TavernKeeper Scan Report

twitter/twemoji

Commit bad3bce Reviewed

1 material concern identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 1 material 32 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-6rw7-vpxm-498p applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6rw7-vpxm-498p to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6rw7-vpxm-498p
File role
production
Source
yarn.lock

Dependency advisory GHSA-72xf-g2v4-qvf3 applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-72xf-g2v4-qvf3 to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-72xf-g2v4-qvf3
File role
production
Source
yarn.lock

Dependency advisory GHSA-p8p7-x288-28g6 applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-p8p7-x288-28g6 to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-p8p7-x288-28g6
File role
production
Source
yarn.lock

Dependency advisory GHSA-c2qf-rxjj-qqgw applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2qf-rxjj-qqgw to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2qf-rxjj-qqgw
File role
production
Source
yarn.lock

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
yarn.lock

Dependency advisory GHSA-hrpp-h998-j3pp applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hrpp-h998-j3pp to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hrpp-h998-j3pp
File role
production
Source
yarn.lock

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
yarn.lock

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · medium confidence

The project uses some outdated tools to build its files, but those tools are not included in the final product that users download. This means the security issues in those tools don't directly affect people using the library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The advisory matches a dependency declared in the project's lockfile. This project is a client-side emoji library, and the lockfile dependencies are used for the build process rather than shipped to end users. The vulnerable code is not included in the distributed artifact, so there is no runtime reachability for end users. The impact is limited to the local build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependencies to their patched versions to secure the development and build environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
yarn.lock

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A build-tool package used during development has a known security issue, but the finished emoji library that users actually load does not include this package. The risk to people using the library is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: This advisory matches a declared dependency in the project yarn.lock. The project is a client-side emoji parsing library whose shipped artifact is a standalone minified script and image assets. The advisory corresponds to a build-tooling dependency that is not part of the runtime artifact consumed by end users. No data flow from untrusted user input to the vulnerable code in a production runtime context is demonstrated by the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependency to a patched version when convenient; this is low priority for end-user safety.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
yarn.lock

Dependency advisory GHSA-vh95-rmgr-6w4m applies

Minor caution · medium confidence

A development-time package has a known issue, but it is not part of the emoji library that end users load, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-vh95-rmgr-6w4m to a dependency declared by this repository.

Contextual assessment: This advisory matches a declared dependency in the yarn.lock. The project ships a standalone client-side emoji script; the affected package is a build or tooling dependency not present in the runtime artifact. No runtime reachability from attacker-controlled input to the vulnerable code is evident in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-vh95-rmgr-6w4m
File role
production
Source
yarn.lock

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Minor caution · medium confidence

A minor known issue exists in a development package, but it does not reach the emoji library that users actually use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: This low-severity advisory matches a declared dependency in the yarn.lock. The affected package is part of the build toolchain for a client-side emoji library and is not included in the shipped runtime artifact. No concrete end-user harm path is demonstrated by the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
yarn.lock

Dependency advisory GHSA-896r-f27r-55mw applies

Minor caution · medium confidence

A development package has a serious known issue, but because it is only used during the build process and is not included in the emoji library that users load, the actual risk to users is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-896r-f27r-55mw to a dependency declared by this repository.

Contextual assessment: Although the scanner rates this advisory as critical, the affected dependency is declared in the file of a client-side emoji library whose shipped artifact is a standalone script. The vulnerable package is a build or tooling dependency with no demonstrated runtime reachability in the shipped library. Advisory severity alone does not establish immediate danger without a reachable exploitation path in the production artifact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected build-time dependency to a patched version as part of routine maintenance; prioritize it above lower-severity items but it is not an end-user emergency.

Scanner
osv-scanner 2.4.0
Rule
GHSA-896r-f27r-55mw
File role
production
Source
yarn.lock

Dependency advisory GHSA-f8q6-p94x-37v3 applies

Minor caution · medium confidence

A build-time package has a known issue, but it is not part of the emoji library that end users load, so practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f8q6-p94x-37v3 to a dependency declared by this repository.

Contextual assessment: This advisory matches a declared dependency in the yarn.lock. The project is a client-side emoji library; the affected package is a build or tooling dependency not present in the shipped runtime artifact. No data flow from untrusted input to the vulnerable code in production is demonstrated.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f8q6-p94x-37v3
File role
production
Source
yarn.lock

Dependency advisory GHSA-3xgq-45jj-v275 applies

Minor caution · medium confidence

A development package has a known issue, but it does not reach the emoji library that users actually load.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3xgq-45jj-v275 to a dependency declared by this repository.

Contextual assessment: This advisory matches a declared dependency in the file of a client-side emoji library. The affected package is part of the build toolchain and is not included in the shipped runtime artifact. No runtime reachability from attacker-controlled input is evident in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3xgq-45jj-v275
File role
production
Source
yarn.lock

Dependency advisory GHSA-395f-4hp3-45gv applies

Minor caution · medium confidence

A build-time package has a known issue, but it is not part of the emoji library that end users load, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-395f-4hp3-45gv to a dependency declared by this repository.

Contextual assessment: This advisory matches a declared dependency in the yarn.lock. The project ships a standalone client-side emoji script; the affected package is a build or tooling dependency not present in the runtime artifact. No concrete exploitation path in the shipped library is demonstrated by the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-395f-4hp3-45gv
File role
production
Source
yarn.lock

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · medium confidence

A development package has a known issue, but it does not reach the emoji library that users actually use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: This advisory matches a declared dependency in the file of a client-side emoji library. The affected package is a build or tooling dependency not included in the shipped runtime artifact. No runtime reachability from untrusted input to the vulnerable code is demonstrated by the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
yarn.lock

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
yarn.lock

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
yarn.lock

Dependency advisory GHSA-fjxv-7rqg-78g4 applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fjxv-7rqg-78g4 to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fjxv-7rqg-78g4
File role
production
Source
yarn.lock

Dependency advisory GHSA-xvch-5gv4-984h applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvch-5gv4-984h to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvch-5gv4-984h
File role
production
Source
yarn.lock

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
yarn.lock

Dependency advisory GHSA-hmw2-7cc7-3qxx applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-hmw2-7cc7-3qxx to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-hmw2-7cc7-3qxx
File role
production
Source
yarn.lock

Dependency advisory GHSA-w5hq-g745-h8pq applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w5hq-g745-h8pq to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w5hq-g745-h8pq
File role
production
Source
yarn.lock

Dependency advisory GHSA-w7jw-789q-3m8p applies

Minor caution · medium confidence

The flagged dependency is a tool used by the developers to build the library, not a part of the final product that users run. The security issue does not affect people using the emoji library.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w7jw-789q-3m8p to a dependency declared by this repository.

Contextual assessment: The advisory matches a development dependency declared in the project's lockfile. Twemoji is a client-side emoji parsing library that ships a static built JavaScript file. The dependencies in the lockfile are used for building and testing the repository and are not bundled into the shipped artifact consumed by extensions. Therefore, the vulnerable code has no runtime reachability in production environments.

Impact: none · Exploitability: unlikely

Developer action: Update the development dependency in the repository to resolve the advisory, though it does not affect the shipped product.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w7jw-789q-3m8p
File role
production
Source
yarn.lock
Expected scanner matches (5)

JavaScript analysis reported javascript.xray.unsafe-command

Expected behavior · high confidence

This is a build helper that calls the openssl program to generate a security hash for emoji asset files. The command and its options are fixed, and the file name is passed safely as a separate argument, so there is no way for input to sneak in extra commands.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.

Contextual assessment: The flagged line uses spawnSync to invoke the openssl binary with an argument array to compute a SHA-384 digest for SRI integrity hashing. The executable name and algorithm are static literals, and the filename is passed as a discrete array element rather than through a shell string, so there is no command-injection vector. This is a standard build-time tooling operation consistent with the file role.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.unsafe-command
File role
tooling
Source
scripts/utils.js:34

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The code is a test file for an emoji library. The flagged 'obfuscation' is actually just the standard way of writing emoji characters in JavaScript code for testing purposes.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The scanner flagged this file for obfuscated code, but the source context shows it is a standard test file for the twemoji library. The unicode escape sequences (e.g., \u2764) are used to represent emoji characters in test strings, which is normal for an emoji parsing library and not an obfuscation technique.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
test
Source
src/test/test.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a small test image file used by the emoji library. The flagged link is just the standard identifier that all SVG files must include; it is not a real internet connection and does nothing harmful.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged content is a static SVG test fixture containing a standard XML namespace declaration and an inline emoji character. The namespace URI is a structural identifier required by SVG, not a runtime network destination. No script execution, network request, credential access, or data flow occurs. The scanner signal is a false positive on a literal namespace string in a test asset.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
src/test/test.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a test that loads a small piece of example emoji text into a browser frame using a built-in data link, then checks that the emoji library can process it correctly. It does not contact any external website or send any data anywhere. The alert is a false alarm caused by the test's use of an encoded data link.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged line is inside a test file for the twemoji library. The test named 'XHTML parseNode compatibility' creates an iframe whose src is a data URI containing URL-encoded XHTML with a heart emoji character. This is a standard technique for loading test XHTML content into an iframe without a separate server-hosted file. The data URI decodes to a minimal XHTML document used solely to verify that twemoji.parse correctly handles XHTML nodes. There is no network request to an external host, no credential access, no exfiltration, and no concealed execution. The scanner's shady-link signal is a false positive triggered by the data URI scheme combined with encoded content.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
src/test/test.js:613

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

This is a build helper that assembles the final emoji library file by combining text and code templates. The scanner mistook this normal code-generation pattern for obfuscation. There is no hidden or harmful behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The scanner flagged an obfuscation signal on a build script that generates the distributed twemoji library by concatenating string literals with an inline function source. This pattern of writing a generated file via string concatenation and function serialization is standard for build tooling and does not indicate concealed logic, encoded payloads, or hidden execution. The script imports only expected Node modules and local project utilities, with no network exfiltration, credential access, or runtime obfuscation of malicious behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
tooling
Source
scripts/build.js:1

Related contextual observations

spawnSync used with static command and argument array for integrity hashing

low risk · high confidence

The code safely runs an external hashing tool by passing fixed options and the file name as separate items, which prevents any hidden command injection.

Technical assessment

spawnSync is invoked with a fixed executable and an arguments array, avoiding shell interpretation. The filename argument is passed directly, preventing injection. This matches the tooling file role of generating SRI hashes.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

SVG namespace declaration mistaken for network link

low risk · high confidence

The scanner saw a web address inside an image file, but that address is a mandatory label for SVG images and is never actually contacted.

Technical assessment

The file is an SVG fixture whose root element declares the standard SVG namespace. JS-X-Ray appears to have treated the namespace literal as a fixed link. No fetch, import, or network call is present; the string is a structural XML identifier.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

All advisories target build-tooling dependencies in a client-side emoji library

low risk · medium confidence

All of the flagged security issues are in packages used to build the emoji library, not in the library itself. Users who load the finished emoji script are not exposed to these issues. Updating the build packages is good hygiene but is not urgent for user safety.

Technical assessment

The supplied file is for a project whose shipped artifact is a standalone client-side emoji parsing script and image assets. All eight advisories match declared dependencies that are part of the build or development toolchain rather than the runtime library. The source context is truncated, preventing exact per-advisory package-version mapping, but the project purpose and the nature of the visible dependency tree indicate no runtime reachability from end-user input to any vulnerable code in the shipped artifact. The confidence is medium because the truncated source does not allow full verification of every package version and its dependency classification.

Impact: low · Exploitability: unlikely

Developer action: Run a dependency update pass to resolve all flagged advisories in the build toolchain. No urgent end-user-facing action is required.

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity