masterpdfeditor

LOW
maintainer pgoetz 202 votes scanned 2026-10-02 00:00:32.890515
View on AUR
Why flagged

The package downloads a source tarball from the project's official domain for building the software, which is a normal AUR practice; the host is not whitelisted but is plausibly project-owned, and the content is not executed remotely.

Triggered rules

Low AI review llm_review

An AI model (qwen/qwen3-235b-a22b-2507) reviewed this and agrees it is LOW (confidence 95%): The package downloads a source tarball from the project's official domain for building the software, which is a normal AUR practice; the host is not whitelisted but is plausibly project-owned, and the content is not executed remotely.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:15 source_x86_64=("https://code-industry.net/public/master-pdf-editor-${pkgver}-qt5.x86_64.tar.gz")

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Patrick Goetz <pgoetz at mail dot utexas dot edu>
2# Contributor: Doug Newgard <scimmia at archlinux dot org>
3# Contributor: Jiachen Yang <farseerfc@gmail.com>
4# Contributor: Miguel Revilla <yo@miguelrevilla.com>
5# Contributor: Ferik <djferik at gmail dot com>
6
7pkgname=masterpdfeditor
8pkgver=5.9.99
9pkgrel=3
10pkgdesc='A complete solution for viewing, creating and editing PDF files'
11url='https://code-industry.net/free-pdf-editor/'
12arch=('x86_64')
13license=('custom')
14makedepends=('patchelf')
15source_x86_64=("https://code-industry.net/public/master-pdf-editor-${pkgver}-qt5.x86_64.tar.gz")
16sha1sums_x86_64=('bf84fca45c8e416f959b9667a21baf45d87e0f39')
17
18package() {
19 depends=('libgl' 'pkcs11-helper' 'qt5-base' 'qt5-svg' 'qt5-declarative' 'sane')
20
21 install -d "$pkgdir"{/opt/,/usr/bin/}
22 cp -a --no-preserve=ownership master-pdf-editor-${pkgver%%.*} "$pkgdir/opt/"
23
24 cd "$pkgdir/opt/master-pdf-editor-${pkgver%%.*}"
25 ln -sr masterpdfeditor${pkgver%%.*} -t "$pkgdir/usr/bin/"
26 install -Dm644 usr/share/applications/net.code-industry.masterpdfeditor${pkgver%%.*}.desktop -t "$pkgdir/usr/share/applications/"
27 install -Dm644 license_en.txt -t "$pkgdir/usr/share/licenses/$pkgname/"
28 find usr/share/icons -type f -exec install -Dm644 "{}" "$pkgdir/{}" \;
29 patchelf --remove-rpath masterpdfeditor${pkgver%%.*}
30}
31
32

Scan history

Scanned at (UTC)SeverityRules
2026-10-02 00:00:32 Low 2
2026-10-01 00:02:06 Low 2
2026-09-30 00:20:07 Low 2
2026-09-29 00:07:46 Low 2
2026-09-28 00:28:32 Low 2
2026-09-27 00:07:07 Low 2
2026-09-26 00:12:15 Low 2
2026-09-25 00:03:36 Low 2
2026-09-24 00:24:14 Low 2
2026-09-23 00:28:13 Low 2
2026-09-22 00:15:14 Low 2
2026-09-21 00:26:32 Low 2
2026-09-20 00:25:31 Low 2
2026-09-19 00:25:36 Low 2
2026-09-18 00:17:11 Low 2
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion