Togoder security

npm package security report

axe-core npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 4.13.0 Files reviewed 1 Size 6.8 KB Scanned

Summary

Togoder Security scanned the npm package axe-core@4.13.0 on Oct 6, 2026. An AI review of 1 source file produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
1
low

Findings 4

medium

DOM enumeration and internal state extraction

NPS-BA518750FD6F

The code walks the entire DOM tree (including shadow roots) and attempts to extract ElementInternals objects from custom elements using multiple property and symbol name guesses. This could be used to gather accessibility internals, form associations, roles, and labels for all elements on a page. While not directly exfiltration, this is a systematic information-gathering routine that could be used for fingerprinting or scraping page structure and semantics.

gather-internals.js
medium

Cross-shadow-root traversal

NPS-3D2BA396A849

The walkTree function recursively traverses shadow roots, allowing inspection of encapsulated DOM content. This breaks encapsulation assumptions and can expose otherwise hidden component internals.

gather-internals.js
medium

Sensitive internal property access

NPS-D24F8CD5AE7C

The getElementInternals function probes properties named '_internals', 'internals', and 'internals_', as well as symbols with descriptions 'internals' and 'privateInternals'. These are typically private implementation details. Accessing them may expose framework- or component-specific internal state that shouldn't be publicly readable.

gather-internals.js
low

Global state pollution / side effects at import

NPS-6F5FAD821A76

The module immediately invokes walkTree() at load time via require_main(), scanning the entire document and populating a global-ish array (elementInternalsMap). This runs side effects on import, which can be used to silently collect data without an explicit function call by the consumer.

gather-internals.js

Files reviewed

FileVerdictWhat the reviewer saw
gather-internals.js medium This code systematically scans the DOM (including shadow DOM) to harvest accessibility-related ElementInternals data from custom elements, which is not overtly malicious but constitutes a privacy-invasive information-gathering routine with side effects at import time.

Scanned versions of axe-core

VersionVerdictFilesScanned
4.13.0 Needs review 1 Oct 6, 2026

Frequently asked questions

Is axe-core safe to use?

No confirmed malware was found in axe-core@4.13.0, but the review flagged 3 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does axe-core contain malware?

No malware was identified in axe-core@4.13.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was axe-core checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan axe-core together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in axe-core@4.13.0, cost nothing.

Related security reports