# caniuse-lite@1.0.30001810 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:14:44.000Z
- Files reviewed: 838
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/caniuse-lite
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package caniuse-lite@1.0.30001810 on Oct 6, 2026. An AI review of 838 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Obfuscated code / encoded data

Finding ID: `NPS-D6A0465599AE`

File: `data/features/xhr2.js:1`

The file contains heavily obfuscated data with many short, meaningless identifiers (e.g., _Z, _A, _K, _I) and nested object structures. While no direct malicious behavior is evident, the obfuscation is suspicious and could conceal malicious logic or encoded payloads. Such patterns are often used to hide data exfiltration, dynamic code execution, or other malicious activities.

### [low] Dynamic module loading

Finding ID: `NPS-45930D4DDE8B`

File: `dist/unpacker/features.js:6`

The file uses require('../../data/features') with a relative path that traverses outside the current directory (../../). While the comment states this is done to keep the module out of the rollup bundle, dynamic relative requires can load unexpected or attacker-controlled modules if the package structure is manipulated. However, the path is static and not computed from external input, so the risk is limited.

### [low] Top-level code execution on import

Finding ID: `NPS-BAFB73FC80D7`

File: `dist/unpacker/features.js:6`

The require() call executes at module load time, meaning any side effects in '../../data/features' will run when this module is imported. This is standard for CommonJS but could be abused if the referenced file is replaced or contains malicious code. The referenced file is not provided for inspection.

## Files reviewed

- `data/features/xhr2.js` (medium): The file contains obfuscated code that may hide malicious patterns, but no clear malicious behavior is detected.
- `dist/unpacker/features.js` (medium): The code contains a dynamic relative require that executes at import time, which is a minor security concern but no overt malicious patterns were detected.
- `data/agents.js` (safe): The file is a static browser compatibility data table (Browserslist-style) with no executable code, network calls, or suspicious patterns.
- `data/browserVersions.js` (safe): No malicious patterns detected
- `data/browsers.js` (safe): No malicious patterns detected
- `data/features.js` (safe): No malicious patterns detected; this file is a static feature-detection registry that only requires local sibling modules.
- `data/features/aac.js` (safe): The file contains only static feature-detection metadata for the AAC audio format and exhibits no malicious patterns.
- `data/features/abortcontroller.js` (safe): No malicious patterns detected; the file contains only static feature-detection data with no executable code or suspicious behavior.
- `data/features/ac3-ec3.js` (safe): No malicious patterns detected; the file contains only static feature-detection data for AC-3/EC-3 codec support.
- `data/features/accelerometer.js` (safe): This file contains only static feature-detection metadata (likely Babel/core-js browser capability data) with no executable code, network calls, or other malicious patterns.
- `data/features/addeventlistener.js` (safe): No malicious patterns detected; the file contains a static data object with feature detection metadata and no executable or suspicious code.
- `data/features/alternate-stylesheet.js` (safe): This file contains only static browser feature-detection data with no executable or malicious patterns.
- `data/features/ambient-light.js` (safe): No malicious patterns detected; the file contains only minified feature-detection data for the Ambient Light Sensor API.
- `data/features/apng.js` (safe): No malicious patterns detected; the file contains only static feature detection metadata
- `data/features/array-find-index.js` (safe): No malicious patterns detected
- `data/features/array-find.js` (safe): No malicious patterns detected
- `data/features/array-flat.js` (safe): This file is a static browserslist feature-detection data map for the Array.flat/flatMap method, containing no executable code, network activity, or malicious patterns.
- `data/features/array-includes.js` (safe): No malicious patterns detected; the file contains only static feature-detection metadata for Array.prototype.includes with no executable code or external interactions.
- `data/features/arrow-functions.js` (safe): No malicious patterns detected; the file is a static data structure for arrow function feature detection with no executable or network activity.
- `data/features/asmjs.js` (safe): No malicious patterns detected
- `data/features/async-clipboard.js` (safe): No malicious patterns detected; the file contains a minified static feature-support matrix for the Asynchronous Clipboard API with no executable logic, network calls, or filesystem access.
- `data/features/async-functions.js` (safe): No malicious patterns detected; the file is a static feature-detection data table for async functions.
- `data/features/atob-btoa.js` (safe): No malicious patterns detected
- `data/features/audio-api.js` (safe): No malicious patterns detected
- `data/features/audio.js` (safe): No malicious patterns detected
- `data/features/audiotracks.js` (safe): No malicious patterns detected; the code is a static data structure mapping audio track feature detection keys to numeric feature flags.
- `data/features/autofocus.js` (safe): No malicious patterns detected
- `data/features/auxclick.js` (safe): No malicious patterns detected; the file is a benign static feature-detection data structure for the 'Auxclick' browser API.
- `data/features/av1.js` (safe): No malicious patterns detected; the file contains only static feature-detection data for AV1 video format.
- `data/features/avif.js` (safe): No malicious patterns detected; the code is a static data object for the 'avif' feature, containing only format detection keys and values with no executable logic, network requests, or environment access.
- `data/features/background-attachment.js` (safe): The file contains only a static data object mapping feature detection flags for CSS background-attachment, with no executable code, obfuscation, network activity, or other malicious patterns.
- `data/features/background-clip-text.js` (safe): The file contains only static data (likely a minified feature detection map) with no executable code, network access, file operations, or other malicious patterns.
- `data/features/background-img-opts.js` (safe): No malicious patterns detected; the file contains only a static data module mapping browser feature identifiers with no executable code, network activity, or filesystem access.
- `data/features/background-position-x-y.js` (safe): No malicious patterns detected
- `data/features/background-repeat-round-space.js` (safe): No malicious patterns detected
- `data/features/background-sync.js` (safe): No malicious patterns detected
- `data/features/battery-status.js` (safe): No malicious patterns detected; the file contains only a static feature-detection data structure for the Battery Status API.
- `data/features/beacon.js` (safe): No malicious patterns detected; the file contains only a static feature-detection table for the Beacon API.
- `data/features/beforeafterprint.js` (safe): The file is a static data export with no executable code or suspicious patterns.
- `data/features/bigint.js` (safe): No malicious patterns detected; the file contains static feature-detection data for BigInt compatibility tables with no executable code.
- `data/features/blobbuilder.js` (safe): No malicious patterns detected; the file contains only static feature-detection metadata with no executable code, network requests, or suspicious behavior.
- `data/features/bloburls.js` (safe): This is a static feature-detection/data table for Blob URLs with no executable code, network access, filesystem operations, or obfuscated payloads.
- `data/features/border-image.js` (safe): The file contains only static browser-compatibility data with no executable or malicious code.
- `data/features/border-radius.js` (safe): No malicious patterns detected; the file is a benign feature-detection data structure for CSS border-radius support.
- `data/features/broadcastchannel.js` (safe): The file contains a static data object representing Browserify/browserslist feature support data for BroadcastChannel, with no executable code, network activity, or suspicious patterns.
- `data/features/brotli.js` (safe): The file contains only static feature-detection data related to Brotli Accept-Encoding/Content-Encoding support, with no executable, obfuscated, or network-related code.
- `data/features/calc.js` (safe): The file contains only a static data object for CSS calc() feature support, with no executable code, network requests, file system access, or other malicious patterns.
- `data/features/canvas-blending.js` (safe): The file is a static feature data object (likely a browser compatibility table) with no executable code, network access, filesystem manipulation, or malicious patterns.
- `data/features/canvas-text.js` (safe): This file is a Canvas Text API feature-detection metadata map; it contains no executable logic, network access, obfuscation, or suspicious patterns.
- `data/features/canvas.js` (safe): No malicious patterns detected; the file is a static Babel feature-detection metadata object with no executable code or suspicious behavior.
- `data/features/ch-unit.js` (safe): No malicious patterns detected; the file contains only a static data object mapping indicating feature availability for the 'ch' character unit, likely part of a polyfill configuration.
- `data/features/chacha20-poly1305.js` (safe): No malicious patterns detected; the file contains only browser feature detection metadata for ChaCha20-Poly1305 TLS cipher suites.
- `data/features/channel-messaging.js` (safe): No malicious patterns detected
- `data/features/childnode-remove.js` (safe): The file contains only a static feature-detection flag object for 'ChildNode.remove()'; no malicious patterns, obfuscation, network activity, or execution logic are present.
- `data/features/classlist.js` (safe): The file contains only static feature-detection metadata for classList support; no executable, obfuscated, or network-related code is present.
- `data/features/client-hints-dpr-width-viewport.js` (safe): This file is a static Babel/browser-compat-data feature descriptor object with no executable code, network requests, or suspicious patterns.
- `data/features/clipboard.js` (safe): No malicious patterns detected; the file contains only a minified data object likely used for browser feature detection.
- `data/features/colr-v1.js` (safe): No malicious patterns detected; the file is a static feature-detection data module for COLR/CPAL v1 font format support.
- `data/features/colr.js` (safe): The file is a static Babel-generated feature detection table for COLR/CPAL font formats with no executable code or malicious patterns.
- `data/features/comparedocumentposition.js` (safe): The file contains only static data mapping for feature detection and exhibits no malicious patterns.
- `data/features/console-basic.js` (safe): No malicious patterns detected; the file contains only a static data/feature-detection object with no executable code, network calls, or suspicious behavior.
- `data/features/console-time.js` (safe): No malicious patterns detected; the file is a static feature-detection data object with no executable code.
- `data/features/const.js` (safe): No malicious patterns detected; the file contains only a minified static feature-detection data object for the 'const' JavaScript feature.
- `data/features/constraint-validation.js` (safe): The file is a static data table (likely from Can I Use/browser feature support data) with no executable code, no suspicious imports, and no behavior beyond exporting a configuration object.
- `data/features/contenteditable.js` (safe): No malicious patterns detected; the file contains a static data structure describing contenteditable feature support with no executable code, network activity, or suspicious behavior.
- `data/features/contentsecuritypolicy.js` (safe): This is a benign, minified feature-detection data file for Content Security Policy 1.0 with no executable code, network calls, or malicious patterns.
- `data/features/contentsecuritypolicy2.js` (safe): The file is a static Babel/TypeScript helper mapping object with no executable code, network activity, credential access, or malicious patterns.
- `data/features/cookie-store-api.js` (safe): No malicious patterns detected; the file is a standard Babel-generated browser feature detection configuration with no executable or obfuscated code.
- `data/features/cors.js` (safe): No malicious patterns detected; the file is a benign CommonJS module exporting a static data object related to Cross-Origin Resource Sharing.
- `data/features/createimagebitmap.js` (safe): No malicious patterns detected; the file contains only a minified data structure likely used for browser feature detection.
- `data/features/credential-management.js` (safe): No malicious patterns detected; the file is a static Babel/webpack runtime configuration object with no executable, network, or filesystem behavior.
- `data/features/cross-document-view-transitions.js` (safe): No malicious patterns detected; the file is a static data export of feature detection flags for cross-document view transitions.
- `data/features/cryptography.js` (safe): No malicious patterns detected; the file contains only static feature-flag metadata for Web Cryptography.
- `data/features/css-all.js` (safe): No malicious patterns detected
- `data/features/css-anchor-positioning.js` (safe): No malicious patterns detected; this is a static data file exporting feature support metadata with no executable code.
- `data/features/css-animation.js` (safe): The file contains only static browser feature detection data with no executable, obfuscated, or network-related code, so no malicious patterns were detected.
- `data/features/css-any-link.js` (safe): No malicious patterns detected
- `data/features/css-appearance.js` (safe): No malicious patterns detected; the file contains only static data used for feature detection in a CSS appearance polyfill.
- `data/features/css-at-counter-style.js` (safe): No malicious patterns detected
- `data/features/css-autofill.js` (safe): The file contains only a minified mapping object of CSS autofill feature identifiers to internal codes, with no executable code, network activity, file system access, or other malicious patterns.
- `data/features/css-backdrop-filter.js` (safe): No malicious patterns detected; the file contains only minified feature-detection metadata for CSS Backdrop Filter support.
- `data/features/css-background-offsets.js` (safe): No malicious patterns detected; the file contains only a static data object mapping feature support flags to browser versions.
- `data/features/css-backgroundblendmode.js` (safe): No malicious patterns detected
- `data/features/css-boxdecorationbreak.js` (safe): This file is a minified feature-support data table for the caniuse-lite database (CSS box-decoration-break), containing only static encoded strings and booleans with no executable code, network calls, file access, or other malicious patterns.
- `data/features/css-boxshadow.js` (safe): This file is a benign caniuse-lite browser support data table for the CSS box-shadow feature with no executable code, network calls, or malicious patterns.
- `data/features/css-canvas.js` (safe): No malicious patterns detected
- `data/features/css-caret-color.js` (safe): No malicious patterns detected
- `data/features/css-cascade-layers.js` (safe): No malicious patterns detected; the file contains only minified browser compatibility metadata with no executable code, network activity, or file system access.
- `data/features/css-cascade-scope.js` (safe): The file contains only a static data object mapping browser feature support flags with no executable code, network activity, or suspicious patterns.
- `data/features/css-case-insensitive.js` (safe): No malicious patterns detected; the file contains only static feature-detection metadata for CSS case-insensitive attribute selectors.
- `data/features/css-clip-path.js` (safe): This file contains only static feature-detection data for CSS clip-path support across browsers, with no executable code or malicious patterns.
- `data/features/css-color-adjust.js` (safe): This file is a static data export (likely caniuse/browserslist feature data) with no executable code, network access, file operations, or other malicious patterns.
- `data/features/css-color-function.js` (safe): No malicious patterns detected; the file is a static feature-detection data object with no executable or network-related behavior.
- `data/features/css-conic-gradients.js` (safe): No malicious patterns detected; the file contains only static feature-detection data with no executable or obfuscated code.
- `data/features/css-container-queries-style.js` (safe): The file contains only a static feature-database export mapping CSS Container Style Queries to browser support flags, with no executable code, network requests, filesystem access, or other malicious patterns.
- `data/features/css-container-queries.js` (safe): No malicious patterns detected; the file contains only a static data export using minified property keys.
- `data/features/css-container-query-units.js` (safe): No malicious patterns detected; the file contains only static browser compatibility data with no executable code, network calls, or filesystem access.
- `data/features/css-containment.js` (safe): The code is a static data export with no executable logic, imports, network, file system, or dynamic code execution patterns.
- `data/features/css-content-visibility.js` (safe): The file contains a minified data object likely representing a feature support matrix for a CSS feature, with no executable code, suspicious patterns, or malicious behavior detected.
- `data/features/css-counters.js` (safe): No malicious patterns detected; the file contains only static CSS counter feature-support metadata with no executable, network, or filesystem behavior.
- `data/features/css-crisp-edges.js` (safe): The file contains only a static data export (likely browser compatibility feature metadata) with no executable code, network calls, credential access, or other malicious patterns.
- `data/features/css-cross-fade.js` (safe): No malicious patterns detected; the file contains only static feature-detection data with no executable code, network access, or suspicious behavior.
- `data/features/css-default-pseudo.js` (safe): This file is a static feature/data table mapping browser feature flags, with no executable code, network calls, or suspicious patterns.
- `data/features/css-descendant-gtgt.js` (safe): No malicious patterns detected; the file is a static Babel/browser compatibility data module with no executable code, network access, or sensitive operations.
- `data/features/css-deviceadaptation.js` (safe): No malicious patterns detected; the file contains only a static data export of CSS Device Adaptation feature flags.
- `data/features/css-dir-pseudo.js` (safe): No malicious patterns detected; the file contains only static, minified data mappings with no executable code, network requests, or filesystem access.
- `data/features/css-display-contents.js` (safe): This file contains only minified static browser compatibility data for CSS display:contents; no executable, network, filesystem, or process-related code is present.
- `data/features/css-element-function.js` (safe): No malicious patterns detected
- `data/features/css-env-function.js` (safe): No malicious patterns detected; the file is a static data/feature definition for CSS Environment Variables env() and contains no executable code, network activity, or credential access.
- `data/features/css-exclusions.js` (safe): No malicious patterns detected; the file contains only a static data table, likely feature detection metadata, with no executable logic or suspicious behavior.
- `data/features/css-featurequeries.js` (safe): The file is a static data structure for CSS Feature Queries browser support metadata with no executable or malicious code.
- `data/features/css-file-selector-button.js` (safe): The file contains only minified feature-support flag data with no executable code, network access, or obfuscated payloads.
- `data/features/css-filter-function.js` (safe): This file is a static Babel/browser compatibility feature detection mapping with no executable code, network access, or suspicious patterns.
- `data/features/css-filters.js` (safe): No malicious patterns detected; the file is a standard Babel metadata object containing CSS filter feature support data.
- `data/features/css-first-letter.js` (safe): No malicious patterns detected; the file contains only static caniuse feature data for the ::first-letter CSS pseudo-element.
- `data/features/css-first-line.js` (safe): No malicious patterns detected; the file contains only a static feature-support data map with no executable logic, network access, or system interaction.
- `data/features/css-fixed.js` (safe): No malicious patterns detected
- `data/features/css-focus-visible.js` (safe): No malicious patterns detected; the file is a static Babel/browser-compatibility data table with no executable logic, network access, or filesystem operations.
- `data/features/css-focus-within.js` (safe): The file is a static metadata/feature-definition object (CSS :focus-within support data) with no executable code, network access, file system operations, or other malicious patterns.
- `data/features/css-font-palette.js` (safe): No malicious patterns detected; the file is a static feature-support data table with no executable behavior.
- `data/features/css-font-rendering-controls.js` (safe): No malicious patterns detected
- `data/features/css-font-stretch.js` (safe): No malicious patterns detected
- `data/features/css-gencontent.js` (safe): No malicious patterns detected; the file is a benign static data structure (likely from a browser compatibility database such as caniuse) with no executable code or security concerns.
- `data/features/css-gradients.js` (safe): The file is a static Babel browser support data table (CSS Gradients feature) with no executable code, network calls, or suspicious patterns.
- `data/features/css-grid-animation.js` (safe): The file contains only a static data configuration object for CSS Grid animation feature detection with no executable, network, filesystem, or obfuscated code.
- `data/features/css-grid-lanes.js` (safe): The file contains only static, minified feature-detection metadata with no executable code, network activity, or suspicious patterns.
- `data/features/css-grid.js` (safe): No malicious patterns detected; the file is a standard minified feature-detection data module with no executable code, network access, or filesystem operations.
- `data/features/css-hanging-punctuation.js` (safe): No malicious patterns detected; the file contains only static feature-flag metadata for CSS hanging-punctuation support.
- `data/features/css-has.js` (safe): The file is a static CSS feature support data module (likely from caniuse-lite) with no executable code or malicious patterns.
- `data/features/css-hyphens.js` (safe): No malicious patterns detected; the file is a static data structure used by Babel feature detection.
- `data/features/css-if.js` (safe): No malicious patterns detected
- `data/features/css-image-orientation.js` (safe): No malicious patterns detected
- `data/features/css-image-set.js` (safe): No malicious patterns detected
- `data/features/css-in-out-of-range.js` (safe): No malicious patterns detected; the file is a static data module (likely a Babel feature mapping) with no executable or suspicious code.
- `data/features/css-indeterminate-pseudo.js` (safe): No malicious patterns detected
- `data/features/css-initial-letter.js` (safe): No malicious patterns detected; the file contains static data tables likely generated for browser feature detection.
- `data/features/css-initial-value.js` (safe): No malicious patterns detected; the file is a static feature-support data object with no executable code or suspicious behavior.
- `data/features/css-lch-lab.js` (safe): The file contains only static feature support data with no executable code, network requests, or malicious patterns.
- `data/features/css-letter-spacing.js` (safe): No malicious patterns detected
- `data/features/css-line-clamp.js` (safe): The file contains only a minified/compressed feature detection data object with no executable code or malicious patterns.
- `data/features/css-logical-props.js` (safe): This file is a static feature-detection data structure mapping CSS Logical Properties support with no executable, network, or filesystem operations.
- `data/features/css-marker-pseudo.js` (safe): The file contains only static feature flag data with no executable code or malicious patterns.
- `data/features/css-masks.js` (safe): The file contains only static feature-flag metadata for CSS Masks, with no executable, network, filesystem, or obfuscated code.
- `data/features/css-matches-pseudo.js` (safe): The file is minified browser feature-detection data (can I use / CSS pseudo-class support table) with no executable code, obfuscation, network access, or suspicious patterns.
- `data/features/css-math-functions.js` (safe): No malicious patterns detected
- `data/features/css-media-interaction.js` (safe): This file contains only a static object literal mapping feature names to support flags for a CSS media query feature; no executable code or suspicious patterns are present.
- `data/features/css-media-range-syntax.js` (safe): No malicious patterns detected
- `data/features/css-media-resolution.js` (safe): No malicious patterns detected; the file contains a static feature-data mapping object with no executable or network activity.
- `data/features/css-media-scripting.js` (safe): This is a static Babel feature-detection data table with no executable code, network calls, file system access, or suspicious patterns.
- `data/features/css-mediaqueries.js` (safe): No malicious patterns detected; the file contains only static CSS feature support data with no executable code or suspicious behavior.
- `data/features/css-mixblendmode.js` (safe): No malicious patterns detected; the file is a static data structure (likely a Babel feature flag configuration) with no executable code, network requests, or suspicious behavior.
- `data/features/css-module-scripts.js` (safe): The file is a static data export of feature-detection flags with no executable code, network access, or malicious patterns.
- `data/features/css-motion-paths.js` (safe): The file is a static, minified data export (likely Babel/browser compatibility metadata for CSS Motion Path) with no executable code, network activity, or suspicious patterns.
- `data/features/css-namespaces.js` (safe): No malicious patterns detected; the file contains only static feature-detection data for CSS namespace support.
- `data/features/css-nesting.js` (safe): This is a minified data/feature-support table (likely from caniuse-lite or similar) containing only static property mappings with no executable, network, or file system behavior.
- `data/features/css-not-sel-list.js` (safe): The file is a benign Babel/feature data table (compat data for CSS :not() selector list) with no executable code or malicious patterns.
- `data/features/css-nth-child-of.js` (safe): The file is a static feature-detection data module (likely a Babel preset or browser-compat data) containing only a plain object export with no executable, network, filesystem, or process-spawning behavior.
- `data/features/css-opacity.js` (safe): No malicious patterns detected
- `data/features/css-optional-pseudo.js` (safe): No malicious patterns detected; the file is a static data module describing CSS optional pseudo-class feature support.
- `data/features/css-overflow-anchor.js` (safe): No malicious patterns detected; the file contains only a static data structure with no executable code, network activity, file access, or process spawning.
- `data/features/css-overflow-overlay.js` (safe): No malicious patterns detected; the file contains only minified CSS feature support data with no executable or network code.
- `data/features/css-overflow.js` (safe): No malicious patterns detected; the file contains only static feature-detection data with obfuscated property names and no executable code.
- `data/features/css-overscroll-behavior.js` (safe): No malicious patterns detected; the file contains only minified browser feature detection data for CSS overscroll-behavior.
- `data/features/css-page-break.js` (safe): The file contains only a static data object with feature flags and no executable code, network calls, or other suspicious patterns.
- `data/features/css-paged-media.js` (safe): The file contains only static minified data mapping feature flags and CSS Paged Media support, with no executable, network, filesystem, or obfuscated malicious code.
- `data/features/css-paint-api.js` (safe): No malicious patterns detected; the file is a static feature-detection data structure with no executable code.
- `data/features/css-placeholder-shown.js` (safe): This is a static data table (likely browser compatibility metadata) with no executable code, network calls, or suspicious patterns.
- `data/features/css-placeholder.js` (safe): No malicious patterns detected; the file contains only a static feature-detection data structure.
- `data/features/css-print-color-adjust.js` (safe): No malicious patterns detected; the file contains only a minified data structure mapping feature support flags and property names, with no executable code or suspicious behavior.
- `data/features/css-read-only-write.js` (safe): No malicious patterns detected; this is a Babel runtime helper or feature detection data object with no executable code or suspicious behavior.
- `data/features/css-rebeccapurple.js` (safe): No malicious patterns detected; the file is a benign data module for feature detection.
- `data/features/css-reflections.js` (safe): No malicious patterns detected; the file contains a static data structure (likely a feature definition or compatibility table) with no executable code, network activity, or filesystem access.
- `data/features/css-regions.js` (safe): No malicious patterns detected; the file is a static, minified data export containing browser feature-support metadata with no executable, network, filesystem, or credential-access behavior.
- `data/features/css-relative-colors.js` (safe): No malicious patterns detected
- `data/features/css-repeating-gradients.js` (safe): This file is a static feature-detection data table for CSS repeating gradients with no executable code, network requests, or suspicious patterns.
- `data/features/css-resize.js` (safe): No malicious patterns detected; the file contains only a static data structure likely generated by a browser compatibility database.
- `data/features/css-revert-value.js` (safe): The file contains only a static data object with references and no executable or malicious code patterns.
- `data/features/css-rrggbbaa.js` (safe): This file contains a static feature detection data object for the CSS #rrggbbaa hex color notation, with no executable code, network activity, or malicious patterns.
- `data/features/css-scroll-behavior.js` (safe): This is a standard Babel-generated browser feature detection data file with no executable code or malicious patterns.
- `data/features/css-scrollbar.js` (safe): No malicious patterns detected; the file contains only static, minified data used for feature detection and does not execute code, access the network, or manipulate the file system.
- `data/features/css-sel2.js` (safe): No malicious patterns detected; the file is a benign static compatibility data map for CSS selectors.
- `data/features/css-sel3.js` (safe): No malicious patterns detected; the file is a static data export for CSS3 selector feature mappings with no executable code, network access, or filesystem manipulation.
- `data/features/css-selection.js` (safe): No malicious patterns detected; the file contains only static CSS feature-support metadata.
- `data/features/css-shapes.js` (safe): The file contains only a static data object with browser compatibility information and no executable code or malicious patterns.
- `data/features/css-snappoints.js` (safe): No malicious patterns detected; the file is a static feature flag lookup table with no executable or network behavior
- `data/features/css-sticky.js` (safe): No malicious patterns detected; the file is a minified feature data object with no executable code.
- `data/features/css-subgrid.js` (safe): No malicious patterns detected; the file contains only static minified browser compatibility data.
- `data/features/css-supports-api.js` (safe): No malicious patterns detected
- `data/features/css-table.js` (safe): No malicious patterns detected; the file contains only static feature detection data for CSS Table display.
- `data/features/css-text-align-last.js` (safe): The file is a static caniuse-style feature support data object containing only short string identifiers and booleans, with no executable code, network access, filesystem operations, credential harvesting, or dynamic code execution.
- `data/features/css-text-box-trim.js` (safe): No malicious patterns detected; the file contains only static feature-detection metadata for CSS Text Box.
- `data/features/css-text-indent.js` (safe): No malicious patterns detected; the file is a static data export of CSS feature support information with no executable logic, network access, or system interaction.
- `data/features/css-text-justify.js` (safe): No malicious patterns detected; the file contains only a static data object mapping browser support keys for CSS text-justify, with no executable code or suspicious behavior.
- `data/features/css-text-orientation.js` (safe): No malicious patterns detected; the file contains only static configuration data for CSS text-orientation feature detection.
- `data/features/css-text-spacing.js` (safe): This file contains only a static data object mapping feature identifiers, with no executable code, network activity, or suspicious patterns.
- `data/features/css-text-wrap-balance.js` (safe): No malicious patterns detected; the file contains only a static feature-detection data object for CSS text-wrap: balance.
- `data/features/css-textshadow.js` (safe): No malicious patterns detected
- `data/features/css-touch-action.js` (safe): No malicious patterns detected; the file contains only static configuration data for the CSS touch-action property.
- `data/features/css-transitions.js` (safe): No malicious patterns detected; the file is a minified feature-detection module containing only static configuration data with no executable or suspicious code.
- `data/features/css-unicode-bidi.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
