Togoder security

Go package security report

github.com/quagmt/udecimal@v1.10.1 security report

Risky patterns found that deserve a look.

Needs review Version v1.10.1 Files reviewed 6 Size 78.8 KB Scanned

Summary

Togoder Security scanned the Go package github.com/quagmt/udecimal@v1.10.1 on Oct 5, 2026. An AI review of 6 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
0
low

Findings 2

medium

Unsafe memory manipulation

NPS-D3101D0F8BDE

The function unsafeStringToBytes uses unsafe.Slice and unsafe.StringData to reinterpret a string's underlying bytes as a mutable []byte without copying. This violates Go's string immutability and could lead to memory corruption if the returned slice is modified. It is used in MarshalJSON to return a byte slice backed by a string, which is then returned to the caller. While not overtly malicious, this is a dangerous pattern that can cause undefined behavior and is generally considered a security risk.

codec.go:287
medium

Potential JSON output corruption

NPS-CA163AFFDDB9

In MarshalJSON, the result of d.stringU128(true, true) is converted to a []byte via unsafeStringToBytes. The string is built in appendBuffer with a fixed-size local buffer and then copied into a new slice. However, using unsafe to convert the string back to a byte slice means the returned byte slice shares memory with the string. If the caller modifies the byte slice, it would corrupt the string, though in practice the caller (json.Marshal) typically does not. Still, it is a fragile and risky pattern.

codec.go:295

Files reviewed

FileVerdictWhat the reviewer saw
codec.go medium The code contains unsafe memory manipulation via unsafe.Slice/unsafe.StringData, which is a risky but potentially performance-motivated pattern; no overt malicious behavior detected.
bint.go safe Cleared by Jev triage; no further analysis needed
decimal.go safe Cleared by Jev triage; no further analysis needed
doc.go safe Cleared by Jev triage; no further analysis needed
u128.go safe Cleared by Jev triage; no further analysis needed
u256.go safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is github.com/quagmt/udecimal safe to use?

No confirmed malware was found in github.com/quagmt/udecimal@v1.10.1, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.

Does github.com/quagmt/udecimal contain malware?

No malware was identified in github.com/quagmt/udecimal@v1.10.1 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/quagmt/udecimal checked?

Togoder Security downloaded the published Go package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/quagmt/udecimal together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/quagmt/udecimal@v1.10.1, cost nothing.

Related security reports