softethervpn-server-manager

maintainer orphaned · 2 votes · scanned 2026-08-03 00:08:14.047287
LOW
View on AUR ↗
Why flagged The package downloads official SoftEther VPN tools from the project's own download domain, which is not on the whitelist but is plausibly legitimate; the files are used as intended and not obfuscated, posing low risk despite the non-standard host.

Triggered rules

LOW AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-07-25) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package downloads official SoftEther VPN tools from the project's own download domain, which is not on the whitelist but is plausibly legitimate; the files are used as intended and not obfuscated, posing low risk despite the non-standard host.

1 higher static finding superseded - not the current verdict (shown for transparency)
MEDIUM source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:11 source=("https://www.softether-download.com/files/softether/${_realpkgver}-tree/Windows/Admin_Tools/VPN_Server_Manager_and_Command-line_Utility_Package/softether-vpn_admin_tools-${_realpkgver}-win32.zip"

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Jonathan Liu <net147@gmail.com>
2pkgname=softethervpn-server-manager
3pkgver=v4.44_9807
4_realpkgver=${pkgver//_/-}-rtm-2025.04.16
5pkgrel=1
6pkgdesc="SoftEther VPN Server Manager"
7arch=('i686' 'x86_64')
8url="https://www.softether.org/"
9license=('Apache')
10depends=('desktop-file-utils' 'wine')
11source=("https://www.softether-download.com/files/softether/${_realpkgver}-tree/Windows/Admin_Tools/VPN_Server_Manager_and_Command-line_Utility_Package/softether-vpn_admin_tools-${_realpkgver}-win32.zip"
12 'vpnsmgr.desktop'
13 'vpnsmgr.png'
14 'vpnsmgr.sh')
15md5sums=('d4ee2376f2697f4d32c8dc213ea898ba'
16 'e3b4b8905f18330728afc17ad90570b3'
17 '43aa41b68db7ec99b461f17cb6834396'
18 '4fbbe5c79abb498a4ec71f8715c5a7db')
19
20package() {
21 install -D -m 755 vpnsmgr.sh "${pkgdir}/usr/bin/vpnsmgr"
22 install -D -m 644 hamcore.se2 "${pkgdir}/usr/lib/softethervpn/vpnsmgr/hamcore.se2"
23 install -D -m 644 vpnsmgr.exe "${pkgdir}/usr/lib/softethervpn/vpnsmgr/vpnsmgr.exe"
24 install -D -m 644 vpnsmgr.desktop "${pkgdir}/usr/share/applications/vpnsmgr.desktop"
25 install -D -m 644 vpnsmgr.png "${pkgdir}/usr/share/pixmaps/vpnsmgr.png"
26}
27
28# vim:set ts=2 sw=2 et:
29

Scan history

Scanned at (UTC)SeverityRules
2026-08-03 00:08:14 LOW 2
2026-08-02 00:16:08 LOW 2
2026-08-01 00:11:18 LOW 2
2026-07-31 00:14:10 LOW 2
2026-07-30 00:17:23 LOW 2
2026-07-29 00:25:53 LOW 2
2026-07-28 00:07:28 LOW 2
2026-07-27 00:24:32 LOW 2
2026-07-26 00:07:32 LOW 2
2026-07-25 00:13:44 LOW 2
2026-07-24 00:02:28 LOW 2
2026-07-23 00:14:47 LOW 2
2026-07-22 00:29:32 LOW 2
2026-07-21 00:24:15 LOW 2
2026-07-20 00:19:49 LOW 2
2026-07-19 00:17:08 LOW 2
2026-07-18 00:14:48 LOW 2
2026-07-17 00:06:16 LOW 2
2026-07-16 00:05:41 LOW 2
2026-07-15 00:09:25 LOW 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion