github.com / webflow
webflow/ codeflow
TypeScript·64 files·commit b4802ae·scanned 11m ago·cached ✓
11/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
verdict accurate?
Social engineering indicators
threat-state: lowlive
FINDINGS ░▒▓
warningHigh-entropy string literalsFound 5 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/components/ui/dropdown-menu.tsx+3
warningHigh-entropy string literalsFound 12 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/components/ui/sidebar.tsx+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
40 files scanned @ b4802ae | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation6
supply chain0
owasp / injection0
telemetry
files 40/64rules hit 3engine v6commit b4802ae
github
webflow/codeflow
16
5
357d
64 files
40 scanned(63%)
b4802ae
architecture░▒▓
entry (1) flagged (2) pkg (36)
72 nodes · 120 edgesscroll to zoom · click node to jump to finding