What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-6rw7-vpxm-498p applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6rw7-vpxm-498p to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6rw7-vpxm-498p
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-72xf-g2v4-qvf3 applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-72xf-g2v4-qvf3 to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-72xf-g2v4-qvf3
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-p8p7-x288-28g6 applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-p8p7-x288-28g6 to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-p8p7-x288-28g6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-c2qf-rxjj-qqgw applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2qf-rxjj-qqgw to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2qf-rxjj-qqgw
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-2g4f-4pwh-qvx6 applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2g4f-4pwh-qvx6
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-hrpp-h998-j3pp applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hrpp-h998-j3pp to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hrpp-h998-j3pp
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · medium confidence
The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · medium confidence
A build-tool package used during development has a known security issue, but the finished emoji library that users actually load does not include this package. The risk to people using the library is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the project yarn.lock. The project is a client-side emoji parsing library whose shipped artifact is a standalone minified script and image assets. The advisory corresponds to a build-tooling dependency that is not part of the runtime artifact consumed by end users. No data flow from untrusted user input to the vulnerable code in a production runtime context is demonstrated by the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependency to a patched version when convenient; this is low priority for end-user safety.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-vh95-rmgr-6w4m applies
Minor caution · medium confidence
A development-time package has a known issue, but it is not part of the emoji library that end users load, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-vh95-rmgr-6w4m to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the yarn.lock. The project ships a standalone client-side emoji script; the affected package is a build or tooling dependency not present in the runtime artifact. No runtime reachability from attacker-controlled input to the vulnerable code is evident in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-vh95-rmgr-6w4m
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-v6h2-p8h4-qcjw applies
Minor caution · medium confidence
A minor known issue exists in a development package, but it does not reach the emoji library that users actually use.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.
Contextual assessment: This low-severity advisory matches a declared dependency in the yarn.lock. The affected package is part of the build toolchain for a client-side emoji library and is not included in the shipped runtime artifact. No concrete end-user harm path is demonstrated by the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6h2-p8h4-qcjw
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-896r-f27r-55mw applies
Minor caution · medium confidence
A development package has a serious known issue, but because it is only used during the build process and is not included in the emoji library that users load, the actual risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-896r-f27r-55mw to a dependency declared by this repository.
Contextual assessment: Although the scanner rates this advisory as critical, the affected dependency is declared in the file of a client-side emoji library whose shipped artifact is a standalone script. The vulnerable package is a build or tooling dependency with no demonstrated runtime reachability in the shipped library. Advisory severity alone does not establish immediate danger without a reachable exploitation path in the production artifact.
Impact: low · Exploitability: unlikely
Developer action: Update the affected build-time dependency to a patched version as part of routine maintenance; prioritize it above lower-severity items but it is not an end-user emergency.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-896r-f27r-55mw
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-f8q6-p94x-37v3 applies
Minor caution · medium confidence
A build-time package has a known issue, but it is not part of the emoji library that end users load, so practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f8q6-p94x-37v3 to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the yarn.lock. The project is a client-side emoji library; the affected package is a build or tooling dependency not present in the shipped runtime artifact. No data flow from untrusted input to the vulnerable code in production is demonstrated.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f8q6-p94x-37v3
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3xgq-45jj-v275 applies
Minor caution · medium confidence
A development package has a known issue, but it does not reach the emoji library that users actually load.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3xgq-45jj-v275 to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the file of a client-side emoji library. The affected package is part of the build toolchain and is not included in the shipped runtime artifact. No runtime reachability from attacker-controlled input is evident in the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3xgq-45jj-v275
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-395f-4hp3-45gv applies
Minor caution · medium confidence
A build-time package has a known issue, but it is not part of the emoji library that end users load, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the yarn.lock. The project ships a standalone client-side emoji script; the affected package is a build or tooling dependency not present in the runtime artifact. No concrete exploitation path in the shipped library is demonstrated by the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version during routine maintenance.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-395f-4hp3-45gv
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-7r86-cg39-jmmj applies
Minor caution · medium confidence
A development package has a known issue, but it does not reach the emoji library that users actually use.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: This advisory matches a declared dependency in the file of a client-side emoji library. The affected package is a build or tooling dependency not included in the shipped runtime artifact. No runtime reachability from untrusted input to the vulnerable code is demonstrated by the supplied evidence.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-fjxv-7rqg-78g4 applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fjxv-7rqg-78g4 to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fjxv-7rqg-78g4
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-xvch-5gv4-984h applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-xvch-5gv4-984h to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-xvch-5gv4-984h
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-hmw2-7cc7-3qxx applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-hmw2-7cc7-3qxx
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-w5hq-g745-h8pq applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w5hq-g745-h8pq
- File role
- production
- Source
- yarn.lock
Dependency advisory GHSA-w7jw-789q-3m8p applies
Minor caution · medium confidence
The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-w7jw-789q-3m8p to a dependency declared by this repository.
Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.
Impact: none · Exploitability: unlikely
Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-w7jw-789q-3m8p
- File role
- production
- Source
- yarn.lock
Expected scanner matches (5)
JavaScript analysis reported javascript.xray.unsafe-command
Expected behavior · high confidence
This is a build helper that calls the openssl program to generate a security hash for emoji asset files. The command and its options are fixed, and the file name is passed safely as a separate argument, so there is no way for input to sneak in extra commands.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.
Contextual assessment: The flagged line uses spawnSync to invoke the openssl binary with an argument array to compute a SHA-384 digest for SRI integrity hashing. The executable name and algorithm are static literals, and the filename is passed as a discrete array element rather than through a shell string, so there is no command-injection vector. This is a standard build-time tooling operation consistent with the file role.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.unsafe-command
- File role
- tooling
- Source
- scripts/utils.js:34
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · high confidence
The code is a test file for an emoji library. The flagged 'obfuscation' is actually just the standard way of writing emoji characters in JavaScript code for testing purposes.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The scanner flagged this file for obfuscated code, but the source context shows it is a standard test file for the twemoji library. The unicode escape sequences (e.g., \u2764) are used to represent emoji characters in test strings, which is normal for an emoji parsing library and not an obfuscation technique.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- test
- Source
- src/test/test.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
This is a small test image file used by the emoji library. The flagged link is just the standard identifier that all SVG files must include; it is not a real internet connection and does nothing harmful.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The flagged content is a static SVG test fixture containing a standard XML namespace declaration and an inline emoji character. The namespace URI is a structural identifier required by SVG, not a runtime network destination. No script execution, network request, credential access, or data flow occurs. The scanner signal is a false positive on a literal namespace string in a test asset.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- src/test/test.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
This is a test that loads a small piece of example emoji text into a browser frame using a built-in data link, then checks that the emoji library can process it correctly. It does not contact any external website or send any data anywhere. The alert is a false alarm caused by the test's use of an encoded data link.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The flagged line is inside a test file for the twemoji library. The test named 'XHTML parseNode compatibility' creates an iframe whose src is a data URI containing URL-encoded XHTML with a heart emoji character. This is a standard technique for loading test XHTML content into an iframe without a separate server-hosted file. The data URI decodes to a minimal XHTML document used solely to verify that twemoji.parse correctly handles XHTML nodes. There is no network request to an external host, no credential access, no exfiltration, and no concealed execution. The scanner's shady-link signal is a false positive triggered by the data URI scheme combined with encoded content.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- src/test/test.js:613
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · high confidence
This is a build helper that assembles the final emoji library file by combining text and code templates. The scanner mistook this normal code-generation pattern for obfuscation. There is no hidden or harmful behavior.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The scanner flagged an obfuscation signal on a build script that generates the distributed twemoji library by concatenating string literals with an inline function source. This pattern of writing a generated file via string concatenation and function serialization is standard for build tooling and does not indicate concealed logic, encoded payloads, or hidden execution. The script imports only expected Node modules and local project utilities, with no network exfiltration, credential access, or runtime obfuscation of malicious behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- tooling
- Source
- scripts/build.js:1