# cookie-signature@1.0.7 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:22:16.000Z
- Files reviewed: 1
- Findings: 1 medium severity finding
- Report: https://security.togoder.click/npm/cookie-signature@1.0.7
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package cookie-signature@1.0.7 on Oct 4, 2026. An AI review of 1 source file produced 1 medium severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Weak cryptographic comparison

Finding ID: `NPS-5715150A44C5`

File: `index.js:47`

The unsign function validates the signature using a non-constant-time comparison (sha1(mac) == sha1(val)). This is vulnerable to timing attacks, allowing an attacker to incrementally guess the correct signature. It also unnecessarily hashes the HMAC before comparison, which, while harmless here, is a non-standard pattern that weakens the security intent relative to a direct constant-time comparison.

## Files reviewed

- `index.js` (medium): The file implements cookie signing/unsigning logic without malicious patterns, but uses a non-constant-time signature comparison that is vulnerable to timing attacks.

## Version ranges

None of the 3 scanned versions of cookie-signature are flagged high or critical. The latest scanned version, 1.2.2, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.2.2 (`1.2.2`): clean
- 1.0.7 (`1.0.7`): medium (Weak cryptographic comparison)
- 1.0.6 (`1.0.6`): clean

## Scanned versions

- [1.2.2](https://security.togoder.click/npm/cookie-signature@1.2.2): safe, 2026-10-04T14:41:23.000Z
- [1.0.7](https://security.togoder.click/npm/cookie-signature@1.0.7): medium, 2026-10-04T16:22:16.000Z
- [1.0.6](https://security.togoder.click/npm/cookie-signature@1.0.6): safe, 2026-10-04T16:51:34.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
