# @panva/hkdf@1.2.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:11:25.000Z
- Files reviewed: 8
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@panva/hkdf
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @panva/hkdf@1.2.1 on Oct 6, 2026. An AI review of 8 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] cryptographic_function

Finding ID: `NPS-BFE803BB2387`

File: `dist/node/esm/runtime/fallback.js`

This file implements HKDF (HMAC-based Key Derivation Function) using Node.js crypto's createHmac. It performs standard key derivation operations, hashing input key material with a salt and info parameter. No external communication, environment access, obfuscation, file system manipulation, process spawning, or dynamic imports are present. This is a legitimate cryptographic utility.

## Files reviewed

- `dist/node/cjs/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/cjs/runtime/fallback.js` (safe): No malicious patterns detected; the code implements HKDF key derivation using Node.js crypto and performs no network, filesystem, process, or dynamic code execution.
- `dist/node/cjs/runtime/hkdf.js` (safe): No malicious patterns detected; the file implements a standard HKDF key derivation wrapper with a fallback, using only Node.js crypto APIs and no external network, filesystem, or process operations.
- `dist/node/esm/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node/esm/runtime/fallback.js` (safe): Legitimate HKDF key derivation implementation using crypto.createHmac with no malicious patterns detected.
- `dist/node/esm/runtime/hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/web/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/web/runtime/hkdf.js` (safe): No malicious patterns detected; the code implements standard HKDF key derivation using the Web Crypto API.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
