# @next/eslint-plugin-next@16.3.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:17.000Z
- Files reviewed: 27
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@next/eslint-plugin-next
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @next/eslint-plugin-next@16.3.8 on Oct 6, 2026. An AI review of 27 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] File system enumeration via user-controlled glob

Finding ID: `NPS-B38991888EF4`

File: `dist/utils/get-root-dirs.js:15`

The ESLint setting `settings.next.rootDir` is read from configuration and passed directly into fast-glob's globSync. When an attacker can influence ESLint config (e.g., via a malicious repository or shared config), this can be used to enumerate directories outside the intended project scope (e.g., using patterns like '../*' or absolute paths) and potentially leak directory structure through rule behavior. This is a configuration-driven filesystem read, but not a direct exfiltration path on its own.

## Files reviewed

- `dist/utils/get-root-dirs.js` (medium): The utility only performs user-configuration-driven directory globbing with fast-glob; it contains no obvious malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning, though the unsanitized rootDir setting could allow out-of-scope directory enumeration if config is attacker-controlled.
- `dist/index.js` (safe): No malicious patterns detected; this is the legitimate Next.js ESLint plugin index file with only rule imports and configuration exports.
- `dist/rules/google-font-display.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation for enforcing font-display behavior in Google Fonts links.
- `dist/rules/google-font-preconnect.js` (safe): No malicious patterns detected; the code is a benign ESLint rule that checks for missing rel="preconnect" on Google Fonts link elements.
- `dist/rules/inline-script-id.js` (safe): No malicious patterns detected; the file defines an ESLint rule for Next.js inline script IDs without any exfiltration, credential harvesting, obfuscation, or execution-at-import-time behavior.
- `dist/rules/next-script-for-ga.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation for Next.js that inspects JSX script tags for Google Analytics/Tag Manager usage.
- `dist/rules/no-assign-module-variable.js` (safe): No malicious patterns detected; the file is a benign ESLint rule implementation for preventing assignment to the `module` variable.
- `dist/rules/no-async-client-component.js` (safe): No malicious patterns detected; this is a standard ESLint rule definition that checks for async client components.
- `dist/rules/no-before-interactive-script-outside-document.js` (safe): This is a standard ESLint rule implementation from Next.js that checks for beforeInteractive script usage outside _document.js, with no malicious patterns detected.
- `dist/rules/no-css-tags.js` (safe): No malicious patterns detected; the file is a benign ESLint rule implementation from Next.js.
- `dist/rules/no-document-import-in-page.js` (safe): No malicious patterns detected
- `dist/rules/no-duplicate-head.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation that statically analyzes AST for duplicate <Head> usage without any suspicious behavior.
- `dist/rules/no-head-element.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation with no external network, filesystem, or process activity.
- `dist/rules/no-head-import-in-document.js` (safe): This is a standard ESLint rule definition for Next.js that checks for disallowed `next/head` imports in `pages/_document.js` with no malicious patterns.
- `dist/rules/no-html-link-for-pages.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule from Next.js that reads filesystem paths and inspects JSX for internal link usage without any exfiltration, exec, or suspicious behavior.
- `dist/rules/no-img-element.js` (safe): No malicious patterns detected; the file is a standard ESLint rule from Next.js that warns against using `<img>` elements for performance reasons.
- `dist/rules/no-location-assign-relative-destination.js` (safe): No malicious patterns detected; this is a standard ESLint rule implementation for Next.js that analyzes AST nodes for relative URL navigation patterns.
- `dist/rules/no-page-custom-font.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule implementation for Next.js that checks for page-only custom fonts without any data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/rules/no-script-component-in-head.js` (safe): This is a standard ESLint rule implementation for Next.js that checks for `next/script` usage inside `next/head` components; it contains no malicious patterns, network requests, code execution, or filesystem access.
- `dist/rules/no-styled-jsx-in-document.js` (safe): No malicious patterns detected; the file is a legitimate ESLint rule implementation for Next.js with no network, filesystem, or code execution concerns.
- `dist/rules/no-sync-scripts.js` (safe): No malicious patterns detected
- `dist/rules/no-title-in-document-head.js` (safe): This is a benign ESLint rule from Next.js that prevents using <title> in next/document Head component, with no malicious patterns detected.
- `dist/rules/no-typos.js` (safe): This file is a standard ESLint rule implementation from the eslint-plugin-next package; it contains no malicious patterns, network activity, credential access, or dynamic code execution.
- `dist/rules/no-unwanted-polyfillio.js` (safe): No malicious patterns detected; the code is a benign ESLint rule that flags unwanted Polyfill.io imports.
- `dist/utils/define-rule.js` (safe): No malicious patterns detected
- `dist/utils/node-attributes.js` (safe): No malicious patterns detected; the code only extracts JSX attribute metadata from AST nodes.
- `dist/utils/url.js` (safe): No malicious patterns detected; the code only performs local filesystem directory reading and URL normalization without any network, credential, or process execution activity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
