github.com / firecrawl
firecrawl/ anydoc
Rust·329 files·commit 261fc25·scanned 2h ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 22,028+ stars — findings likely false positives
verdict accurate?
22,028 stars
37% file coverage
threat-state: lowlive
FINDINGS ░▒▓
warningHigh-entropy string literalsFound 8 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.node/index.js+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.bench/judge.py+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.node/anydoc.js+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
121 files scanned @ 261fc25 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation9
supply chain0
owasp / injection0
telemetry
files 121/329rules hit 4engine v6commit 261fc25
github
firecrawl/anydoc
Convert Word, PowerPoint, Excel, OpenDocument, RTF, EPUB, CSV, and PDF to clean Markdown. Built in Rust, with Node.js and Python bindings.
22028
1376
53d
329 files
121 scanned(37%)
261fc25
architecture░▒▓
entry (1) flagged (3) pkg (121)
237 nodes · 168 edgesscroll to zoom · click node to jump to finding