# @asamuzakjp/dom-selector@9.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:10:44.000Z
- Files reviewed: 15
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@asamuzakjp/dom-selector
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @asamuzakjp/dom-selector@9.2.1 on Oct 6, 2026. An AI review of 15 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-655C1DE89062`

File: `src/js/nwsapi.js`

The `compile` method uses `Function()` constructor to generate executable selector-matching functions from string-built source. While this is the core design of nwsapi and mirrors the upstream library's behavior, using `new Function` with dynamically assembled strings is inherently risky because it relies on strict input sanitization (via `#reValidator` regex) to prevent code injection. If the selector validation regex is bypassed or flawed, arbitrary JavaScript could be injected into the generated function body. The selector strings are also used to build regexes and concatenated into source code in multiple places (compileId, compileClass, compileAttribute), increasing the attack surface.

### [medium] Potential ReDoS in regex validation

Finding ID: `NPS-A10E227D6BE4`

File: `src/js/nwsapi.js`

The selector parser uses multiple complex regular expressions with nested quantifiers and backreferences (e.g., `#reValidator`, `REX.splitGroup`, `REX.commaGroup`, patterns for attributes/pseudos with `(?:...)*?` and `{0,255}` bounds). These are used against user-supplied selector strings. Although the library includes length bounds (e.g., `{0,255}`), such patterns have historically been vulnerable to catastrophic backtracking with crafted inputs, potentially causing denial of service.

### [low] DOM API usage / dynamic HTML query

Finding ID: `NPS-689E6BA633F4`

File: `src/js/nwsapi.js`

The `:has()` pseudo-class handling directly interpolates the parsed expression into `e.querySelector(":scope ${escapedExpr}")`. If the escaping (backslash and quote escaping) is insufficient against certain selector strings, this could lead to unexpected DOM query behavior. It does not execute code, but it is a dynamic string-to-DOM-query path worth noting.

## Files reviewed

- `src/js/nwsapi.js` (medium): The file is a fork of the nwsapi CSS selector engine that uses `new Function` to compile selectors and complex regex-based parsing, which are inherent risk factors but consistent with the upstream library's design; no exfiltration, credential harvesting, network calls, or process spawning were found.
- `src/index.js` (safe): No malicious patterns detected; the code is a legitimate CSS selector engine with no exfiltration, obfuscation, or suspicious behavior.
- `src/js/constant.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/evaluator.js` (safe): No malicious patterns detected; the code implements a standard CSS selector evaluator with no external network, filesystem, process, or dynamic code execution activity.
- `src/js/event.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/finder.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/mapper.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/matcher.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/parser.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/processor.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/pseudo-class.js` (safe): No malicious patterns detected; the file is a legitimate CSS pseudo-class evaluator with no network, filesystem, process, or obfuscated code concerns.
- `src/js/selector.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/shadow.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/traverser.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/js/utility.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
