github.com / xiaojieonly
xiaojieonly/ Ehviewer_CN_SXJ
C·2570 files·commit 3974bda·scanned 54s ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 27,071+ stars — findings likely false positives
verdict accurate?
27,071 stars
2% file coverage
threat-state: lowlive
FINDINGS ░▒▓
criticalFunction() constructor detectednew Function() is equivalent to eval() and can execute arbitrary code strings.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/jquery.js
/*! jQuery v1.7.1 jquery.com | jquery.org/license */
(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f("<"...+5warningGo unsafe package usageunsafe package bypasses Go's type safety. Malware uses it for memory tricks, pointer casts, and hiding behavior.app/src/main/cpp/jni/libwebp/swig/libwebp.go
import _ "runtime/cgo" import "unsafe" type _ unsafe.Pointer+3
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/jquery.js+4
infoMinified code in source directoryMinified/obfuscated code in source directories (not dist/) makes code review impossible.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/jquery.js+3
warningHigh-entropy string literalsFound 34 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/jquery.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/jquery.js+3
warningHigh-entropy string literalsFound 92 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/search/all_74.js+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/search/enums_74.js+3
warningLarge base64-encoded blobA 256-character base64 blob was found. May hide a remote payload or encoded executable code.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/search/search.js
000000000000000000000000000000000000000000000000000000000000...+3
warningLarge hex-encoded blobA 256-character hex blob was found. Often used to hide shellcode or C2 addresses.app/src/main/cpp/jni/libjpeg-turbo/libjpeg-turbo/doc/html/search/search.js
000000000000000000000000000000000000000000000000000000000000...+3
infoSuspicious file in repoExecutable file (png2pnm.bat) in repositoryapp/src/main/cpp/jni/libpng/libpng/contrib/pngminus/png2pnm.bat+2
infoSuspicious file in repoExecutable file (pngminus.bat) in repositoryapp/src/main/cpp/jni/libpng/libpng/contrib/pngminus/pngminus.bat+2
infoSuspicious file in repoExecutable file (pnm2png.bat) in repositoryapp/src/main/cpp/jni/libpng/libpng/contrib/pngminus/pnm2png.bat+2
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
63 files scanned @ 3974bda | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution10
network & exfiltration0
file system access0
obfuscation15
supply chain10
owasp / injection0
telemetry
files 63/2570rules hit 14engine v6commit 3974bda
github
xiaojieonly/Ehviewer_CN_SXJ
ehviewer,用爱发电,快乐前行
27071
714
2146d
2570 files
63 scanned(2%)
3974bda
architecture░▒▓
entry (0) flagged (9) pkg (12)
48 nodes · 12 edgesscroll to zoom · click node to jump to finding