Hub rules-cordova

rules-cordova

v5 public Verified

Cordova

Apache Cordova is a mobile development framework for building cross-platform apps using web technologies. These rules assist AI agents in plugin management, build configurations, and native platform integration.

@sigmashakeinc 2 pulls 6 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-cordova →
Severity
2 error 2 warn 2 info
demo.cast
Apache Cordova is a mobile development framework for building cross-platform apps using web technologies. These rules assist AI agents in plugin management, build configurations, and native platform integration.

Rules index

6 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

cordova

cordova-allow-intent-wildcard warning log

Cordova config.xml allows any URL to be opened externally (allow-intent href='*'). This allows the app to be redirected to open arbitrary URLs — including custom scheme handlers and malicious deep links — in the system browser. Enumerate the specific schemes and domains your app needs (e.g., 'https://*.example.com' and 'mailto:*').

Rule source requires an active Pro or Enterprise subscription.
cordova-block-unsafe-patterns info log

cordova.exec() detected — Cordova native bridge call. Ensure the plugin and method name are from a trusted, maintained plugin. User-controlled data passed to cordova.exec() arguments can be misused if the native plugin does not validate inputs.

Rule source requires an active Pro or Enterprise subscription.
cordova-debuggable-true error block

android:debuggable="true" in AndroidManifest.xml enables ADB-level debugging access to the app on any device, including production. Attackers with USB or ADB network access can dump memory, bypass authentication, and inspect WebView content. Remove this attribute — release builds set debuggable=false automatically when signed with a release key.

Rule source requires an active Pro or Enterprise subscription.
cordova-force-updated-api info log

window.plugins is a legacy Cordova plugin namespace. Modern Cordova plugins register under cordova.plugins or expose a top-level global. Migrate to the plugin's current API and verify the plugin is actively maintained.

Rule source requires an active Pro or Enterprise subscription.
cordova-missing-csp warning log

Cordova app index.html is missing a Content-Security-Policy meta tag. Without a CSP, any injected script in the WebView can call cordova.exec() and access native device APIs (camera, contacts, filesystem). Add a strict CSP: "default-src 'self'; script-src 'self'; object-src 'none'" and avoid 'unsafe-inline'.

Rule source requires an active Pro or Enterprise subscription.
cordova-wildcard-allow-navigation error block

Cordova config.xml allows navigation to any URL (allow-navigation href='*'). This permits WebView navigation to arbitrary attacker-controlled pages, enabling phishing, data exfiltration, and Cordova bridge abuse. Restrict allow-navigation to the exact origins your app navigates to, and use allow-intent for external URLs opened in the system browser.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
959a2d8663549e580f25a307b0da9d6944f409676cb57a85ea3b8829ac190640
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-cordova/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-cordova. The published version only bumps when a maintainer resyncs.

No commit history available.