File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- .env:1
- Evidence
PRIVATE_KEY=[REDACTED]
Security audit
Security checks across malware telemetry and agentic risk
This translation plugin contains undisclosed Orbit registry/billing behavior and private-key handling that do not match its translation-only description.
Do not install this version unless you are comfortable with the undisclosed Orbit registry/billing integration and private-key handling. Ask the publisher to remove the packaged .env secrets, declare any required PRIVATE_KEY and Orbit behavior, and clearly document any fees or usage recording. If you only need translation, prefer a version that only calls a trusted LibreTranslate-compatible endpoint.
VirusTotal engine telemetry is currently stale for this artifact.
Detected: suspicious.exposed_secret_literal
PRIVATE_KEY=[REDACTED]