github.com / pingmike2
pingmike2/ freebuff2api-wokers
JavaScript·17 files·commit c875b1e·scanned 4d ago·cached ✓
24/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
verdict accurate?
Created 14 days ago
Created 14 days ago
threat-state: lowlive
FINDINGS ░▒▓
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.worker.js+3
warningHigh-entropy string literalsFound 5 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.scripts/build-freebuff-models-json.mjs+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.scripts/build-freebuff-models-json.mjs+3
warningHigh-entropy string literalsFound 39 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.freebuff_tools/extract_freebuff.py+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
7 files scanned @ c875b1e | 8/20/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation12
supply chain2
owasp / injection0
telemetry
files 7/17rules hit 6engine v5commit c875b1e
github
pingmike2/freebuff2api-wokers
320
196
18d
17 files
7 scanned(41%)
c875b1e
architecture░▒▓
entry (0) flagged (3) pkg (7)
11 nodes · 8 edgesscroll to zoom · click node to jump to finding