# @testing-library/dom@10.4.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:12:40.000Z
- Files reviewed: 29
- Findings: no findings
- Report: https://security.togoder.click/npm/@testing-library/dom
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @testing-library/dom@10.4.2 on Oct 6, 2026. An AI review of 29 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/@testing-library/dom.esm.js` (safe): No malicious patterns detected; the code is the legitimate @testing-library/dom ESM bundle with expected testing utilities and no data exfiltration, obfuscation, or unauthorized system access.
- `dist/DOMElementFilter.js` (safe): No malicious patterns detected; the file is a legitimate Jest pretty-format DOMElement plugin with only local string escaping and serialization logic.
- `dist/config.js` (safe): No malicious patterns detected
- `dist/event-map.js` (safe): No malicious patterns detected; this is a static event map configuration for testing library event handling.
- `dist/events.js` (safe): No malicious patterns detected; the code is a standard DOM event creation/firing utility with no exfiltration, code execution, or filesystem/network abuse.
- `dist/get-node-text.js` (safe): No malicious patterns detected
- `dist/get-queries-for-element.js` (safe): No malicious patterns detected
- `dist/get-user-code-frame.js` (safe): The code only reads local source files to generate helpful error code frames and does not exhibit any exfiltration, obfuscation, or suspicious behavior.
- `dist/helpers.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected
- `dist/label-helpers.js` (safe): No malicious patterns detected; the code is a standard accessibility helper for extracting label content from DOM elements.
- `dist/matches.js` (safe): No malicious patterns detected in the analyzed JavaScript file.
- `dist/pretty-dom.js` (safe): No malicious patterns detected; the code is a standard DOM pretty-printing utility from the @testing-library/dom package with only benign environment variable use for color configuration.
- `dist/queries/all-utils.js` (safe): No malicious patterns detected; the file is a standard Babel/TypeScript re-export helper that re-exports named exports from sibling modules without any I/O, network, process, or dynamic execution behavior.
- `dist/queries/alt-text.js` (safe): No malicious patterns detected; this is a standard Testing Library alt text query implementation with only local module imports and DOM querying logic.
- `dist/queries/display-value.js` (safe): No malicious patterns detected; the file contains standard DOM query helper functions with no network, filesystem, process execution, or obfuscated code.
- `dist/queries/index.js` (safe): No malicious patterns detected; the file contains standard ES module re-export logic for query helpers.
- `dist/queries/label-text.js` (safe): No malicious patterns detected
- `dist/queries/placeholder-text.js` (safe): No malicious patterns detected; the file contains standard testing-library query helpers for placeholder text with no network, filesystem, process, or dynamic execution activity.
- `dist/queries/role.js` (safe): No malicious patterns detected; this is a legitimate DOM testing-library role query module with no network, filesystem, process, or dynamic execution behavior.
- `dist/queries/test-id.js` (safe): No malicious patterns detected; this is a standard testing-library query file that only uses internal requires and no network, filesystem, process, or credential access.
- `dist/queries/text.js` (safe): No malicious patterns detected; the code is a standard DOM text query utility from a testing library with no external data transmission, credential access, dynamic execution, or process spawning.
- `dist/queries/title.js` (safe): No malicious patterns detected; the code is a standard DOM query helper for finding elements by title attribute.
- `dist/query-helpers.js` (safe): No malicious patterns detected in this query helper module; it only contains DOM querying and error message utilities from the testing-library ecosystem.
- `dist/role-helpers.js` (safe): No malicious patterns detected; the code is a legitimate accessibility helper library using standard DOM APIs and dependencies.
- `dist/screen.js` (safe): No malicious patterns detected; the code is a standard testing-library screen module with only benign external URL generation and logging.
- `dist/suggestions.js` (safe): No malicious patterns detected
- `dist/wait-for-element-to-be-removed.js` (safe): No malicious patterns detected; this is a legitimate DOM testing utility from Testing Library that waits for elements to be removed.
- `dist/wait-for.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
