Togoder security

npm package security report

@next/eslint-plugin-next@16.3.8 security report

Risky patterns found that deserve a look.

Needs review Version 16.3.8 Files reviewed 27 Size 96.8 KB Scanned

Summary

Togoder Security scanned the npm package @next/eslint-plugin-next@16.3.8 on Oct 6, 2026. An AI review of 27 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
1
low

Findings 1

low

File system enumeration via user-controlled glob

NPS-B38991888EF4

The ESLint setting settings.next.rootDir is read from configuration and passed directly into fast-glob's globSync. When an attacker can influence ESLint config (e.g., via a malicious repository or shared config), this can be used to enumerate directories outside the intended project scope (e.g., using patterns like '../*' or absolute paths) and potentially leak directory structure through rule behavior. This is a configuration-driven filesystem read, but not a direct exfiltration path on its own.

dist/utils/get-root-dirs.js:15

Files reviewed

FileVerdictWhat the reviewer saw
dist/utils/get-root-dirs.js medium The utility only performs user-configuration-driven directory globbing with fast-glob; it contains no obvious malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning, though the unsanitized rootDir setting could allow out-of-scope directory enumeration if config is attacker-controlled.
dist/index.js safe No malicious patterns detected; this is the legitimate Next.js ESLint plugin index file with only rule imports and configuration exports.
dist/rules/google-font-display.js safe No malicious patterns detected; the file is a standard ESLint rule implementation for enforcing font-display behavior in Google Fonts links.
dist/rules/google-font-preconnect.js safe No malicious patterns detected; the code is a benign ESLint rule that checks for missing rel="preconnect" on Google Fonts link elements.
dist/rules/inline-script-id.js safe No malicious patterns detected; the file defines an ESLint rule for Next.js inline script IDs without any exfiltration, credential harvesting, obfuscation, or execution-at-import-time behavior.
dist/rules/next-script-for-ga.js safe No malicious patterns detected; the code is a standard ESLint rule implementation for Next.js that inspects JSX script tags for Google Analytics/Tag Manager usage.
dist/rules/no-assign-module-variable.js safe No malicious patterns detected; the file is a benign ESLint rule implementation for preventing assignment to the module variable.
dist/rules/no-async-client-component.js safe No malicious patterns detected; this is a standard ESLint rule definition that checks for async client components.
dist/rules/no-before-interactive-script-outside-document.js safe This is a standard ESLint rule implementation from Next.js that checks for beforeInteractive script usage outside _document.js, with no malicious patterns detected.
dist/rules/no-css-tags.js safe No malicious patterns detected; the file is a benign ESLint rule implementation from Next.js.
dist/rules/no-document-import-in-page.js safe No malicious patterns detected
dist/rules/no-duplicate-head.js safe No malicious patterns detected; the code is a standard ESLint rule implementation that statically analyzes AST for duplicate <Head> usage without any suspicious behavior.
dist/rules/no-head-element.js safe No malicious patterns detected; the code is a standard ESLint rule implementation with no external network, filesystem, or process activity.
dist/rules/no-head-import-in-document.js safe This is a standard ESLint rule definition for Next.js that checks for disallowed next/head imports in pages/_document.js with no malicious patterns.
dist/rules/no-html-link-for-pages.js safe No malicious patterns detected; this is a legitimate ESLint rule from Next.js that reads filesystem paths and inspects JSX for internal link usage without any exfiltration, exec, or suspicious behavior.
dist/rules/no-img-element.js safe No malicious patterns detected; the file is a standard ESLint rule from Next.js that warns against using <img> elements for performance reasons.
dist/rules/no-location-assign-relative-destination.js safe No malicious patterns detected; this is a standard ESLint rule implementation for Next.js that analyzes AST nodes for relative URL navigation patterns.
dist/rules/no-page-custom-font.js safe No malicious patterns detected; this is a legitimate ESLint rule implementation for Next.js that checks for page-only custom fonts without any data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/rules/no-script-component-in-head.js safe This is a standard ESLint rule implementation for Next.js that checks for next/script usage inside next/head components; it contains no malicious patterns, network requests, code execution, or filesystem access.
dist/rules/no-styled-jsx-in-document.js safe No malicious patterns detected; the file is a legitimate ESLint rule implementation for Next.js with no network, filesystem, or code execution concerns.
dist/rules/no-sync-scripts.js safe No malicious patterns detected
dist/rules/no-title-in-document-head.js safe This is a benign ESLint rule from Next.js that prevents using <title> in next/document Head component, with no malicious patterns detected.
dist/rules/no-typos.js safe This file is a standard ESLint rule implementation from the eslint-plugin-next package; it contains no malicious patterns, network activity, credential access, or dynamic code execution.
dist/rules/no-unwanted-polyfillio.js safe No malicious patterns detected; the code is a benign ESLint rule that flags unwanted Polyfill.io imports.
dist/utils/define-rule.js safe No malicious patterns detected
Show 2 more files
FileVerdictWhat the reviewer saw
dist/utils/node-attributes.js safe No malicious patterns detected; the code only extracts JSX attribute metadata from AST nodes.
dist/utils/url.js safe No malicious patterns detected; the code only performs local filesystem directory reading and URL normalization without any network, credential, or process execution activity.

Frequently asked questions

Is @next/eslint-plugin-next safe to use?

No confirmed malware was found in @next/eslint-plugin-next@16.3.8, but the review flagged 1 low severity finding for risky patterns worth checking before you rely on it.

Does @next/eslint-plugin-next contain malware?

No malware was identified in @next/eslint-plugin-next@16.3.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @next/eslint-plugin-next checked?

Togoder Security downloaded the published npm package and had an AI model read its 27 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @next/eslint-plugin-next together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @next/eslint-plugin-next@16.3.8, cost nothing.

Related security reports