Togoder security

npm package security report

engine.io-parser@5.2.3 security report

No malicious code found.

No issues Version 5.2.3 Files reviewed 14 Size 32.9 KB Scanned

Summary

Togoder Security scanned the npm package engine.io-parser@5.2.3 on Oct 4, 2026. An AI review of 14 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
build/cjs/commons.js safe The file only defines static packet type constants and an error packet object with no network, filesystem, process, or dynamic execution behavior.
build/cjs/contrib/base64-arraybuffer.js safe No malicious patterns detected; the file contains only a standard base64 encoding/decoding implementation with no network, filesystem, process, or dynamic code execution activity.
build/cjs/decodePacket.browser.js safe No malicious patterns detected; the code is a standard packet decoder for a Socket.IO-like library with no data exfiltration, dynamic code execution, or suspicious behavior.
build/cjs/decodePacket.js safe No malicious patterns detected; the code implements standard packet decoding for a Socket.IO-like protocol without any exfiltration, obfuscation, or dangerous behavior.
build/cjs/encodePacket.browser.js safe No malicious patterns detected; the code performs standard packet encoding for the Socket.IO protocol using browser-native APIs without any external communication, credential access, dynamic code execution, or filesystem/process manipulation.
build/cjs/encodePacket.js safe No malicious patterns detected; the code is a standard packet encoding utility using only Node.js core APIs for data serialization.
build/cjs/index.js safe No malicious patterns detected
build/esm/commons.js safe Cleared by Jev triage; no further analysis needed
build/esm/contrib/base64-arraybuffer.js safe This is a standard base64 encode/decode implementation for ArrayBuffer with no malicious patterns, network calls, or environment access.
build/esm/decodePacket.browser.js safe Cleared by Jev triage; no further analysis needed
build/esm/decodePacket.js safe The code is a straightforward packet decoder for Socket.IO with no malicious patterns, external network calls, or dynamic code execution.
build/esm/encodePacket.browser.js safe No malicious patterns detected; the code is a standard packet encoding utility for socket.io with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
build/esm/encodePacket.js safe Cleared by Jev triage; no further analysis needed
build/esm/index.js safe No malicious patterns detected; the code implements packet encoding/decoding for the Socket.IO protocol using standard patterns.

Frequently asked questions

Is engine.io-parser safe to use?

Our AI source review of engine.io-parser@5.2.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does engine.io-parser contain malware?

No malware was identified in engine.io-parser@5.2.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was engine.io-parser checked?

Togoder Security downloaded the published npm package and had an AI model read its 14 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan engine.io-parser together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in engine.io-parser@5.2.3, cost nothing.

Related security reports