TavernKeeper Scan Report

Decidetto/ME-accent-color-changer

Commit 47d443f Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 2 low

What this review found

No material or immediate-danger item was identified.

Contextual expected matches (1)

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged content is just an SVG picture used as an icon. It contains no web links, no network access, and nothing that sends data anywhere. The scanner warning is a false alarm triggered by standard SVG markup.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
ext.js:1

Related contextual observations

file contains only inline SVG icon markup, no network or executable behavior

low risk · high confidence

The file content is a static SVG icon, not executable network code. No risk is shown.

Technical assessment

The entire supplied file content is a single line of inline SVG markup representing a sliders/settings icon. It contains only standard SVG elements and attributes, with no JavaScript logic, network calls, or external resource references beyond the standard W3C namespace.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity