Summary
Togoder Security scanned the npm package @testing-library/user-event@14.6.7 on Oct 6, 2026. An AI review of 202 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Prototype Pollution / Monkey Patching
NPS-7002B840A57E
The code modifies the global HTMLElement.prototype by overriding the focus and blur methods. This is a form of monkey patching that can affect all elements in the application, potentially leading to unexpected behavior or security issues if not properly scoped. While this appears to be part of a testing library (likely @testing-library/user-event), such global modifications can have side effects.
Dynamic Code Execution via Symbol
NPS-279209A6DEFF
The code uses a Symbol('patched focus/blur methods') to mark patched prototypes and stores original methods. While not directly malicious, this technique could be used to hide modifications or bypass detection. However, in this context, it seems to be used for legitimate restoration purposes.
Event Dispatch Manipulation
NPS-648F99781EF2
The patched methods manually dispatch DOM events (blur, focusout, focus, focusin) with custom relatedTarget values. This could be used to trigger unintended event handlers or bypass event-based security checks if the library is used in a production environment. However, this is likely intended for testing purposes.
Clipboard API interception
NPS-2F7800AF0E86
attachClipboardStubToView replaces navigator.clipboard with a stub that stores items in memory and read/writeText/readText operate on that stub. This design is intended for testing but constitutes clipboard data interception if invoked unexpectedly, and could be abused to capture or alter clipboard contents in a controlled page context.
Global object prototype/navigator property manipulation
NPS-7A1ED9BAF146
The code defines and overrides window.navigator.clipboard using Object.defineProperty with a getter, and writes to window.navigator. This is an intentional stubbing mechanism for testing, but it modifies a sensitive browser API surface at runtime. If used outside tests, it could intercept clipboard reads/writes.
Top-level code execution on import
NPS-D5C7CC8AF5B0
The module registers top-level hooks on globalThis.afterEach and globalThis.afterAll if they exist. While these are typical test framework hooks that merely reset/detach the clipboard stub, they still execute code automatically upon import in any environment that defines these globals, which is a behavior worth noting for supply-chain analysis.
Import-time side effects
NPS-00B824F6A3A3
The module imports '../utils/dataTransfer/Clipboard.js' and '@testing-library/dom'. While the patchFocus/restoreFocus functions are exported, the side-effect imports may execute code at module load time. This is not inherently malicious, but combined with prototype patching, it means simply importing this module can alter global state without explicit invocation.
Monkey-patching global prototypes
NPS-E03205C78FC0
The code globally overrides HTMLElement.prototype.focus and HTMLElement.prototype.blur with custom implementations. This is a common pattern in testing libraries (e.g., @testing-library/user-event) to simulate focus/blur behavior in headless environments, but it modifies global browser APIs for all elements in the page. If used maliciously or unexpectedly in production, this could alter UI behavior, interfere with accessibility, and potentially be used to harvest focus-related interactions.
Synthetic event dispatching
NPS-84D2AFD360BC
The patched focus/blur methods dispatch DOM events ('blur', 'focusout', 'focus', 'focusin') manually. This is standard in testing libraries to ensure event listeners fire correctly when programmatically focusing elements in hidden documents. No external data transfer or credential access is involved.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/cjs/document/patchFocus.js | medium | The code is a testing utility that monkey-patches HTMLElement.prototype focus/blur methods to simulate focus behavior when the document is hidden, which is a legitimate testing pattern but carries moderate risk due to global prototype modification. |
| dist/cjs/utils/dataTransfer/Clipboard.js | medium | No malicious exfiltration, credential harvesting, obfuscation, process spawning, or backdoor behavior detected; the code is a testing utility that stubs the Clipboard API and registers test-framework cleanup hooks, with only low-severity concerns around global navigator.clipboard manipulation. |
| dist/esm/document/patchFocus.js | medium | No malicious data exfiltration, credential harvesting, or code execution was found; the code is consistent with legitimate testing-library focus/blur simulation utilities, though it does globally patch DOM prototypes at import time. |
| dist/cjs/clipboard/copy.js | safe | No malicious patterns detected; the code simply performs a copy operation using local document and clipboard utilities. |
| dist/cjs/clipboard/cut.js | safe | No malicious patterns detected |
| dist/cjs/clipboard/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/clipboard/paste.js | safe | No malicious patterns detected; the code implements a paste utility for user-event simulation without any exfiltration, obfuscation, or process execution. |
| dist/cjs/convenience/click.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/convenience/hover.js | safe | No malicious patterns detected |
| dist/cjs/convenience/index.js | safe | No malicious patterns detected |
| dist/cjs/convenience/tab.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/document/UI.js | safe | No malicious patterns detected; the code implements UI value and selection management for form elements without any security-sensitive operations. |
| dist/cjs/document/copySelection.js | safe | No malicious patterns detected; the code only reads local selection data and creates an in-memory DataTransfer object. |
| dist/cjs/document/getValueOrTextContent.js | safe | No malicious patterns detected; the code simply retrieves value or text content from DOM elements. |
| dist/cjs/document/index.js | safe | No malicious patterns detected; the file is a simple CommonJS module that imports and re-exports UI and utility functions without any obfuscation, network, filesystem, or process execution activity. |
| dist/cjs/document/interceptor.js | safe | No malicious patterns detected; the code only intercepts DOM element property accessors for UI testing purposes without any exfiltration, obfuscation, or system interaction. |
| dist/cjs/document/prepareDocument.js | safe | No malicious patterns detected; the code implements browser event handling and DOM utility workarounds for testing purposes without any exfiltration, dynamic execution, or suspicious behavior. |
| dist/cjs/document/trackValue.js | safe | No malicious patterns detected; the code only handles React 17 input value tracking for testing-library/user-event. |
| dist/cjs/event/behavior/click.js | safe | The code implements standard click behavior for testing library, no malicious patterns detected. |
| dist/cjs/event/behavior/cut.js | safe | The code is a benign event handler for cut behavior in an input simulation library, with no malicious patterns detected. |
| dist/cjs/event/behavior/index.js | safe | No malicious patterns detected; the file only re-exports a registry module after requiring internal behavior modules. |
| dist/cjs/event/behavior/keydown.js | safe | The code is a legitimate keyboard event handling module for a testing library, with no malicious patterns such as data exfiltration, environment harvesting, obfuscation, or process spawning. |
| dist/cjs/event/behavior/keypress.js | safe | No malicious patterns detected |
| dist/cjs/event/behavior/keyup.js | safe | The file contains only a simple keyup behavior handler for clickable inputs with no malicious patterns detected. |
| dist/cjs/event/behavior/paste.js | safe | No malicious patterns detected |
Show 177 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/cjs/event/behavior/registry.js | safe | No malicious patterns detected |
| dist/cjs/event/createEvent.js | safe | No malicious patterns detected; the code only constructs synthetic DOM events for testing purposes. |
| dist/cjs/event/dispatchEvent.js | safe | No malicious patterns detected |
| dist/cjs/event/eventMap.js | safe | The file contains only a static event mapping table and pure utility functions with no network, filesystem, process, or dynamic code execution patterns. |
| dist/cjs/event/focus.js | safe | No malicious patterns detected; the code performs DOM focus/blur management only, with no network, filesystem, process, or dynamic code execution concerns. |
| dist/cjs/event/index.js | safe | No malicious patterns detected; the file is a simple re-export barrel module for event-related utilities. |
| dist/cjs/event/input.js | safe | No malicious patterns detected; the code implements DOM input simulation for a testing library. |
| dist/cjs/event/radio.js | safe | No malicious patterns detected; the code performs standard radio button group navigation using safe DOM APIs and CSS escaping. |
| dist/cjs/event/selection/getInputRange.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/getTargetTypeAndSelection.js | safe | No malicious patterns detected; the code only handles DOM selection and contenteditable logic without exfiltration, obfuscation, or system access. |
| dist/cjs/event/selection/index.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/modifySelection.js | safe | No malicious patterns detected; the code only manipulates DOM selection state and does not perform any network, filesystem, process, or dynamic execution activity. |
| dist/cjs/event/selection/modifySelectionPerMouse.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/moveSelection.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/resolveCaretPosition.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/selectAll.js | safe | No malicious patterns detected; the file contains legitimate selection-handling logic with no network, filesystem, process, or obfuscated code. |
| dist/cjs/event/selection/setSelection.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/setSelectionPerMouse.js | safe | No malicious patterns detected; the code only implements DOM text selection logic using standard browser APIs and internal utilities. |
| dist/cjs/event/selection/setSelectionRange.js | safe | No malicious patterns detected |
| dist/cjs/event/selection/updateSelectionOnFocus.js | safe | No malicious patterns detected; the code is a benign DOM selection utility with no network, filesystem, process, or dynamic code execution behavior. |
| dist/cjs/event/types.js | safe | The file contains only a 'use strict' directive with no executable or suspicious code. |
| dist/cjs/event/wrapEvent.js | safe | No malicious patterns detected; the file is a simple wrapper around @testing-library/dom's eventWrapper configuration. |
| dist/cjs/index.js | safe | The file is a simple CommonJS re-export shim with no dynamic execution, network access, filesystem manipulation, or other malicious patterns. |
| dist/cjs/keyboard/index.js | safe | No malicious patterns detected; the code implements keyboard input simulation with no exfiltration, obfuscation, or system manipulation. |
| dist/cjs/keyboard/keyMap.js | safe | No malicious patterns detected; the file only defines a static keyboard key map and requires a local sibling module. |
| dist/cjs/keyboard/parseKeyDef.js | safe | No malicious patterns detected |
| dist/cjs/options.js | safe | No malicious patterns detected |
| dist/cjs/pointer/index.js | safe | No malicious patterns detected |
| dist/cjs/pointer/keyMap.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/pointer/parseKeyDef.js | safe | No malicious patterns detected |
| dist/cjs/setup/api.js | safe | No malicious patterns detected |
| dist/cjs/setup/directApi.js | safe | This file is a thin wrapper around a local 'setup' module for user interaction APIs and contains no suspicious, obfuscated, or malicious patterns. |
| dist/cjs/setup/index.js | safe | This file is a simple re-export shim that merges the directApi module with a setupMain function from setup.js and exports it as userEvent; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic execution are present in the provided code. |
| dist/cjs/setup/setup.js | safe | No malicious patterns detected |
| dist/cjs/setup/wrapAsync.js | safe | No malicious patterns detected |
| dist/cjs/system/index.js | safe | No malicious patterns detected; the file defines a System class that manages keyboard and pointer state with no external network, filesystem, process, or dynamic code execution. |
| dist/cjs/system/keyboard.js | safe | No malicious patterns detected; the code implements keyboard event simulation for a testing framework without any network, filesystem, process execution, or obfuscation concerns. |
| dist/cjs/system/pointer/buttons.js | safe | No malicious patterns detected; the code is a standard input handling utility for mouse buttons. |
| dist/cjs/system/pointer/device.js | safe | No malicious patterns detected |
| dist/cjs/system/pointer/index.js | safe | No malicious patterns detected; the code is a legitimate pointer/input abstraction layer for a testing or UI interaction library. |
| dist/cjs/system/pointer/mouse.js | safe | No malicious patterns detected |
| dist/cjs/system/pointer/pointer.js | safe | No malicious patterns detected |
| dist/cjs/system/pointer/shared.js | safe | No malicious patterns detected in the provided source code; it is a simple utility function for comparing pointer positions with no external I/O, dynamic code execution, or obfuscation. |
| dist/cjs/utility/clear.js | safe | No malicious patterns detected; the code implements a clear() utility for editable elements using standard testing-library modules and contains no exfiltration, obfuscation, or suspicious behavior. |
| dist/cjs/utility/index.js | safe | No malicious patterns detected |
| dist/cjs/utility/selectOptions.js | safe | No malicious patterns detected; this is standard @testing-library/user-event code for simulating select/deselect interactions. |
| dist/cjs/utility/type.js | safe | No malicious patterns detected; the code is a benign utility for simulating typing interactions in a testing library. |
| dist/cjs/utility/upload.js | safe | No malicious patterns detected; the code is a standard file upload utility for testing libraries. |
| dist/cjs/utils/click/isClickableInput.js | safe | This utility module only defines a type enum and a helper to check if an element is a clickable input, with no malicious patterns detected. |
| dist/cjs/utils/dataTransfer/Blob.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/dataTransfer/DataTransfer.js | safe | This file is a legitimate jsdom-compatible DataTransfer polyfill with no malicious patterns, network activity, credential access, or code execution concerns. |
| dist/cjs/utils/dataTransfer/FileList.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/edit/isContentEditable.js | safe | No malicious patterns detected |
| dist/cjs/utils/edit/isEditable.js | safe | No malicious patterns detected |
| dist/cjs/utils/edit/maxLength.js | safe | No malicious patterns detected; the code is a small utility for reading maxlength attributes and checking input types. |
| dist/cjs/utils/edit/setFiles.js | safe | The code is a benign utility for mocking file input elements in testing environments (likely part of Testing Library) with no malicious patterns, network activity, credential access, or dynamic code execution. |
| dist/cjs/utils/edit/timeValue.js | safe | The code is a benign utility for formatting time values and contains no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| dist/cjs/utils/focus/cursor.js | safe | No malicious patterns detected; the code implements DOM cursor navigation logic without network, filesystem, or process execution concerns. |
| dist/cjs/utils/focus/getActiveElement.js | safe | No malicious patterns detected; the code only traverses the DOM to find the active element, including shadow roots and iframes, with no network, filesystem, process, or dynamic code execution behavior. |
| dist/cjs/utils/focus/getTabDestination.js | safe | No malicious patterns detected |
| dist/cjs/utils/focus/isFocusable.js | safe | No malicious patterns detected |
| dist/cjs/utils/focus/selection.js | safe | No malicious patterns detected |
| dist/cjs/utils/focus/selector.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/index.js | safe | This is a standard barrel/index file that re-exports utilities from a DOM testing library; no malicious patterns, dynamic execution, network calls, or process spawning detected. |
| dist/cjs/utils/keyDef/readNextDescriptor.js | safe | No malicious patterns detected |
| dist/cjs/utils/misc/cloneEvent.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/misc/findClosest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/misc/getDocumentFromNode.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/misc/getTreeDiff.js | safe | No malicious patterns detected |
| dist/cjs/utils/misc/getWindow.js | safe | No malicious patterns detected |
| dist/cjs/utils/misc/isDescendantOrSelf.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/misc/isDisabled.js | safe | No malicious patterns detected; the code is a straightforward DOM utility for checking disabled state of form elements. |
| dist/cjs/utils/misc/isElementType.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/utils/misc/isVisible.js | safe | No malicious patterns detected |
| dist/cjs/utils/misc/level.js | safe | No malicious patterns detected |
| dist/cjs/utils/misc/wait.js | safe | No malicious patterns detected |
| dist/cjs/utils/pointer/cssPointerEvents.js | safe | No malicious patterns detected |
| dist/esm/clipboard/copy.js | safe | No malicious patterns detected; the code only copies the current selection to the clipboard via the browser's clipboard API. |
| dist/esm/clipboard/cut.js | safe | The code implements a legitimate clipboard 'cut' operation with no malicious patterns detected. |
| dist/esm/clipboard/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/clipboard/paste.js | safe | No malicious patterns detected |
| dist/esm/convenience/click.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/convenience/hover.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/convenience/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/convenience/tab.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/document/UI.js | safe | No malicious patterns detected; the code only manages UI value and selection state for input elements without any suspicious network, filesystem, or process operations. |
| dist/esm/document/copySelection.js | safe | No malicious patterns detected |
| dist/esm/document/getValueOrTextContent.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/document/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/document/interceptor.js | safe | No malicious patterns detected; the code implements property interception for value/selection tracking in DOM elements without any exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/esm/document/prepareDocument.js | safe | No malicious patterns detected |
| dist/esm/document/trackValue.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/behavior/click.js | safe | No malicious patterns detected; the code implements browser event simulation for user interaction testing without any security-sensitive operations. |
| dist/esm/event/behavior/cut.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/behavior/index.js | safe | No malicious patterns detected; the file only imports local event handler modules and re-exports a registry entry. |
| dist/esm/event/behavior/keydown.js | safe | No malicious patterns detected; the code implements keyboard event behavior for a DOM testing library with no network, filesystem, process, or obfuscation concerns. |
| dist/esm/event/behavior/keypress.js | safe | No malicious patterns detected |
| dist/esm/event/behavior/keyup.js | safe | No malicious patterns detected |
| dist/esm/event/behavior/paste.js | safe | The paste behavior handler only reads clipboard text and inserts it into editable targets without any network, filesystem, or dynamic execution activity. |
| dist/esm/event/behavior/registry.js | safe | No malicious patterns detected |
| dist/esm/event/createEvent.js | safe | No malicious patterns detected; the code is a legitimate event creation utility from a testing library. |
| dist/esm/event/dispatchEvent.js | safe | No malicious patterns detected; the code is a standard UI event dispatch module with no network, file system, process, or dynamic code execution concerns. |
| dist/esm/event/eventMap.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/focus.js | safe | No malicious patterns detected |
| dist/esm/event/index.js | safe | No malicious patterns detected; the file only re-exports event and selection utilities with no side effects or suspicious activity. |
| dist/esm/event/input.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/radio.js | safe | No malicious patterns detected; the code implements standard radio button keyboard navigation for accessibility. |
| dist/esm/event/selection/getInputRange.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/getTargetTypeAndSelection.js | safe | No malicious patterns detected; the code performs DOM selection logic without network, filesystem, or process activity. |
| dist/esm/event/selection/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/modifySelection.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/modifySelectionPerMouse.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/moveSelection.js | safe | No malicious patterns detected; the code implements selection movement logic using standard DOM APIs without exfiltration, obfuscation, or dangerous operations. |
| dist/esm/event/selection/resolveCaretPosition.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/selectAll.js | safe | No malicious patterns detected; the code implements standard DOM selection logic without network, filesystem, process, or dynamic execution behavior. |
| dist/esm/event/selection/setSelection.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/setSelectionPerMouse.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/selection/setSelectionRange.js | safe | No malicious patterns detected; the code only performs DOM selection range logic without network, filesystem, process, or dynamic execution behavior. |
| dist/esm/event/selection/updateSelectionOnFocus.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/event/types.js | safe | No malicious patterns detected |
| dist/esm/event/wrapEvent.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/keyboard/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/keyboard/keyMap.js | safe | No malicious patterns detected |
| dist/esm/keyboard/parseKeyDef.js | safe | No malicious patterns detected; the code is a benign keyboard key definition parser with no network, filesystem, process execution, or obfuscation concerns. |
| dist/esm/options.js | safe | No malicious patterns detected |
| dist/esm/pointer/index.js | safe | No malicious patterns detected; the code implements pointer/keyboard action simulation for testing purposes. |
| dist/esm/pointer/keyMap.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/pointer/parseKeyDef.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/setup/api.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/setup/directApi.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/setup/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/setup/setup.js | safe | No malicious patterns detected in the userEvent setup module, which contains only legitimate testing utility setup logic. |
| dist/esm/setup/wrapAsync.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/system/index.js | safe | No malicious patterns detected; the code only defines a UI event modifier helper class with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/system/keyboard.js | safe | No malicious patterns detected; the code implements keyboard event simulation for testing with no exfiltration, code execution, or filesystem access. |
| dist/esm/system/pointer/buttons.js | safe | No malicious patterns detected; the code is a simple mouse button state tracker with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/system/pointer/device.js | safe | No malicious patterns detected; the code is a simple class-based implementation for tracking pressed keys. |
| dist/esm/system/pointer/index.js | safe | No malicious patterns detected; the code is a legitimate pointer/input event handling module with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/system/pointer/mouse.js | safe | No malicious patterns detected; the code is a legitimate virtual mouse implementation for testing library user-event with only static imports and no exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/esm/system/pointer/pointer.js | safe | No malicious patterns detected; the code implements pointer event handling with no external network, filesystem, or process activity. |
| dist/esm/system/pointer/shared.js | safe | No malicious patterns detected |
| dist/esm/utility/clear.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utility/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utility/selectOptions.js | safe | This is legitimate Testing Library DOM utility code for simulating user interactions with select elements; no malicious patterns detected. |
| dist/esm/utility/type.js | safe | No malicious patterns detected; the code is a straightforward typing utility with no network, filesystem, process, or obfuscation concerns. |
| dist/esm/utility/upload.js | safe | No malicious patterns detected; the code is a legitimate file upload utility for testing libraries like Testing Library. |
| dist/esm/utils/click/isClickableInput.js | safe | No malicious patterns detected; the file only exports a utility function that checks element types and input attributes. |
| dist/esm/utils/dataTransfer/Blob.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/dataTransfer/Clipboard.js | safe | No malicious patterns detected; the file implements clipboard stub utilities for testing with no network, credential, or code-execution exfiltration behavior. |
| dist/esm/utils/dataTransfer/DataTransfer.js | safe | No malicious patterns detected |
| dist/esm/utils/dataTransfer/FileList.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/edit/isContentEditable.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/edit/isEditable.js | safe | No malicious patterns detected; the file only provides utility functions to check whether an element is editable. |
| dist/esm/utils/edit/maxLength.js | safe | No malicious patterns detected |
| dist/esm/utils/edit/setFiles.js | safe | No malicious patterns detected; the code only monkey-patches DOM element properties to simulate file input behavior for testing. |
| dist/esm/utils/edit/timeValue.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/focus/cursor.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/focus/getActiveElement.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/focus/getTabDestination.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/focus/isFocusable.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/focus/selection.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/focus/selector.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/keyDef/readNextDescriptor.js | safe | No malicious patterns detected |
| dist/esm/utils/misc/cloneEvent.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/misc/findClosest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/misc/getDocumentFromNode.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/misc/getTreeDiff.js | safe | No malicious patterns detected |
| dist/esm/utils/misc/getWindow.js | safe | No malicious patterns detected |
| dist/esm/utils/misc/isDescendantOrSelf.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/misc/isDisabled.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/misc/isElementType.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/misc/isVisible.js | safe | No malicious patterns detected |
| dist/esm/utils/misc/level.js | safe | No malicious patterns detected |
| dist/esm/utils/misc/wait.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/utils/pointer/cssPointerEvents.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is @testing-library/user-event safe to use?
No confirmed malware was found in @testing-library/user-event@14.6.7, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does @testing-library/user-event contain malware?
No malware was identified in @testing-library/user-event@14.6.7 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @testing-library/user-event checked?
Togoder Security downloaded the published npm package and had an AI model read its 202 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @testing-library/user-event together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @testing-library/user-event@14.6.7, cost nothing.