Togoder security

npm package security report

better-sqlite3@11.10.0 security report

Risky patterns found that deserve a look.

Needs review Version 11.10.0 Files reviewed 14 Size 23.7 KB Scanned

Summary

Togoder Security scanned the npm package better-sqlite3@11.10.0 on Oct 4, 2026. An AI review of 14 source files produced 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
3
low

Findings 6

medium

File system manipulation outside package scope

NPS-15CFB71B46A5

The script copies files to a destination directory specified via process.argv[2]. If this argument is controlled by an attacker, it could be used to write files outside the intended package scope. However, this is likely intended for build purposes.

deps/copy.js:6
medium

Dynamic module loading with computed path

NPS-A8CFA7D8D146

The nativeBinding option allows loading an arbitrary .node addon from a caller-supplied path using path.resolve and a computed require. While this is a documented feature, it permits dynamic native code loading from any path, which could be abused if the option value is attacker-controlled.

lib/database.js:62
medium

SQL injection / unsafe query construction

NPS-6F2D9384F087

The 'source' parameter is interpolated directly into a PRAGMA statement via template literal without sanitization or parameterization. PRAGMA statements cannot use bound parameters in SQLite, but accepting arbitrary strings here allows an attacker to inject additional SQL commands (e.g. attaching databases, altering settings, or chaining statements) if untrusted input reaches this function. This is an injection sink rather than an exfiltration mechanism, but it is a real security weakness.

lib/methods/pragma.js:9
low

Potential path traversal

NPS-21FA80ACCB12

The source path is resolved using path.resolve(path.sep, process.argv[3] || path.join(__dirname, 'sqlite3')). If process.argv[3] contains absolute paths or traversal sequences, it could read files from unintended locations. However, this is likely intended for custom builds.

deps/copy.js:7
low

Native addon loading

NPS-63E75A9E99D9

The module loads a native binary (better_sqlite3.node) via bindings at import/construction time. Native addons execute arbitrary machine code and cannot be audited in this JavaScript file; supply-chain integrity of the binary is a trust assumption.

lib/database.js:58
low

Native addon interaction (cppdb)

NPS-35D28EF766DD

The code accesses this[cppdb] and calls prepare() against a native C++ database binding. While not malicious per se, native addons execute outside the JS sandbox and are a common vector for hidden data access or process spawning that is not visible in this JS file. The behavior of the underlying binding cannot be verified from this snippet alone.

lib/methods/pragma.js

Files reviewed

FileVerdictWhat the reviewer saw
deps/copy.js medium The script performs file copying operations with user-provided paths, which could potentially be exploited for path traversal or unauthorized file writes, but no overtly malicious patterns are present.
lib/database.js medium This is the legitimate better-sqlite3 Database constructor; no malicious exfiltration, credential harvesting, shell execution, or obfuscation is present, but it dynamically loads native addons and supports an arbitrary nativeBinding path, which are inherent trust/attack-surface concerns.
lib/methods/pragma.js medium No overt malicious patterns, but the PRAGMA method builds SQL by string interpolation of an unvalidated 'source' argument, creating a SQL injection sink, and relies on an opaque native addon.
lib/index.js safe Cleared by Jev triage; no further analysis needed
lib/methods/aggregate.js safe Cleared by Jev triage; no further analysis needed
lib/methods/backup.js safe No malicious patterns detected; the code is a legitimate database backup utility that validates inputs, checks directory existence, and asynchronously transfers backup data without any network, credential, or shell access.
lib/methods/function.js safe No malicious patterns detected; the code is a standard argument validator and binding for native database user-defined functions.
lib/methods/inspect.js safe Cleared by Jev triage; no further analysis needed
lib/methods/serialize.js safe Cleared by Jev triage; no further analysis needed
lib/methods/table.js safe No malicious patterns detected; the code defines a database virtual table API with strict input validation and no external network, filesystem, or process activity.
lib/methods/transaction.js safe No malicious patterns detected
lib/methods/wrappers.js safe No malicious patterns detected; the file is a thin, straightforward wrapper exposing native database methods and properties without any of the flagged red flags.
lib/sqlite-error.js safe Cleared by Jev triage; no further analysis needed
lib/util.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is better-sqlite3 safe to use?

No confirmed malware was found in better-sqlite3@11.10.0, but the review flagged 3 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does better-sqlite3 contain malware?

No malware was identified in better-sqlite3@11.10.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was better-sqlite3 checked?

Togoder Security downloaded the published npm package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan better-sqlite3 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in better-sqlite3@11.10.0, cost nothing.

Related security reports