# @octokit/plugin-throttling@11.0.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:23.000Z
- Files reviewed: 6
- Findings: 1 medium severity finding
- Report: https://security.togoder.click/npm/@octokit/plugin-throttling
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @octokit/plugin-throttling@11.0.3 on Oct 6, 2026. An AI review of 6 source files produced 1 medium severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] ReDoS (Regular Expression Denial of Service)

Finding ID: `NPS-07907DCC9F87`

File: `dist-src/route-matcher.js`

The routeMatcher function builds a regular expression from user-controlled paths. The pattern `(?:.+?)` inserted for each `{...}` segment, combined with nested non-capturing groups and alternation, can lead to catastrophic backtracking on crafted inputs, potentially causing excessive CPU usage and denial of service.

## Files reviewed

- `dist-src/route-matcher.js` (medium): The code is not malicious, but it constructs regexes from external input in a way that can cause ReDoS.
- `dist-bundle/index.js` (safe): No malicious patterns detected; the code is a legitimate Octokit throttling plugin with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `dist-src/generated/triggers-notification-paths.js` (safe): No malicious patterns detected; the file contains only a static array of GitHub API notification path templates with no executable, network, or file-system behavior.
- `dist-src/index.js` (safe): No malicious patterns detected; code implements GitHub API throttling with expected Bottleneck usage and no exfiltration, credential harvesting, or dynamic execution.
- `dist-src/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist-src/wrap-request.js` (safe): No malicious patterns detected; the code implements rate-limiting/retry logic for GitHub API requests without exfiltration, credential harvesting, obfuscation, or process execution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
