Summary
Togoder Security scanned the npm package @testing-library/dom@10.4.2 on Oct 6, 2026. An AI review of 29 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/@testing-library/dom.esm.js | safe | No malicious patterns detected; the code is the legitimate @testing-library/dom ESM bundle with expected testing utilities and no data exfiltration, obfuscation, or unauthorized system access. |
| dist/DOMElementFilter.js | safe | No malicious patterns detected; the file is a legitimate Jest pretty-format DOMElement plugin with only local string escaping and serialization logic. |
| dist/config.js | safe | No malicious patterns detected |
| dist/event-map.js | safe | No malicious patterns detected; this is a static event map configuration for testing library event handling. |
| dist/events.js | safe | No malicious patterns detected; the code is a standard DOM event creation/firing utility with no exfiltration, code execution, or filesystem/network abuse. |
| dist/get-node-text.js | safe | No malicious patterns detected |
| dist/get-queries-for-element.js | safe | No malicious patterns detected |
| dist/get-user-code-frame.js | safe | The code only reads local source files to generate helpful error code frames and does not exhibit any exfiltration, obfuscation, or suspicious behavior. |
| dist/helpers.js | safe | No malicious patterns detected |
| dist/index.js | safe | No malicious patterns detected |
| dist/label-helpers.js | safe | No malicious patterns detected; the code is a standard accessibility helper for extracting label content from DOM elements. |
| dist/matches.js | safe | No malicious patterns detected in the analyzed JavaScript file. |
| dist/pretty-dom.js | safe | No malicious patterns detected; the code is a standard DOM pretty-printing utility from the @testing-library/dom package with only benign environment variable use for color configuration. |
| dist/queries/all-utils.js | safe | No malicious patterns detected; the file is a standard Babel/TypeScript re-export helper that re-exports named exports from sibling modules without any I/O, network, process, or dynamic execution behavior. |
| dist/queries/alt-text.js | safe | No malicious patterns detected; this is a standard Testing Library alt text query implementation with only local module imports and DOM querying logic. |
| dist/queries/display-value.js | safe | No malicious patterns detected; the file contains standard DOM query helper functions with no network, filesystem, process execution, or obfuscated code. |
| dist/queries/index.js | safe | No malicious patterns detected; the file contains standard ES module re-export logic for query helpers. |
| dist/queries/label-text.js | safe | No malicious patterns detected |
| dist/queries/placeholder-text.js | safe | No malicious patterns detected; the file contains standard testing-library query helpers for placeholder text with no network, filesystem, process, or dynamic execution activity. |
| dist/queries/role.js | safe | No malicious patterns detected; this is a legitimate DOM testing-library role query module with no network, filesystem, process, or dynamic execution behavior. |
| dist/queries/test-id.js | safe | No malicious patterns detected; this is a standard testing-library query file that only uses internal requires and no network, filesystem, process, or credential access. |
| dist/queries/text.js | safe | No malicious patterns detected; the code is a standard DOM text query utility from a testing library with no external data transmission, credential access, dynamic execution, or process spawning. |
| dist/queries/title.js | safe | No malicious patterns detected; the code is a standard DOM query helper for finding elements by title attribute. |
| dist/query-helpers.js | safe | No malicious patterns detected in this query helper module; it only contains DOM querying and error message utilities from the testing-library ecosystem. |
| dist/role-helpers.js | safe | No malicious patterns detected; the code is a legitimate accessibility helper library using standard DOM APIs and dependencies. |
Show 4 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/screen.js | safe | No malicious patterns detected; the code is a standard testing-library screen module with only benign external URL generation and logging. |
| dist/suggestions.js | safe | No malicious patterns detected |
| dist/wait-for-element-to-be-removed.js | safe | No malicious patterns detected; this is a legitimate DOM testing utility from Testing Library that waits for elements to be removed. |
| dist/wait-for.js | safe | No malicious patterns detected |
Frequently asked questions
Is @testing-library/dom safe to use?
Our AI source review of @testing-library/dom@10.4.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @testing-library/dom contain malware?
No malware was identified in @testing-library/dom@10.4.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @testing-library/dom checked?
Togoder Security downloaded the published npm package and had an AI model read its 29 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @testing-library/dom together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @testing-library/dom@10.4.2, cost nothing.