# aria-query@5.3.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:46.000Z
- Files reviewed: 154
- Findings: no findings
- Report: https://security.togoder.click/npm/aria-query
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package aria-query@5.3.2 on Oct 6, 2026. An AI review of 154 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `lib/ariaPropsMap.js` (safe): No malicious patterns detected; the file defines a static ARIA properties map with standard Babel-compiled helper functions and no network, filesystem, process, or dynamic execution activity.
- `lib/domMap.js` (safe): No malicious patterns detected; the file is a benign Babel-compiled DOM element map utility with no network, filesystem, process, or dynamic code execution activity.
- `lib/elementRoleMap.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/commandRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/compositeRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/inputRole.js` (safe): No malicious patterns detected; the file defines a static ARIA role descriptor with no execution, I/O, network, or credential access.
- `lib/etc/roles/abstract/landmarkRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/rangeRole.js` (safe): No malicious patterns detected; this is a static ARIA role definition with no executable, network, filesystem, or dynamic code behavior.
- `lib/etc/roles/abstract/roletypeRole.js` (safe): No malicious patterns detected; this file only defines a static ARIA role metadata object.
- `lib/etc/roles/abstract/sectionRole.js` (safe): No malicious patterns detected; the file only defines a static role metadata object with no executable code, network access, or file system interaction.
- `lib/etc/roles/abstract/sectionheadRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/selectRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/structureRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/widgetRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/abstract/windowRole.js` (safe): No malicious patterns detected; the file contains only a static ARIA role definition with no executable, network, filesystem, or process-related code.
- `lib/etc/roles/ariaAbstractRoles.js` (safe): No malicious patterns detected; the file only imports and re-exports static ARIA role modules.
- `lib/etc/roles/ariaDpubRoles.js` (safe): No malicious patterns detected
- `lib/etc/roles/ariaGraphicsRoles.js` (safe): No malicious patterns detected; the file is a simple module exporting ARIA graphics role mappings with no network, filesystem, process, or dynamic code execution activity.
- `lib/etc/roles/ariaLiteralRoles.js` (safe): No malicious patterns detected; this file only statically imports and exports an array of ARIA role definitions.
- `lib/etc/roles/dpub/docAbstractRole.js` (safe): This file is a static data definition for an accessibility role with no executable code, network access, file system operations, or other malicious patterns.
- `lib/etc/roles/dpub/docAcknowledgmentsRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable logic, network access, or filesystem operations.
- `lib/etc/roles/dpub/docAfterwordRole.js` (safe): No malicious patterns detected; the file only defines a static ARIA role metadata object with no executable or network-related code.
- `lib/etc/roles/dpub/docAppendixRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, filesystem, or obfuscated code.
- `lib/etc/roles/dpub/docBacklinkRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docBiblioentryRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docBibliographyRole.js` (safe): No malicious patterns detected; this is a static accessibility role definition object with no executable or network behavior.
- `lib/etc/roles/dpub/docBibliorefRole.js` (safe): This file is a static ARIA role definition containing only configuration data and no executable or suspicious code.
- `lib/etc/roles/dpub/docChapterRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docColophonRole.js` (safe): This file contains only static accessibility role metadata with no executable, network, or file system operations.
- `lib/etc/roles/dpub/docConclusionRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docCoverRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, or filesystem behavior.
- `lib/etc/roles/dpub/docCreditRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, or filesystem activity.
- `lib/etc/roles/dpub/docCreditsRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docDedicationRole.js` (safe): No malicious patterns detected; the file only defines a static ARIA role metadata object with no executable or network-related code.
- `lib/etc/roles/dpub/docEndnoteRole.js` (safe): This is a static ARIA role definition file with no executable code, network access, file system manipulation, or other malicious patterns.
- `lib/etc/roles/dpub/docEndnotesRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docEpigraphRole.js` (safe): No malicious patterns detected; the file is a static accessibility role definition with no executable or network activity
- `lib/etc/roles/dpub/docEpilogueRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docErrataRole.js` (safe): No malicious patterns detected; the file contains only a static ARIA role definition with no executable, network, or file system behavior.
- `lib/etc/roles/dpub/docExampleRole.js` (safe): This file contains only static ARIA role metadata with no executable, network, filesystem, or process-related code and is not malicious.
- `lib/etc/roles/dpub/docFootnoteRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docForewordRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docGlossaryRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docGlossrefRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docIndexRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docIntroductionRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docNoterefRole.js` (safe): No malicious patterns detected; the file contains only a static ARIA role definition with no executable or suspicious code.
- `lib/etc/roles/dpub/docNoticeRole.js` (safe): This file is a static ARIA role definition object from what appears to be an accessibility library, containing no executable code, network activity, or malicious patterns.
- `lib/etc/roles/dpub/docPagebreakRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata with no executable, network, filesystem, or process-related code.
- `lib/etc/roles/dpub/docPagefooterRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docPageheaderRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docPagelistRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docPartRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docPrefaceRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docPrologueRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata with no executable, network, or filesystem behavior.
- `lib/etc/roles/dpub/docPullquoteRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docQnaRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docSubtitleRole.js` (safe): No malicious patterns detected; the file contains only a static ARIA role definition object with no executable, network, filesystem, or process-related code.
- `lib/etc/roles/dpub/docTipRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/dpub/docTocRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/graphics/graphicsDocumentRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/graphics/graphicsObjectRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/graphics/graphicsSymbolRole.js` (safe): No malicious patterns detected; the file is a static data object defining ARIA graphics-symbol role metadata with no executable or network behavior.
- `lib/etc/roles/literal/alertRole.js` (safe): This file only defines a static ARIA role configuration object with no executable code, network activity, or malicious patterns.
- `lib/etc/roles/literal/alertdialogRole.js` (safe): No malicious patterns detected; the file only defines a static accessibility role metadata object.
- `lib/etc/roles/literal/applicationRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata with no executable code, network activity, or filesystem access.
- `lib/etc/roles/literal/articleRole.js` (safe): This file is a static ARIA role definition with no executable logic, network access, file system operations, or suspicious patterns.
- `lib/etc/roles/literal/bannerRole.js` (safe): No malicious patterns detected; the file contains only static role metadata for accessibility purposes.
- `lib/etc/roles/literal/blockquoteRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/buttonRole.js` (safe): No malicious patterns detected; this is a benign static ARIA role definition file from an accessibility library.
- `lib/etc/roles/literal/captionRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/cellRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata definitions.
- `lib/etc/roles/literal/checkboxRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, or filesystem activity.
- `lib/etc/roles/literal/codeRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/columnheaderRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, or filesystem behavior.
- `lib/etc/roles/literal/comboboxRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/complementaryRole.js` (safe): No malicious patterns detected; the file contains a static ARIA role definition with no executable or network-related code.
- `lib/etc/roles/literal/contentinfoRole.js` (safe): No malicious patterns detected; the file only defines a static ARIA role metadata object with no executable code, network activity, or filesystem access.
- `lib/etc/roles/literal/definitionRole.js` (safe): This file contains only a static WAI-ARIA role definition object with no executable logic, network calls, file operations, or other malicious patterns.
- `lib/etc/roles/literal/deletionRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/dialogRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/directoryRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/documentRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/emphasisRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/feedRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/figureRole.js` (safe): This file is a static ARIA role definition object with no executable logic, network calls, file system access, or obfuscation.
- `lib/etc/roles/literal/formRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/genericRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/graphicsDocumentRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/graphicsObjectRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/graphicsSymbolRole.js` (safe): No malicious patterns detected; the file is a static data object defining ARIA graphics-symbol role metadata with no executable or network behavior.
- `lib/etc/roles/literal/gridRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable code, network access, or filesystem interaction.
- `lib/etc/roles/literal/gridcellRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/groupRole.js` (safe): No malicious patterns detected; the file contains only a static metadata object defining accessibility role properties with no executable or dynamic behavior.
- `lib/etc/roles/literal/headingRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable or network-related code.
- `lib/etc/roles/literal/imgRole.js` (safe): The file is a static ARIA role definition object with no executable code, network calls, or suspicious patterns.
- `lib/etc/roles/literal/insertionRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no dynamic code, network, filesystem, or process activity.
- `lib/etc/roles/literal/linkRole.js` (safe): This file only defines a static ARIA link role metadata object and contains no executable or suspicious behavior.
- `lib/etc/roles/literal/listRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/listboxRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/listitemRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/logRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/mainRole.js` (safe): This file is a static ARIA role definition data object with no executable code, network calls, filesystem access, or dynamic behavior.
- `lib/etc/roles/literal/markRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/marqueeRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/mathRole.js` (safe): No malicious patterns detected; the file contains only a static data object defining an ARIA math role.
- `lib/etc/roles/literal/menuRole.js` (safe): The file contains only a static ARIA role definition object with no executable, network, filesystem, process, or obfuscated code patterns.
- `lib/etc/roles/literal/menubarRole.js` (safe): This file contains only a static ARIA role definition with no executable code, network access, or suspicious patterns.
- `lib/etc/roles/literal/menuitemRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/menuitemcheckboxRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/menuitemradioRole.js` (safe): This file contains only static ARIA role definition metadata for menuitemradioRole with no executable code, network calls, or malicious patterns.
- `lib/etc/roles/literal/meterRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata definitions.
- `lib/etc/roles/literal/navigationRole.js` (safe): No malicious patterns detected; the file only exports a static ARIA role definition object.
- `lib/etc/roles/literal/noneRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/noteRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/optionRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable code or external interactions.
- `lib/etc/roles/literal/paragraphRole.js` (safe): No malicious patterns detected; the file only defines a static accessibility role descriptor for the HTML paragraph element.
- `lib/etc/roles/literal/presentationRole.js` (safe): This file only exports a static ARIA presentation role definition object with no executable, network, filesystem, or obfuscated behavior.
- `lib/etc/roles/literal/progressbarRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/radioRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata definitions.
- `lib/etc/roles/literal/radiogroupRole.js` (safe): The file contains only static ARIA role metadata with no network, filesystem, process, or dynamic code execution behavior, indicating no malicious patterns.
- `lib/etc/roles/literal/regionRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/rowRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata definitions.
- `lib/etc/roles/literal/rowgroupRole.js` (safe): This file is a static ARIA role definition object with no executable logic, network calls, file access, or other malicious patterns.
- `lib/etc/roles/literal/rowheaderRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/scrollbarRole.js` (safe): No malicious patterns detected; the file only defines a static ARIA role metadata object with no executable or suspicious behavior.
- `lib/etc/roles/literal/searchRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata definitions.
- `lib/etc/roles/literal/searchboxRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, or filesystem behavior.
- `lib/etc/roles/literal/separatorRole.js` (safe): No malicious patterns detected; the file only defines a static ARIA role configuration object.
- `lib/etc/roles/literal/sliderRole.js` (safe): No malicious patterns detected; the file is a static ARIA role definition with no executable, network, or filesystem behavior.
- `lib/etc/roles/literal/spinbuttonRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/statusRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/strongRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/subscriptRole.js` (safe): No malicious patterns detected; the file contains only a static ARIA role definition with no executable or suspicious behavior.
- `lib/etc/roles/literal/superscriptRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/switchRole.js` (safe): No malicious patterns detected; the file contains only static ARIA role metadata with no executable or network behavior.
- `lib/etc/roles/literal/tabRole.js` (safe): The file contains only static ARIA role metadata with no executable, network, filesystem, or process-related behavior, and is not malicious.
- `lib/etc/roles/literal/tableRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/tablistRole.js` (safe): This is a static ARIA role definition file with no executable code, network calls, or suspicious patterns.
- `lib/etc/roles/literal/tabpanelRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/termRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/textboxRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/timeRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/timerRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/toolbarRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/tooltipRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/treeRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/treegridRole.js` (safe): No malicious patterns detected
- `lib/etc/roles/literal/treeitemRole.js` (safe): No malicious patterns detected
- `lib/index.js` (safe): No malicious patterns detected; the file only re-exports static map modules without any dynamic execution, network access, or filesystem operations.
- `lib/roleElementMap.js` (safe): No malicious patterns detected; the file is a standard compiled role element map helper for aria-query.
- `lib/rolesMap.js` (safe): No malicious patterns detected; the code is a standard Babel-transpiled ARIA roles map with no network, filesystem, or dynamic execution behavior.
- `lib/util/iterationDecorator.js` (safe): No malicious patterns detected
- `lib/util/iteratorProxy.js` (safe): The file implements a simple, self-contained iterator proxy utility with no network, filesystem, process, or dynamic code execution activity, and no malicious patterns were detected.

## Version ranges

None of the 2 scanned versions of aria-query are flagged high or critical. The latest scanned version, 5.3.2, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.3.0 – 5.3.2 (`>=5.3.0 <=5.3.2`): clean
- 5.1.3 (`5.1.3`): not scanned

## Scanned versions

- [5.3.2](https://security.togoder.click/npm/aria-query@5.3.2): safe, 2026-10-06T14:13:46.000Z
- [5.3.0](https://security.togoder.click/npm/aria-query@5.3.0): safe, 2026-10-06T14:12:52.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
