Togoder security

npm package security report

@testing-library/user-event@14.6.7 security report

Risky patterns found that deserve a look.

Needs review Version 14.6.7 Files reviewed 202 Size 369.3 KB Scanned

Summary

Togoder Security scanned the npm package @testing-library/user-event@14.6.7 on Oct 6, 2026. An AI review of 202 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
8
low

Findings 9

medium

Prototype Pollution / Monkey Patching

NPS-7002B840A57E

The code modifies the global HTMLElement.prototype by overriding the focus and blur methods. This is a form of monkey patching that can affect all elements in the application, potentially leading to unexpected behavior or security issues if not properly scoped. While this appears to be part of a testing library (likely @testing-library/user-event), such global modifications can have side effects.

dist/cjs/document/patchFocus.js:8
low

Dynamic Code Execution via Symbol

NPS-279209A6DEFF

The code uses a Symbol('patched focus/blur methods') to mark patched prototypes and stores original methods. While not directly malicious, this technique could be used to hide modifications or bypass detection. However, in this context, it seems to be used for legitimate restoration purposes.

dist/cjs/document/patchFocus.js:6
low

Event Dispatch Manipulation

NPS-648F99781EF2

The patched methods manually dispatch DOM events (blur, focusout, focus, focusin) with custom relatedTarget values. This could be used to trigger unintended event handlers or bypass event-based security checks if the library is used in a production environment. However, this is likely intended for testing purposes.

dist/cjs/document/patchFocus.js:45
low

Clipboard API interception

NPS-2F7800AF0E86

attachClipboardStubToView replaces navigator.clipboard with a stub that stores items in memory and read/writeText/readText operate on that stub. This design is intended for testing but constitutes clipboard data interception if invoked unexpectedly, and could be abused to capture or alter clipboard contents in a controlled page context.

dist/cjs/utils/dataTransfer/Clipboard.js:120
low

Global object prototype/navigator property manipulation

NPS-7A1ED9BAF146

The code defines and overrides window.navigator.clipboard using Object.defineProperty with a getter, and writes to window.navigator. This is an intentional stubbing mechanism for testing, but it modifies a sensitive browser API surface at runtime. If used outside tests, it could intercept clipboard reads/writes.

dist/cjs/utils/dataTransfer/Clipboard.js:138
low

Top-level code execution on import

NPS-D5C7CC8AF5B0

The module registers top-level hooks on globalThis.afterEach and globalThis.afterAll if they exist. While these are typical test framework hooks that merely reset/detach the clipboard stub, they still execute code automatically upon import in any environment that defines these globals, which is a behavior worth noting for supply-chain analysis.

dist/cjs/utils/dataTransfer/Clipboard.js:176
low

Import-time side effects

NPS-00B824F6A3A3

The module imports '../utils/dataTransfer/Clipboard.js' and '@testing-library/dom'. While the patchFocus/restoreFocus functions are exported, the side-effect imports may execute code at module load time. This is not inherently malicious, but combined with prototype patching, it means simply importing this module can alter global state without explicit invocation.

dist/esm/document/patchFocus.js:2
low

Monkey-patching global prototypes

NPS-E03205C78FC0

The code globally overrides HTMLElement.prototype.focus and HTMLElement.prototype.blur with custom implementations. This is a common pattern in testing libraries (e.g., @testing-library/user-event) to simulate focus/blur behavior in headless environments, but it modifies global browser APIs for all elements in the page. If used maliciously or unexpectedly in production, this could alter UI behavior, interfere with accessibility, and potentially be used to harvest focus-related interactions.

dist/esm/document/patchFocus.js:10
low

Synthetic event dispatching

NPS-84D2AFD360BC

The patched focus/blur methods dispatch DOM events ('blur', 'focusout', 'focus', 'focusin') manually. This is standard in testing libraries to ensure event listeners fire correctly when programmatically focusing elements in hidden documents. No external data transfer or credential access is involved.

dist/esm/document/patchFocus.js:47

Files reviewed

FileVerdictWhat the reviewer saw
dist/cjs/document/patchFocus.js medium The code is a testing utility that monkey-patches HTMLElement.prototype focus/blur methods to simulate focus behavior when the document is hidden, which is a legitimate testing pattern but carries moderate risk due to global prototype modification.
dist/cjs/utils/dataTransfer/Clipboard.js medium No malicious exfiltration, credential harvesting, obfuscation, process spawning, or backdoor behavior detected; the code is a testing utility that stubs the Clipboard API and registers test-framework cleanup hooks, with only low-severity concerns around global navigator.clipboard manipulation.
dist/esm/document/patchFocus.js medium No malicious data exfiltration, credential harvesting, or code execution was found; the code is consistent with legitimate testing-library focus/blur simulation utilities, though it does globally patch DOM prototypes at import time.
dist/cjs/clipboard/copy.js safe No malicious patterns detected; the code simply performs a copy operation using local document and clipboard utilities.
dist/cjs/clipboard/cut.js safe No malicious patterns detected
dist/cjs/clipboard/index.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/clipboard/paste.js safe No malicious patterns detected; the code implements a paste utility for user-event simulation without any exfiltration, obfuscation, or process execution.
dist/cjs/convenience/click.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/convenience/hover.js safe No malicious patterns detected
dist/cjs/convenience/index.js safe No malicious patterns detected
dist/cjs/convenience/tab.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/document/UI.js safe No malicious patterns detected; the code implements UI value and selection management for form elements without any security-sensitive operations.
dist/cjs/document/copySelection.js safe No malicious patterns detected; the code only reads local selection data and creates an in-memory DataTransfer object.
dist/cjs/document/getValueOrTextContent.js safe No malicious patterns detected; the code simply retrieves value or text content from DOM elements.
dist/cjs/document/index.js safe No malicious patterns detected; the file is a simple CommonJS module that imports and re-exports UI and utility functions without any obfuscation, network, filesystem, or process execution activity.
dist/cjs/document/interceptor.js safe No malicious patterns detected; the code only intercepts DOM element property accessors for UI testing purposes without any exfiltration, obfuscation, or system interaction.
dist/cjs/document/prepareDocument.js safe No malicious patterns detected; the code implements browser event handling and DOM utility workarounds for testing purposes without any exfiltration, dynamic execution, or suspicious behavior.
dist/cjs/document/trackValue.js safe No malicious patterns detected; the code only handles React 17 input value tracking for testing-library/user-event.
dist/cjs/event/behavior/click.js safe The code implements standard click behavior for testing library, no malicious patterns detected.
dist/cjs/event/behavior/cut.js safe The code is a benign event handler for cut behavior in an input simulation library, with no malicious patterns detected.
dist/cjs/event/behavior/index.js safe No malicious patterns detected; the file only re-exports a registry module after requiring internal behavior modules.
dist/cjs/event/behavior/keydown.js safe The code is a legitimate keyboard event handling module for a testing library, with no malicious patterns such as data exfiltration, environment harvesting, obfuscation, or process spawning.
dist/cjs/event/behavior/keypress.js safe No malicious patterns detected
dist/cjs/event/behavior/keyup.js safe The file contains only a simple keyup behavior handler for clickable inputs with no malicious patterns detected.
dist/cjs/event/behavior/paste.js safe No malicious patterns detected
Show 177 more files
FileVerdictWhat the reviewer saw
dist/cjs/event/behavior/registry.js safe No malicious patterns detected
dist/cjs/event/createEvent.js safe No malicious patterns detected; the code only constructs synthetic DOM events for testing purposes.
dist/cjs/event/dispatchEvent.js safe No malicious patterns detected
dist/cjs/event/eventMap.js safe The file contains only a static event mapping table and pure utility functions with no network, filesystem, process, or dynamic code execution patterns.
dist/cjs/event/focus.js safe No malicious patterns detected; the code performs DOM focus/blur management only, with no network, filesystem, process, or dynamic code execution concerns.
dist/cjs/event/index.js safe No malicious patterns detected; the file is a simple re-export barrel module for event-related utilities.
dist/cjs/event/input.js safe No malicious patterns detected; the code implements DOM input simulation for a testing library.
dist/cjs/event/radio.js safe No malicious patterns detected; the code performs standard radio button group navigation using safe DOM APIs and CSS escaping.
dist/cjs/event/selection/getInputRange.js safe No malicious patterns detected
dist/cjs/event/selection/getTargetTypeAndSelection.js safe No malicious patterns detected; the code only handles DOM selection and contenteditable logic without exfiltration, obfuscation, or system access.
dist/cjs/event/selection/index.js safe No malicious patterns detected
dist/cjs/event/selection/modifySelection.js safe No malicious patterns detected; the code only manipulates DOM selection state and does not perform any network, filesystem, process, or dynamic execution activity.
dist/cjs/event/selection/modifySelectionPerMouse.js safe No malicious patterns detected
dist/cjs/event/selection/moveSelection.js safe No malicious patterns detected
dist/cjs/event/selection/resolveCaretPosition.js safe No malicious patterns detected
dist/cjs/event/selection/selectAll.js safe No malicious patterns detected; the file contains legitimate selection-handling logic with no network, filesystem, process, or obfuscated code.
dist/cjs/event/selection/setSelection.js safe No malicious patterns detected
dist/cjs/event/selection/setSelectionPerMouse.js safe No malicious patterns detected; the code only implements DOM text selection logic using standard browser APIs and internal utilities.
dist/cjs/event/selection/setSelectionRange.js safe No malicious patterns detected
dist/cjs/event/selection/updateSelectionOnFocus.js safe No malicious patterns detected; the code is a benign DOM selection utility with no network, filesystem, process, or dynamic code execution behavior.
dist/cjs/event/types.js safe The file contains only a 'use strict' directive with no executable or suspicious code.
dist/cjs/event/wrapEvent.js safe No malicious patterns detected; the file is a simple wrapper around @testing-library/dom's eventWrapper configuration.
dist/cjs/index.js safe The file is a simple CommonJS re-export shim with no dynamic execution, network access, filesystem manipulation, or other malicious patterns.
dist/cjs/keyboard/index.js safe No malicious patterns detected; the code implements keyboard input simulation with no exfiltration, obfuscation, or system manipulation.
dist/cjs/keyboard/keyMap.js safe No malicious patterns detected; the file only defines a static keyboard key map and requires a local sibling module.
dist/cjs/keyboard/parseKeyDef.js safe No malicious patterns detected
dist/cjs/options.js safe No malicious patterns detected
dist/cjs/pointer/index.js safe No malicious patterns detected
dist/cjs/pointer/keyMap.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/pointer/parseKeyDef.js safe No malicious patterns detected
dist/cjs/setup/api.js safe No malicious patterns detected
dist/cjs/setup/directApi.js safe This file is a thin wrapper around a local 'setup' module for user interaction APIs and contains no suspicious, obfuscated, or malicious patterns.
dist/cjs/setup/index.js safe This file is a simple re-export shim that merges the directApi module with a setupMain function from setup.js and exports it as userEvent; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic execution are present in the provided code.
dist/cjs/setup/setup.js safe No malicious patterns detected
dist/cjs/setup/wrapAsync.js safe No malicious patterns detected
dist/cjs/system/index.js safe No malicious patterns detected; the file defines a System class that manages keyboard and pointer state with no external network, filesystem, process, or dynamic code execution.
dist/cjs/system/keyboard.js safe No malicious patterns detected; the code implements keyboard event simulation for a testing framework without any network, filesystem, process execution, or obfuscation concerns.
dist/cjs/system/pointer/buttons.js safe No malicious patterns detected; the code is a standard input handling utility for mouse buttons.
dist/cjs/system/pointer/device.js safe No malicious patterns detected
dist/cjs/system/pointer/index.js safe No malicious patterns detected; the code is a legitimate pointer/input abstraction layer for a testing or UI interaction library.
dist/cjs/system/pointer/mouse.js safe No malicious patterns detected
dist/cjs/system/pointer/pointer.js safe No malicious patterns detected
dist/cjs/system/pointer/shared.js safe No malicious patterns detected in the provided source code; it is a simple utility function for comparing pointer positions with no external I/O, dynamic code execution, or obfuscation.
dist/cjs/utility/clear.js safe No malicious patterns detected; the code implements a clear() utility for editable elements using standard testing-library modules and contains no exfiltration, obfuscation, or suspicious behavior.
dist/cjs/utility/index.js safe No malicious patterns detected
dist/cjs/utility/selectOptions.js safe No malicious patterns detected; this is standard @testing-library/user-event code for simulating select/deselect interactions.
dist/cjs/utility/type.js safe No malicious patterns detected; the code is a benign utility for simulating typing interactions in a testing library.
dist/cjs/utility/upload.js safe No malicious patterns detected; the code is a standard file upload utility for testing libraries.
dist/cjs/utils/click/isClickableInput.js safe This utility module only defines a type enum and a helper to check if an element is a clickable input, with no malicious patterns detected.
dist/cjs/utils/dataTransfer/Blob.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/dataTransfer/DataTransfer.js safe This file is a legitimate jsdom-compatible DataTransfer polyfill with no malicious patterns, network activity, credential access, or code execution concerns.
dist/cjs/utils/dataTransfer/FileList.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/edit/isContentEditable.js safe No malicious patterns detected
dist/cjs/utils/edit/isEditable.js safe No malicious patterns detected
dist/cjs/utils/edit/maxLength.js safe No malicious patterns detected; the code is a small utility for reading maxlength attributes and checking input types.
dist/cjs/utils/edit/setFiles.js safe The code is a benign utility for mocking file input elements in testing environments (likely part of Testing Library) with no malicious patterns, network activity, credential access, or dynamic code execution.
dist/cjs/utils/edit/timeValue.js safe The code is a benign utility for formatting time values and contains no malicious patterns, network calls, credential harvesting, or dynamic code execution.
dist/cjs/utils/focus/cursor.js safe No malicious patterns detected; the code implements DOM cursor navigation logic without network, filesystem, or process execution concerns.
dist/cjs/utils/focus/getActiveElement.js safe No malicious patterns detected; the code only traverses the DOM to find the active element, including shadow roots and iframes, with no network, filesystem, process, or dynamic code execution behavior.
dist/cjs/utils/focus/getTabDestination.js safe No malicious patterns detected
dist/cjs/utils/focus/isFocusable.js safe No malicious patterns detected
dist/cjs/utils/focus/selection.js safe No malicious patterns detected
dist/cjs/utils/focus/selector.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/index.js safe This is a standard barrel/index file that re-exports utilities from a DOM testing library; no malicious patterns, dynamic execution, network calls, or process spawning detected.
dist/cjs/utils/keyDef/readNextDescriptor.js safe No malicious patterns detected
dist/cjs/utils/misc/cloneEvent.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/misc/findClosest.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/misc/getDocumentFromNode.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/misc/getTreeDiff.js safe No malicious patterns detected
dist/cjs/utils/misc/getWindow.js safe No malicious patterns detected
dist/cjs/utils/misc/isDescendantOrSelf.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/misc/isDisabled.js safe No malicious patterns detected; the code is a straightforward DOM utility for checking disabled state of form elements.
dist/cjs/utils/misc/isElementType.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/utils/misc/isVisible.js safe No malicious patterns detected
dist/cjs/utils/misc/level.js safe No malicious patterns detected
dist/cjs/utils/misc/wait.js safe No malicious patterns detected
dist/cjs/utils/pointer/cssPointerEvents.js safe No malicious patterns detected
dist/esm/clipboard/copy.js safe No malicious patterns detected; the code only copies the current selection to the clipboard via the browser's clipboard API.
dist/esm/clipboard/cut.js safe The code implements a legitimate clipboard 'cut' operation with no malicious patterns detected.
dist/esm/clipboard/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/clipboard/paste.js safe No malicious patterns detected
dist/esm/convenience/click.js safe Cleared by Jev triage; no further analysis needed
dist/esm/convenience/hover.js safe Cleared by Jev triage; no further analysis needed
dist/esm/convenience/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/convenience/tab.js safe Cleared by Jev triage; no further analysis needed
dist/esm/document/UI.js safe No malicious patterns detected; the code only manages UI value and selection state for input elements without any suspicious network, filesystem, or process operations.
dist/esm/document/copySelection.js safe No malicious patterns detected
dist/esm/document/getValueOrTextContent.js safe Cleared by Jev triage; no further analysis needed
dist/esm/document/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/document/interceptor.js safe No malicious patterns detected; the code implements property interception for value/selection tracking in DOM elements without any exfiltration, credential harvesting, dynamic code execution, or process spawning.
dist/esm/document/prepareDocument.js safe No malicious patterns detected
dist/esm/document/trackValue.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/behavior/click.js safe No malicious patterns detected; the code implements browser event simulation for user interaction testing without any security-sensitive operations.
dist/esm/event/behavior/cut.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/behavior/index.js safe No malicious patterns detected; the file only imports local event handler modules and re-exports a registry entry.
dist/esm/event/behavior/keydown.js safe No malicious patterns detected; the code implements keyboard event behavior for a DOM testing library with no network, filesystem, process, or obfuscation concerns.
dist/esm/event/behavior/keypress.js safe No malicious patterns detected
dist/esm/event/behavior/keyup.js safe No malicious patterns detected
dist/esm/event/behavior/paste.js safe The paste behavior handler only reads clipboard text and inserts it into editable targets without any network, filesystem, or dynamic execution activity.
dist/esm/event/behavior/registry.js safe No malicious patterns detected
dist/esm/event/createEvent.js safe No malicious patterns detected; the code is a legitimate event creation utility from a testing library.
dist/esm/event/dispatchEvent.js safe No malicious patterns detected; the code is a standard UI event dispatch module with no network, file system, process, or dynamic code execution concerns.
dist/esm/event/eventMap.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/focus.js safe No malicious patterns detected
dist/esm/event/index.js safe No malicious patterns detected; the file only re-exports event and selection utilities with no side effects or suspicious activity.
dist/esm/event/input.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/radio.js safe No malicious patterns detected; the code implements standard radio button keyboard navigation for accessibility.
dist/esm/event/selection/getInputRange.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/getTargetTypeAndSelection.js safe No malicious patterns detected; the code performs DOM selection logic without network, filesystem, or process activity.
dist/esm/event/selection/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/modifySelection.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/modifySelectionPerMouse.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/moveSelection.js safe No malicious patterns detected; the code implements selection movement logic using standard DOM APIs without exfiltration, obfuscation, or dangerous operations.
dist/esm/event/selection/resolveCaretPosition.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/selectAll.js safe No malicious patterns detected; the code implements standard DOM selection logic without network, filesystem, process, or dynamic execution behavior.
dist/esm/event/selection/setSelection.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/setSelectionPerMouse.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/selection/setSelectionRange.js safe No malicious patterns detected; the code only performs DOM selection range logic without network, filesystem, process, or dynamic execution behavior.
dist/esm/event/selection/updateSelectionOnFocus.js safe Cleared by Jev triage; no further analysis needed
dist/esm/event/types.js safe No malicious patterns detected
dist/esm/event/wrapEvent.js safe Cleared by Jev triage; no further analysis needed
dist/esm/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/keyboard/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/keyboard/keyMap.js safe No malicious patterns detected
dist/esm/keyboard/parseKeyDef.js safe No malicious patterns detected; the code is a benign keyboard key definition parser with no network, filesystem, process execution, or obfuscation concerns.
dist/esm/options.js safe No malicious patterns detected
dist/esm/pointer/index.js safe No malicious patterns detected; the code implements pointer/keyboard action simulation for testing purposes.
dist/esm/pointer/keyMap.js safe Cleared by Jev triage; no further analysis needed
dist/esm/pointer/parseKeyDef.js safe Cleared by Jev triage; no further analysis needed
dist/esm/setup/api.js safe Cleared by Jev triage; no further analysis needed
dist/esm/setup/directApi.js safe Cleared by Jev triage; no further analysis needed
dist/esm/setup/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/setup/setup.js safe No malicious patterns detected in the userEvent setup module, which contains only legitimate testing utility setup logic.
dist/esm/setup/wrapAsync.js safe Cleared by Jev triage; no further analysis needed
dist/esm/system/index.js safe No malicious patterns detected; the code only defines a UI event modifier helper class with no network, filesystem, process, or dynamic execution behavior.
dist/esm/system/keyboard.js safe No malicious patterns detected; the code implements keyboard event simulation for testing with no exfiltration, code execution, or filesystem access.
dist/esm/system/pointer/buttons.js safe No malicious patterns detected; the code is a simple mouse button state tracker with no network, filesystem, process, or dynamic execution activity.
dist/esm/system/pointer/device.js safe No malicious patterns detected; the code is a simple class-based implementation for tracking pressed keys.
dist/esm/system/pointer/index.js safe No malicious patterns detected; the code is a legitimate pointer/input event handling module with no network, filesystem, process, or dynamic execution behavior.
dist/esm/system/pointer/mouse.js safe No malicious patterns detected; the code is a legitimate virtual mouse implementation for testing library user-event with only static imports and no exfiltration, credential harvesting, obfuscation, or process spawning.
dist/esm/system/pointer/pointer.js safe No malicious patterns detected; the code implements pointer event handling with no external network, filesystem, or process activity.
dist/esm/system/pointer/shared.js safe No malicious patterns detected
dist/esm/utility/clear.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utility/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utility/selectOptions.js safe This is legitimate Testing Library DOM utility code for simulating user interactions with select elements; no malicious patterns detected.
dist/esm/utility/type.js safe No malicious patterns detected; the code is a straightforward typing utility with no network, filesystem, process, or obfuscation concerns.
dist/esm/utility/upload.js safe No malicious patterns detected; the code is a legitimate file upload utility for testing libraries like Testing Library.
dist/esm/utils/click/isClickableInput.js safe No malicious patterns detected; the file only exports a utility function that checks element types and input attributes.
dist/esm/utils/dataTransfer/Blob.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/dataTransfer/Clipboard.js safe No malicious patterns detected; the file implements clipboard stub utilities for testing with no network, credential, or code-execution exfiltration behavior.
dist/esm/utils/dataTransfer/DataTransfer.js safe No malicious patterns detected
dist/esm/utils/dataTransfer/FileList.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/edit/isContentEditable.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/edit/isEditable.js safe No malicious patterns detected; the file only provides utility functions to check whether an element is editable.
dist/esm/utils/edit/maxLength.js safe No malicious patterns detected
dist/esm/utils/edit/setFiles.js safe No malicious patterns detected; the code only monkey-patches DOM element properties to simulate file input behavior for testing.
dist/esm/utils/edit/timeValue.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/focus/cursor.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/focus/getActiveElement.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/focus/getTabDestination.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/focus/isFocusable.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/focus/selection.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/focus/selector.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/keyDef/readNextDescriptor.js safe No malicious patterns detected
dist/esm/utils/misc/cloneEvent.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/misc/findClosest.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/misc/getDocumentFromNode.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/misc/getTreeDiff.js safe No malicious patterns detected
dist/esm/utils/misc/getWindow.js safe No malicious patterns detected
dist/esm/utils/misc/isDescendantOrSelf.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/misc/isDisabled.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/misc/isElementType.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/misc/isVisible.js safe No malicious patterns detected
dist/esm/utils/misc/level.js safe No malicious patterns detected
dist/esm/utils/misc/wait.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/pointer/cssPointerEvents.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is @testing-library/user-event safe to use?

No confirmed malware was found in @testing-library/user-event@14.6.7, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does @testing-library/user-event contain malware?

No malware was identified in @testing-library/user-event@14.6.7 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @testing-library/user-event checked?

Togoder Security downloaded the published npm package and had an AI model read its 202 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @testing-library/user-event together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @testing-library/user-event@14.6.7, cost nothing.

Related security reports