Summary
Togoder Security scanned the npm package @next/eslint-plugin-next@16.3.8 on Oct 6, 2026. An AI review of 27 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 1
File system enumeration via user-controlled glob
NPS-B38991888EF4
The ESLint setting settings.next.rootDir is read from configuration and passed directly into fast-glob's globSync. When an attacker can influence ESLint config (e.g., via a malicious repository or shared config), this can be used to enumerate directories outside the intended project scope (e.g., using patterns like '../*' or absolute paths) and potentially leak directory structure through rule behavior. This is a configuration-driven filesystem read, but not a direct exfiltration path on its own.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/utils/get-root-dirs.js | medium | The utility only performs user-configuration-driven directory globbing with fast-glob; it contains no obvious malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning, though the unsanitized rootDir setting could allow out-of-scope directory enumeration if config is attacker-controlled. |
| dist/index.js | safe | No malicious patterns detected; this is the legitimate Next.js ESLint plugin index file with only rule imports and configuration exports. |
| dist/rules/google-font-display.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation for enforcing font-display behavior in Google Fonts links. |
| dist/rules/google-font-preconnect.js | safe | No malicious patterns detected; the code is a benign ESLint rule that checks for missing rel="preconnect" on Google Fonts link elements. |
| dist/rules/inline-script-id.js | safe | No malicious patterns detected; the file defines an ESLint rule for Next.js inline script IDs without any exfiltration, credential harvesting, obfuscation, or execution-at-import-time behavior. |
| dist/rules/next-script-for-ga.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation for Next.js that inspects JSX script tags for Google Analytics/Tag Manager usage. |
| dist/rules/no-assign-module-variable.js | safe | No malicious patterns detected; the file is a benign ESLint rule implementation for preventing assignment to the module variable. |
| dist/rules/no-async-client-component.js | safe | No malicious patterns detected; this is a standard ESLint rule definition that checks for async client components. |
| dist/rules/no-before-interactive-script-outside-document.js | safe | This is a standard ESLint rule implementation from Next.js that checks for beforeInteractive script usage outside _document.js, with no malicious patterns detected. |
| dist/rules/no-css-tags.js | safe | No malicious patterns detected; the file is a benign ESLint rule implementation from Next.js. |
| dist/rules/no-document-import-in-page.js | safe | No malicious patterns detected |
| dist/rules/no-duplicate-head.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation that statically analyzes AST for duplicate <Head> usage without any suspicious behavior. |
| dist/rules/no-head-element.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation with no external network, filesystem, or process activity. |
| dist/rules/no-head-import-in-document.js | safe | This is a standard ESLint rule definition for Next.js that checks for disallowed next/head imports in pages/_document.js with no malicious patterns. |
| dist/rules/no-html-link-for-pages.js | safe | No malicious patterns detected; this is a legitimate ESLint rule from Next.js that reads filesystem paths and inspects JSX for internal link usage without any exfiltration, exec, or suspicious behavior. |
| dist/rules/no-img-element.js | safe | No malicious patterns detected; the file is a standard ESLint rule from Next.js that warns against using <img> elements for performance reasons. |
| dist/rules/no-location-assign-relative-destination.js | safe | No malicious patterns detected; this is a standard ESLint rule implementation for Next.js that analyzes AST nodes for relative URL navigation patterns. |
| dist/rules/no-page-custom-font.js | safe | No malicious patterns detected; this is a legitimate ESLint rule implementation for Next.js that checks for page-only custom fonts without any data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/rules/no-script-component-in-head.js | safe | This is a standard ESLint rule implementation for Next.js that checks for next/script usage inside next/head components; it contains no malicious patterns, network requests, code execution, or filesystem access. |
| dist/rules/no-styled-jsx-in-document.js | safe | No malicious patterns detected; the file is a legitimate ESLint rule implementation for Next.js with no network, filesystem, or code execution concerns. |
| dist/rules/no-sync-scripts.js | safe | No malicious patterns detected |
| dist/rules/no-title-in-document-head.js | safe | This is a benign ESLint rule from Next.js that prevents using <title> in next/document Head component, with no malicious patterns detected. |
| dist/rules/no-typos.js | safe | This file is a standard ESLint rule implementation from the eslint-plugin-next package; it contains no malicious patterns, network activity, credential access, or dynamic code execution. |
| dist/rules/no-unwanted-polyfillio.js | safe | No malicious patterns detected; the code is a benign ESLint rule that flags unwanted Polyfill.io imports. |
| dist/utils/define-rule.js | safe | No malicious patterns detected |
Show 2 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/utils/node-attributes.js | safe | No malicious patterns detected; the code only extracts JSX attribute metadata from AST nodes. |
| dist/utils/url.js | safe | No malicious patterns detected; the code only performs local filesystem directory reading and URL normalization without any network, credential, or process execution activity. |
Scanned versions of @next/eslint-plugin-next
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 16.3.8 | Needs review | 27 | Oct 6, 2026 |
Frequently asked questions
Is @next/eslint-plugin-next safe to use?
No confirmed malware was found in @next/eslint-plugin-next@16.3.8, but the review flagged 1 low severity finding for risky patterns worth checking before you rely on it.
Does @next/eslint-plugin-next contain malware?
No malware was identified in @next/eslint-plugin-next@16.3.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @next/eslint-plugin-next checked?
Togoder Security downloaded the published npm package and had an AI model read its 27 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @next/eslint-plugin-next together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @next/eslint-plugin-next@16.3.8, cost nothing.