Top issues
Detected presence of plaintext credentials within network protocol strings.
Causes risk: web service credentials found
secrets
Problem
Various network communication protocols allow including plaintext authentication credentials. Information such as user names and passwords could be passed through a non-encrypted channel, and therefore intercepted by malicious actors. Credentials are considered secrets, and should be kept encrypted until they are used. This policy control matches the following URI pattern protocol://username:password@domain within any software package component.Prevalence in PyPI community
21 packages
found in
Top 100
86 packages
found in
Top 1k
378 packages
found in
Top 10k
7.36k packages
in community
Next steps
Review the reported matches. If the warning refers to a placeholder credential value, it can be safely ignored.
Top behaviors
Contains URLs that contain basic authentication credentials.
network
Prevalence in PyPI community
Behavior often found in this community (Common)
26 packages
found in
Top 100
118 packages
found in
Top 1k
563 packages
found in
Top 10k
12.66k packages
in community
Renames a file or directory.
file
Prevalence in PyPI community
Behavior often found in this community (Common)
68 packages
found in
Top 100
540 packages
found in
Top 1k
3680 packages
found in
Top 10k
150.76k packages
in community
Contains unusually long strings.
anomaly
Prevalence in PyPI community
Behavior often found in this community (Common)
51 packages
found in
Top 100
408 packages
found in
Top 1k
2829 packages
found in
Top 10k
106.17k packages
in community
Queries the value of an environment variable.
search
Prevalence in PyPI community
Behavior often found in this community (Common)
73 packages
found in
Top 100
614 packages
found in
Top 1k
4460 packages
found in
Top 10k
173.79k packages
in community
Converts binary data to its string representation, commonly used in obfuscation.
packer
Prevalence in PyPI community
Behavior often found in this community (Common)
67 packages
found in
Top 100
586 packages
found in
Top 1k
4061 packages
found in
Top 10k
146.39k packages
in community
Top vulnerabilities
No vulnerabilities found.