# @testing-library/jest-dom@7.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:49.000Z
- Files reviewed: 13
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@testing-library/jest-dom
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @testing-library/jest-dom@7.0.1 on Oct 6, 2026. An AI review of 13 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Top-level code execution on import

Finding ID: `NPS-DC31C93CD3F0`

File: `dist/index.mjs:9`

The module calls expect.extend(extensions) at the top level. This executes immediately when the file is imported, mutating the global expect object. While this is typical behavior for a Jest matcher package, it is still top-level side-effect code that runs on import and could be abused in a malicious package. No data exfiltration, credential harvesting, obfuscation, network requests, process spawning, or dynamic code execution is present.

## Files reviewed

- `dist/index.mjs` (medium): The file is a standard Jest matcher entry point with a top-level expect.extend call and no malicious patterns observed.
- `dist/index.js` (safe): No malicious patterns detected; the file is a simple entry point that imports matchers and testing-library dependencies and registers custom matchers.
- `dist/jest-globals.js` (safe): No malicious patterns detected; the file only imports dependencies and extends Jest matchers.
- `dist/jest-globals.mjs` (safe): No malicious patterns detected; the file only imports Jest globals and extends matchers at import time.
- `dist/matchers-3ed9c960.js` (safe): No malicious patterns detected; the code is a legitimate testing-library matcher bundle with standard DOM utility imports and no suspicious network, filesystem, or process activity.
- `dist/matchers-b01dabb1.mjs` (safe): This is a standard build artifact of jest-dom matchers, containing only legitimate DOM testing utilities with no network, filesystem, process, or obfuscated code.
- `dist/matchers.js` (safe): No malicious patterns detected; the file is a standard re-export module for @testing-library/jest-dom matchers with no suspicious code execution, network, or filesystem activity.
- `dist/matchers.mjs` (safe): This file only re-exports matchers from an internal module and imports dependencies; no malicious patterns detected.
- `dist/vitest.js` (safe): No malicious patterns detected
- `dist/vitest.mjs` (safe): No malicious patterns detected
- `jest-globals.js` (safe): No malicious patterns detected; the file simply imports Jest globals and a local matchers module, then extends expect with the matchers.
- `matchers.js` (safe): Cleared by Jev triage; no further analysis needed
- `vitest.js` (safe): No malicious patterns detected; the file only imports Vitest and registers custom matchers from a local module.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
