github.com / jealous-sound
jealous-sound/ azerothcore-wotlk-coa
C++·12978 files·commit bb7de17·scanned 1h ago·cached ✓
47/100
SUSPICIOUS
Obfuscation or dynamic code paths detected. Intent unclear — review before running anything.
verdict accurate?
Created 18 days ago
Created 18 days ago
1% file coverage
CLI tool detected
threat-state: suspiciouslive
FINDINGS ░▒▓
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.apps/coa-gameplay-test/scenarios/ascension-reward-items.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.apps/coa-gameplay-test/scenarios/barbarian-audit-1051-1069-3730-3904-raid-auras.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.apps/coa-gameplay-test/scenarios/barbarian-audit-1124-1292-2022-stat-passives.json+4
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.apps/EnumUtils/enumutils_describe.py+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.apps/ci/ci-pending-changelogs.ts+3
warningHigh-entropy string literalsFound 9 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.apps/coa-bugreport/relay.py+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.apps/coa-bugreport/relay.py+3
infoSuspicious file in repoExecutable file (extractor.bat) in repositoryapps/extractor/extractor.bat+2
infoSuspicious file in repoExecutable file (extractor_es.bat) in repositoryapps/extractor/extractor_es.bat+2
infoSuspicious file in repoVery large source file (751KB) — could contain obfuscated payloaddata/coa-world/baseline.json+2
warningHardcoded secret/credentialAPI keys, passwords, or tokens hardcoded in source code. Should be in environment variables.apps/coa-bugreport/relay.py
API = SERVICE_URL + "/v1/reports"
DEFAULT_API_KEY = "coa_zRatxUHShOn-HEkoreKGME6sd3DdMG7eKTTKlj2JCK4"
WEB = f"https://github.com/{REPOSITORY}/issues/"
KEY = re.compile(r"[1-9][0-9]{0,9}-[0-9a-f]{16,48...+3Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
120 files scanned @ bb7de17 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain12
owasp / injection3
telemetry
files 120/12978rules hit 12engine v6commit bb7de17
github
jealous-sound/azerothcore-wotlk-coa
Conquest of AzerothCore
197
128
18d
12978 files
120 scanned(1%)
bb7de17
architecture░▒▓
entry (0) flagged (9) pkg (42)
95 nodes · 171 edgesscroll to zoom · click node to jump to finding