Spectra Assure
Community
warningRisk: Secrets
Scanned: 15 days ago

otr-activerecord

latest
Top 10k
Off The Rails: Use ActiveRecord with Grape, Sinatra, Rack, or anything else!
License: Permissive (MIT)
Published: about 2 months ago




SAFE Assessment

Compliance

Licenses
No license compliance issues
Secrets
1 web service credentials found

Security

Vulnerabilities
No known vulnerabilities detected
Hardening
No application hardening issues

Threats

Tampering
No evidence of software tampering
Malware
No evidence of malware inclusion

Popularity

1.01M
Total Downloads
Contributor
Declared Dependencies
2
Dependents

Top issues

Problem

Various network communication protocols allow including plaintext authentication credentials. Information such as user names and passwords could be passed through a non-encrypted channel, and therefore intercepted by malicious actors. Credentials are considered secrets, and should be kept encrypted until they are used. This policy control matches the following URI pattern protocol://username:password@domain within any software package component.

Prevalence in RubyGems community

6 packages
found in
Top 100
16 packages
found in
Top 1k
84 packages
found in
Top 10k
471 packages
in community

Next steps

Review the reported matches. If the warning refers to a placeholder credential value, it can be safely ignored.

Top behaviors

Prevalence in RubyGems community

Behavior often found in this community (Common)
13 packages
found in
Top 100
54 packages
found in
Top 1k
437 packages
found in
Top 10k
5.31k packages
in community

Prevalence in RubyGems community

Behavior often found in this community (Common)
72 packages
found in
Top 100
484 packages
found in
Top 1k
3252 packages
found in
Top 10k
49.22k packages
in community

Prevalence in RubyGems community

Behavior often found in this community (Common)
79 packages
found in
Top 100
433 packages
found in
Top 1k
4385 packages
found in
Top 10k
81.6k packages
in community

Prevalence in RubyGems community

Behavior often found in this community (Common)
35 packages
found in
Top 100
173 packages
found in
Top 1k
1378 packages
found in
Top 10k
29.84k packages
in community

Prevalence in RubyGems community

Behavior often found in this community (Common)
71 packages
found in
Top 100
371 packages
found in
Top 1k
3553 packages
found in
Top 10k
66.39k packages
in community

Top vulnerabilities

No vulnerabilities found.