Togoder security

npm package security report

@paulmillr/qr@0.2.1 security report

Risky patterns found that deserve a look.

Needs review Version 0.2.1 Files reviewed 6 Size 161.8 KB Scanned

Summary

Togoder Security scanned the npm package @paulmillr/qr@0.2.1 on Oct 4, 2026. An AI review of 6 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Potentially misleading comment and variable naming

NPS-64A4A3FC50CE

The comment says 'Creates new QRCamera from frontal camera' but the code uses facingMode: 'environment' which requests the rear camera, not the front camera. This inconsistency could confuse users and may indicate careless code, but it is not a security vulnerability.

dom.js:228
low

Debug logging of MediaStream object

NPS-458B8B99104B

The frontalCamera function logs the entire MediaStream object to the console with console.log('TTT', stream). While not directly malicious, this could leak sensitive information about the user's camera stream (tracks, settings, device IDs) to the browser console, which could be exploited by other scripts or extensions.

dom.js:237
low

debugging/logging

NPS-FAE3202651DB

A console.log statement ('TTT', stream) logs the MediaStream object to console. This is likely leftover debug code, not malicious, but could leak information in production environments if the stream object contains sensitive metadata.

dom.ts

Files reviewed

FileVerdictWhat the reviewer saw
dom.js medium The code appears to be a legitimate DOM utility for QR code decoding from camera, with only minor concerns about debug logging and misleading comments; no malicious patterns detected.
decode.js safe No malicious patterns detected; the code is a legitimate QR code decoder library from a known author with no data exfiltration, network requests, or suspicious behaviors.
decode.ts safe No malicious patterns detected; the code is a legitimate QR code decoder implementation with no network, filesystem, process, or obfuscated code activities.
dom.ts safe No malicious patterns detected; the code is a legitimate QR code scanning utility with only minor debug logging concerns.
index.js safe Cleared by Jev triage; no further analysis needed
index.ts safe This is a legitimate QR code generation library by Paul Miller with no malicious patterns, no network activity, no file system access, no process spawning, and no obfuscated or dynamically executed code.

Frequently asked questions

Is @paulmillr/qr safe to use?

No confirmed malware was found in @paulmillr/qr@0.2.1, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does @paulmillr/qr contain malware?

No malware was identified in @paulmillr/qr@0.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @paulmillr/qr checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @paulmillr/qr together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @paulmillr/qr@0.2.1, cost nothing.

Related security reports