# github.com/buger/jsonparser@v1.6.1 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:08:26.000Z
- Files reviewed: 12
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/go/github.com/buger/jsonparser
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/buger/jsonparser@v1.6.1 on Oct 5, 2026. An AI review of 12 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] unsafe memory manipulation

Finding ID: `NPS-28E4A5A1CEE4`

File: `bytes_unsafe.go:21`

The code uses the unsafe package to cast *[]byte to *string via unsafe.Pointer in equalStr, parseFloat, and bytesToString. This bypasses Go's type safety; if the input slice is mutated or deallocated concurrently, it can lead to memory corruption, data races, or undefined behavior.

### [medium] unsafe reflect header manipulation

Finding ID: `NPS-F045057C254C`

File: `bytes_unsafe.go:33`

StringToBytes creates a byte slice header pointing directly at the string's backing memory using reflect.StringHeader/SliceHeader and unsafe.Pointer, without copying. The resulting []byte is technically read-only but not marked as such; writing to it would cause a fatal error or crash, and the slice must not outlive the source string (mitigated only by runtime.KeepAlive).

### [low] build tag syntax error

Finding ID: `NPS-D823D0D83255`

File: `bytes_unsafe.go:1`

The build constraint `// +build !appengine,!appenginevm, !tinygo` has incorrect syntax (spaces after commas). Modern Go build constraints require comma-separated terms without spaces (e.g., `!appengine,!appenginevm,!tinygo`). This malformed tag may cause the file to be included or excluded unexpectedly depending on Go version, potentially leading to unsafe code being compiled in unintended environments.

## Files reviewed

- `bytes_unsafe.go` (medium): No malicious intent detected, but the file uses unsafe pointer and reflect header tricks that can cause memory safety issues if misused, and contains a malformed build tag.
- `aliases.go` (safe): Cleared by Jev triage; no further analysis needed
- `append.go` (safe): Cleared by Jev triage; no further analysis needed
- `bytes.go` (safe): Cleared by Jev triage; no further analysis needed
- `bytes_safe.go` (safe): Cleared by Jev triage; no further analysis needed
- `config.go` (safe): Cleared by Jev triage; no further analysis needed
- `escape.go` (safe): Cleared by Jev triage; no further analysis needed
- `fuzz.go` (safe): Cleared by Jev triage; no further analysis needed
- `parser.go` (safe): No malicious patterns detected; the code is a legitimate JSON parser implementation with standard parsing logic and no network, file system, process execution, or obfuscation concerns.
- `path_compiler.go` (safe): Cleared by Jev triage; no further analysis needed
- `reader_parser.go` (safe): No malicious patterns detected
- `wildcard.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
