusted input, so even if the advisory targets a production dependency, attacker-controlled input reaching the vulnerable code path is unlikely in this usage-tracking context.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package. If it is a devDependency, update it to protect the build environment. If it is a production dependency, verify whether the vulnerable code path is reachable in the bundled output and update accordingly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mw96-cpmx-2vgc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-wqjv-9729-c5q2 applies
Minor caution · low confidence
A security notice was found for one of the libraries used by this plugin. The practical risk is low because the plugin runs in a browser and works with its own data, but updating the library is recommended.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-wqjv-9729-c5q2 to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in this browser extension project. The shipped artifact is a bundled client-side JS file; build-time dependencies do not ship. The extension processes locally generated API usage statistics and does not expose server-side endpoints that would accept untrusted input, limiting the practical exploitability of most dependency vulnerabilities.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-wqjv-9729-c5q2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · low confidence
A security notice was found for a library used by this plugin. The risk is low, but updating the library is good practice.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency. The project ships a single bundled JS file for use inside RisuAI; build-time dependencies are excluded from the bundle. The extension handles locally generated usage data in a browser context, so attacker-controlled input reaching vulnerable code paths is unlikely.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-866w-xmhq-wj7x applies
Minor caution · low confidence
A security notice was found for a dependency. The risk to users is low, but the dependency should be updated.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-866w-xmhq-wj7x to a dependency declared by this repository.
Contextual assessment: A medium-severity advisory was matched against a dependency in this browser extension. The shipped artifact is a client-side bundle; devDependencies do not ship. The extension processes local usage statistics without exposing server-side endpoints for untrusted input, limiting practical exploitability.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-866w-xmhq-wj7x
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-5j98-mcp5-4vw2 applies
Minor caution · low confidence
A serious security notice was found for a dependency, but it most likely affects a build tool that does not end up in the final plugin. The risk to end users is low, but the dependency should be updated to keep the build environment secure.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5j98-mcp5-4vw2 to a dependency declared by this repository.
Contextual assessment: A high-severity advisory was matched. This project includes many build-time devDependencies (vite, esbuild, terser, postcss, tailwindcss) that are not included in the shipped bundle. High-severity advisories in this ecosystem frequently target these dev-only packages. The production output is a single client-side JS file with no server-side attack surface. Even if the advisory targets a production dependency, the extension processes locally generated usage data, making attacker-controlled input reaching the vulnerable code path unlikely.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package. If it is a devDependency, update it to protect the build environment. If it is a production dependency, verify whether the vulnerable code path is reachable in the bundled output and update accordingly.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5j98-mcp5-4vw2
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · medium confidence
A security scanner found a known issue in one of the project's dependencies. Since this plugin is built into a single file and most of its dependencies are only used during the build process, the issue likely does not affect the final plugin that users load into RisuAI.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: A medium-severity OSV advisory matched a dependency in this lockfile. The project is a browser plugin for RisuAI that ships a single bundled JS file built with Vite. The lockfile is dominated by dev-only build tooling (esbuild, rollup, postcss, terser, tailwindcss, Vite plugins). Runtime dependencies are limited to flatpickr, lodash, lucide-svelte, and svelte. Without the specific package identity, the most likely scenario is a build-time dependency advisory that does not ship in the final plugin artifact. Even if a runtime dependency is affected, the plugin operates within RisuAI's browser context with limited attacker-controlled input reaching vulnerable code paths.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version if one is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · medium confidence
A security scanner found a known issue in one of the project's dependencies. Because the plugin is compiled into a single file and most dependencies are build tools, the issue probably does not reach users of the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: A medium-severity OSV advisory matched a dependency in this lockfile. The shipped artifact is a bundled browser plugin; the majority of lockfile entries are dev-only build tools that do not appear in the final output. The advisory package identity is not provided, but the project's runtime surface is small (flatpickr, lodash, lucide-svelte, svelte). Build-tool vulnerabilities do not affect end users of the shipped plugin, and runtime exploitability in this browser-plugin context is limited.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version if one is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
A security scanner flagged a high-severity issue in a dependency. However, because this plugin is built into a single file and most dependencies are only used during building, the issue likely does not affect the plugin that users actually run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: A high-severity OSV advisory matched a dependency in this lockfile. Despite the high scanner severity, the project ships only a bundled JS file for use inside RisuAI's browser environment. Most lockfile packages are dev-only build tooling. If the advisory targets a build tool, it has no runtime impact on the shipped plugin. If it targets a runtime dependency, the browser-plugin context and limited attacker-controlled input reduce practical exploitability. The specific package is not identified in the evidence.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version. Prioritize updates if the affected package is a runtime dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
A security scanner flagged a high-severity issue in a dependency. Since the plugin is compiled into one file and most dependencies are build tools, the issue probably does not reach end users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: A high-severity OSV advisory matched a dependency in this lockfile. The project is a browser plugin whose final output is a single bundled JS file. The lockfile contains predominantly dev-only build tools. Without the specific package identity, the advisory most likely targets a build-time dependency with no presence in the shipped artifact. Runtime dependencies are limited and operate in a constrained browser-plugin context.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version. Prioritize updates if the affected package is a runtime dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-cfw5-2vxh-hr84 applies
Minor caution · medium confidence
A security scanner found a known issue in a dependency. Because the plugin is built into a single file and most dependencies are build tools, the issue likely does not affect users of the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-cfw5-2vxh-hr84 to a dependency declared by this repository.
Contextual assessment: A medium-severity OSV advisory matched a dependency in this lockfile. The shipped plugin is a bundled browser JS file; most lockfile entries are dev-only build tooling that does not ship. The runtime dependency set is small. Without the specific package identity, the advisory most likely affects a build-time dependency with no runtime reachability in the final artifact.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version if one is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-cfw5-2vxh-hr84
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · medium confidence
A security scanner flagged a high-severity issue in a dependency. Since the plugin is compiled into one file and most dependencies are only used during building, the issue probably does not affect the plugin users run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: A high-severity OSV advisory matched a dependency in this lockfile. The project ships a single bundled JS file as a RisuAI browser plugin. The lockfile is dominated by dev-only build tools. If the advisory targets a build tool, there is no runtime impact. If it targets a runtime dependency, the browser-plugin context limits attacker-controlled input reaching vulnerable code. The specific affected package is not identified in the evidence.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version. Prioritize updates if the affected package is a runtime dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3f6h-2hrp-w5wx applies
Minor caution · medium confidence
A security scanner found a known issue in a dependency. Because the plugin is built into a single file and most dependencies are build tools, the issue likely does not affect users of the finished plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3f6h-2hrp-w5wx to a dependency declared by this repository.
Contextual assessment: A medium-severity OSV advisory matched a dependency in this lockfile. The project is a browser plugin that ships a bundled JS file. Most lockfile packages are dev-only build tooling absent from the final artifact. The runtime dependency surface is small. Without the specific package identity, the advisory most likely targets a build-time dependency with no runtime reachability.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version if one is available.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3f6h-2hrp-w5wx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2v37-7h3g-55p8 applies
Minor caution · medium confidence
A security scanner flagged a high-severity issue in a dependency. Since the plugin is compiled into one file and most dependencies are only used during building, the issue probably does not affect the plugin users run.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8 to a dependency declared by this repository.
Contextual assessment: A high-severity OSV advisory matched a dependency in this lockfile. The project ships a single bundled JS file as a RisuAI browser plugin. The lockfile is dominated by dev-only build tools. If the advisory targets a build tool, there is no runtime impact on the shipped plugin. If it targets a runtime dependency, the browser-plugin context limits practical exploitability. The specific affected package is not identified in the evidence.
Impact: low · Exploitability: unlikely
Developer action: Run npm audit to identify the specific package and update it to a fixed version. Prioritize updates if the affected package is a runtime dependency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2v37-7h3g-55p8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
A security flaw was found in a build tool used during development. The tool helps create the final plugin file but is not included in the plugin itself. People who use the finished plugin are not affected; only developers running the tool locally could be at risk.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: This advisory most likely corresponds to a Vite dev-server vulnerability (arbitrary file read or middleware bypass). Vite is declared as a devDependency at ^5.0.0 and is used only during the build process. The shipped artifact is a single bundled JS file (dist/risu-usage-tracker.js) loaded into RisuAI; the Vite dev server and its vulnerable request-handling code are not present in the build output. End users loading the built extension are not exposed to the vulnerable code path, which requires an attacker to send crafted requests to a locally running dev server.
Impact: none · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version to protect the development environment. No change is required for the shipped extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-pr6f-5x2q-rwfp applies
Minor caution · medium confidence
A moderate security issue was found in a development tool or library used during the build process. The issue does not carry over into the finished plugin that users load into RisuAI.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-pr6f-5x2q-rwfp to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory most likely targets a build-time or transitive devDependency. The project's production dependencies (flatpickr, lodash 4.17.21, lucide-svelte, svelte 4.x) are either at patched versions or are unlikely to carry this advisory. The build output is a bundled JS file that excludes dev tooling. Without the vulnerable code in the shipped artifact, there is no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version as a development-environment best practice. No change is required for the shipped extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-pr6f-5x2q-rwfp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fx2h-pf6j-xcff applies
Minor caution · medium confidence
A serious flaw was found in another build tool used only during development. The tool is not part of the finished plugin, so users of the plugin are not exposed to this issue.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.
Contextual assessment: This high-severity advisory is most likely another Vite or Vite-plugin vulnerability affecting the development server or build pipeline. These packages are devDependencies and their vulnerable code (dev-server request handling, middleware, file-serving logic) is not bundled into the final extension output. The shipped plugin runs in the RisuAI browser context and does not expose the vulnerable code paths to end users or network attackers.
Impact: none · Exploitability: unlikely
Developer action: Update the affected devDependency to a patched version to secure the development workflow. No change is required for the shipped extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fx2h-pf6j-xcff
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-crpf-4hrx-3jrp applies
Minor caution · medium confidence
A moderate security issue was found in a library used during the build process. The library is not included in the finished plugin, so users are not affected.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-crpf-4hrx-3jrp to a dependency declared by this repository.
Contextual assessment: This medium-severity advisory most likely corresponds to a transitive devDependency or build tool. The project's production dependencies are at versions that are either patched or not associated with known advisories of this severity. The build process produces a bundled JS artifact that does not include dev tooling, so the vulnerable code has no runtime reachability in the shipped extension.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version as a development best practice. No change is required for the shipped extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-crpf-4hrx-3jrp
- File role
- production
- Source
- package-lock.json
Expected scanner matches (2)
Dependency advisory GHSA-8qm3-746x-r74r applies
Expected behavior · low confidence
A minor security notice was found for a dependency. The risk is very low and unlikely to affect users of this plugin.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-8qm3-746x-r74r to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency. Low-severity advisories in this ecosystem typically describe minor issues with limited practical impact. In a browser extension context that bundles its production dependencies and does not ship devDependencies, the concrete user harm from a low-severity advisory is negligible.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency when convenient during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-8qm3-746x-r74r
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-pxg6-pf52-xh8x applies
Expected behavior · low confidence
A minor security notice was found for a dependency. The risk is very low and unlikely to affect users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-pxg6-pf52-xh8x to a dependency declared by this repository.
Contextual assessment: A low-severity advisory was matched against a dependency. In this browser extension context where only bundled production code ships and the extension processes locally generated data, a low-severity advisory presents negligible concrete user harm.
Impact: none · Exploitability: unlikely
Developer action: Update the affected dependency when convenient during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-pxg6-pf52-xh8x
- File role
- production
- Source
- package-lock.json