79592945

Date: 2025-04-25 16:35:13
Score: 0.5
Natty:
Report link

You should always do your due diligence when adding a new package to your codebase, at the end of the day it is 3rd party code.

I think your main worry is your credentials being exposed. This package in particular seems to be popular enough to be battle tested and trusted by a good chunk of the community.

I think you'll be fine. Just remember to keep your credentials a secret and that means not adding them to version control. Use env variables or any of the other methods listed here to set your credentials.

Reasons:
  • Long answer (-0.5):
  • No code block (0.5):
  • Low reputation (0.5):
Posted by: Amauri