# @scure/bip39@1.5.4 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:09:56.000Z
- Files reviewed: 23
- Findings: no findings
- Report: https://security.togoder.click/npm/@scure/bip39@1.5.4
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @scure/bip39@1.5.4 on Oct 4, 2026. An AI review of 23 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `esm/index.js` (safe): No malicious patterns detected; the code is a legitimate BIP39 mnemonic implementation using standard cryptographic primitives without exfiltration, obfuscation, or suspicious behavior.
- `esm/wordlists/czech.js` (safe): No malicious patterns detected
- `esm/wordlists/english.js` (safe): No malicious patterns detected; the file only exports a static list of English words with no network, filesystem, process, or dynamic code execution behavior.
- `esm/wordlists/french.js` (safe): No malicious patterns detected
- `esm/wordlists/italian.js` (safe): This file contains only a static exported array of Italian words with no executable code, network calls, or other malicious patterns.
- `esm/wordlists/japanese.js` (safe): No malicious patterns detected
- `esm/wordlists/korean.js` (safe): No malicious patterns detected
- `esm/wordlists/portuguese.js` (safe): The file contains only a hardcoded Portuguese wordlist and no executable or malicious code.
- `esm/wordlists/simplified-chinese.js` (safe): The file contains only a static list of Simplified Chinese words with no executable code or malicious patterns.
- `esm/wordlists/spanish.js` (safe): This file contains only a static Spanish wordlist with no executable code, network requests, or other malicious patterns.
- `esm/wordlists/traditional-chinese.js` (safe): No malicious patterns detected; the file contains only a static string list of common Chinese characters used as a wordlist.
- `index.js` (safe): No malicious patterns detected in this BIP39 mnemonic implementation; it uses standard cryptographic dependencies and contains no data exfiltration, obfuscation, or suspicious behavior.
- `src/index.ts` (safe): No malicious patterns detected; the code is a standard BIP39 mnemonic implementation with no network, filesystem, process, or obfuscation concerns.
- `wordlists/czech.js` (safe): No malicious patterns detected
- `wordlists/english.js` (safe): The file contains only a static English wordlist exported as a string array, with no executable code, network activity, or malicious patterns.
- `wordlists/french.js` (safe): No malicious patterns detected
- `wordlists/italian.js` (safe): No malicious patterns detected
- `wordlists/japanese.js` (safe): No malicious patterns detected
- `wordlists/korean.js` (safe): No malicious patterns detected; the file only exports a static Korean wordlist string with no code execution or external interaction.
- `wordlists/portuguese.js` (safe): No malicious patterns detected
- `wordlists/simplified-chinese.js` (safe): No malicious patterns detected; the file only exports a static string containing a list of Chinese words.
- `wordlists/spanish.js` (safe): No malicious patterns detected; the file only exports a static wordlist of Spanish words and contains no executable or suspicious code.
- `wordlists/traditional-chinese.js` (safe): No malicious patterns detected; the file only exports a static list of traditional Chinese words as a string.

## Version ranges

None of the 3 scanned versions of @scure/bip39 are flagged high or critical. The latest scanned version, 1.6.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.3.0 – 1.6.0 (`>=1.3.0 <=1.6.0`): clean

## Scanned versions

- [1.6.0](https://security.togoder.click/npm/@scure/bip39@1.6.0): safe, 2026-10-04T16:16:34.000Z
- [1.5.4](https://security.togoder.click/npm/@scure/bip39@1.5.4): safe, 2026-10-04T16:09:56.000Z
- [1.3.0](https://security.togoder.click/npm/@scure/bip39@1.3.0): safe, 2026-10-04T16:30:12.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
