# dot-prop@5.3.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:15:51.000Z
- Files reviewed: 1
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/dot-prop
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package dot-prop@5.3.0 on Oct 6, 2026. An AI review of 1 source file produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Prototype pollution protection

Finding ID: `NPS-BEDE1C6C7780`

File: `index.js:4`

The code explicitly checks for and rejects disallowed keys ('__proto__', 'prototype', 'constructor') in path segments, preventing prototype pollution attacks. This is a security hardening measure, not a vulnerability.

## Files reviewed

- `index.js` (safe): No malicious patterns detected; the code implements safe object property access with built-in prototype pollution protection.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
