Togoder security

Go package security report

github.com/buger/jsonparser Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v1.6.1 Files reviewed 12 Size 110.9 KB Scanned

Summary

Togoder Security scanned the Go package github.com/buger/jsonparser@v1.6.1 on Oct 5, 2026. An AI review of 12 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

unsafe memory manipulation

NPS-28E4A5A1CEE4

The code uses the unsafe package to cast *[]byte to *string via unsafe.Pointer in equalStr, parseFloat, and bytesToString. This bypasses Go's type safety; if the input slice is mutated or deallocated concurrently, it can lead to memory corruption, data races, or undefined behavior.

bytes_unsafe.go:21
medium

unsafe reflect header manipulation

NPS-F045057C254C

StringToBytes creates a byte slice header pointing directly at the string's backing memory using reflect.StringHeader/SliceHeader and unsafe.Pointer, without copying. The resulting []byte is technically read-only but not marked as such; writing to it would cause a fatal error or crash, and the slice must not outlive the source string (mitigated only by runtime.KeepAlive).

bytes_unsafe.go:33
low

build tag syntax error

NPS-D823D0D83255

The build constraint // +build !appengine,!appenginevm, !tinygo has incorrect syntax (spaces after commas). Modern Go build constraints require comma-separated terms without spaces (e.g., !appengine,!appenginevm,!tinygo). This malformed tag may cause the file to be included or excluded unexpectedly depending on Go version, potentially leading to unsafe code being compiled in unintended environments.

bytes_unsafe.go:1

Files reviewed

FileVerdictWhat the reviewer saw
bytes_unsafe.go medium No malicious intent detected, but the file uses unsafe pointer and reflect header tricks that can cause memory safety issues if misused, and contains a malformed build tag.
aliases.go safe Cleared by Jev triage; no further analysis needed
append.go safe Cleared by Jev triage; no further analysis needed
bytes.go safe Cleared by Jev triage; no further analysis needed
bytes_safe.go safe Cleared by Jev triage; no further analysis needed
config.go safe Cleared by Jev triage; no further analysis needed
escape.go safe Cleared by Jev triage; no further analysis needed
fuzz.go safe Cleared by Jev triage; no further analysis needed
parser.go safe No malicious patterns detected; the code is a legitimate JSON parser implementation with standard parsing logic and no network, file system, process execution, or obfuscation concerns.
path_compiler.go safe Cleared by Jev triage; no further analysis needed
reader_parser.go safe No malicious patterns detected
wildcard.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/buger/jsonparser

VersionVerdictFilesScanned
v1.6.1 Needs review 12 Oct 5, 2026

Frequently asked questions

Is github.com/buger/jsonparser safe to use?

No confirmed malware was found in github.com/buger/jsonparser@v1.6.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/buger/jsonparser contain malware?

No malware was identified in github.com/buger/jsonparser@v1.6.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/buger/jsonparser checked?

Togoder Security downloaded the published Go package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/buger/jsonparser together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/buger/jsonparser@v1.6.1, cost nothing.

Related security reports