# dotenv@17.2.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-05-15T12:29:43.000Z
- Files reviewed: 4
- Findings: no findings
- Report: https://security.togoder.click/npm/dotenv@17.2.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package dotenv@17.2.3 on May 15, 2026. An AI review of 4 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `cli-options.js` (safe): No malicious patterns detected
- `config.js` (safe): The code is a standard configuration loader for a CLI application that merges environment and command-line options without any malicious patterns.
- `env-options.js` (safe): No malicious patterns detected
- `main.js` (safe): No malicious patterns detected

## Version ranges

None of the 2 scanned versions of dotenv are flagged high or critical. The latest scanned version, 18.0.5, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 18.0.5 (`18.0.5`): medium
- 17.2.3 (`17.2.3`): clean
- 16.4.5 – 16.6.1 (`>=16.4.5 <=16.6.1`): not scanned

## Scanned versions

- [18.0.5](https://security.togoder.click/npm/dotenv@18.0.5): medium, 2026-10-04T15:39:48.000Z
- [17.2.3](https://security.togoder.click/npm/dotenv@17.2.3): safe, 2026-05-15T12:29:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
