Summary
Togoder Security scanned the Go package github.com/buger/jsonparser@v1.6.1 on Oct 5, 2026. An AI review of 12 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
unsafe memory manipulation
NPS-28E4A5A1CEE4
The code uses the unsafe package to cast *[]byte to *string via unsafe.Pointer in equalStr, parseFloat, and bytesToString. This bypasses Go's type safety; if the input slice is mutated or deallocated concurrently, it can lead to memory corruption, data races, or undefined behavior.
unsafe reflect header manipulation
NPS-F045057C254C
StringToBytes creates a byte slice header pointing directly at the string's backing memory using reflect.StringHeader/SliceHeader and unsafe.Pointer, without copying. The resulting []byte is technically read-only but not marked as such; writing to it would cause a fatal error or crash, and the slice must not outlive the source string (mitigated only by runtime.KeepAlive).
build tag syntax error
NPS-D823D0D83255
The build constraint // +build !appengine,!appenginevm, !tinygo has incorrect syntax (spaces after commas). Modern Go build constraints require comma-separated terms without spaces (e.g., !appengine,!appenginevm,!tinygo). This malformed tag may cause the file to be included or excluded unexpectedly depending on Go version, potentially leading to unsafe code being compiled in unintended environments.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bytes_unsafe.go | medium | No malicious intent detected, but the file uses unsafe pointer and reflect header tricks that can cause memory safety issues if misused, and contains a malformed build tag. |
| aliases.go | safe | Cleared by Jev triage; no further analysis needed |
| append.go | safe | Cleared by Jev triage; no further analysis needed |
| bytes.go | safe | Cleared by Jev triage; no further analysis needed |
| bytes_safe.go | safe | Cleared by Jev triage; no further analysis needed |
| config.go | safe | Cleared by Jev triage; no further analysis needed |
| escape.go | safe | Cleared by Jev triage; no further analysis needed |
| fuzz.go | safe | Cleared by Jev triage; no further analysis needed |
| parser.go | safe | No malicious patterns detected; the code is a legitimate JSON parser implementation with standard parsing logic and no network, file system, process execution, or obfuscation concerns. |
| path_compiler.go | safe | Cleared by Jev triage; no further analysis needed |
| reader_parser.go | safe | No malicious patterns detected |
| wildcard.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is github.com/buger/jsonparser safe to use?
No confirmed malware was found in github.com/buger/jsonparser@v1.6.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/buger/jsonparser contain malware?
No malware was identified in github.com/buger/jsonparser@v1.6.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/buger/jsonparser checked?
Togoder Security downloaded the published Go package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/buger/jsonparser together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/buger/jsonparser@v1.6.1, cost nothing.