# Quick reminder about security and shared flows

**URL:** https://discourse.nodered.org/t/quick-reminder-about-security-and-shared-flows/5477
**Category:** General
**Created:** [4 December 2018 12:40 UTC](https://discourse.nodered.org/t/quick-reminder-about-security-and-shared-flows/5477 "2018-12-04T12:40:19Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [4 December 2018 12:40 UTC](https://discourse.nodered.org/t/quick-reminder-about-security-and-shared-flows/5477/1 "2018-12-04T12:40:20Z")

</div>

Hi all,

Just a quick thought. We have a lot of new people in the forum now and, while I'm not suggesting that any would be malicious, we cannot rule it out.

As such, this is just a reminder that, just because someone shares a flow, it doesn't mean that it is necessarily a good idea to plonk it in your Node-RED instance without checking it carefully.

Be safe out there folk! 😄

---

<div class="post-metadata">

### Author: ![JayDickson](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jaydickson/32/90592_2.png) [@JayDickson](https://discourse.nodered.org/u/JayDickson)
#### Post date: [4 December 2018 15:32 UTC](https://discourse.nodered.org/t/quick-reminder-about-security-and-shared-flows/5477/2 "2018-12-04T15:32:57Z")

</div>

[Never not be a little paranoid.](https://medium.com/@liran.tal/malicious-modules-what-you-need-to-know-when-installing-npm-packages-12b2f56d3685)

---

<div class="post-metadata">

### Author: ![krambriw](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/krambriw/32/5429_2.png) [@krambriw](https://discourse.nodered.org/u/krambriw)
#### Post date: [4 December 2018 16:05 UTC](https://discourse.nodered.org/t/quick-reminder-about-security-and-shared-flows/5477/3 "2018-12-04T16:05:33Z")

</div>

Looking at it after import I think is fine, what could be dangerous is to deploy.  
If you just interested and looking at various solutions, do a browser refresh when finished but do not deploy

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [5 December 2018 11:47 UTC](https://discourse.nodered.org/t/quick-reminder-about-security-and-shared-flows/5477/4 "2018-12-05T11:47:20Z")

</div>

Indeed, that would be absolutely fine.
