Summary
Togoder Security scanned the npm package entities@8.1.0 on Oct 6, 2026. An AI review of 20 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
Data file
NPS-86A660673805
This file is a generated static lookup table mapping numeric entity codes to HTML entity names. It contains no executable code, no imports, no function calls, no network access, and no file system operations. The long string is a compressed encoding of the HTML entity table, not an obfuscated payload.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/decode-codepoint.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/decode.js | safe | This is a legitimate HTML/XML entity decoder from the entities package; it contains only pure string parsing logic with no network, filesystem, process, or dynamic code execution capabilities. |
| dist/encode.js | safe | The code is a legitimate HTML entity encoder implementation with no malicious patterns, no external calls, no file system access, no environment variable harvesting, and no dynamic code execution. |
| dist/escape.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/generated/decode-data-html.js | safe | No malicious patterns detected; the file contains a generated, static trie data string for HTML entity decoding with no executable or suspicious behavior. |
| dist/generated/decode-data-xml.js | safe | No malicious patterns detected; the file only contains a static Uint16Array of numeric trie data for XML decoding. |
| dist/generated/encode-html.js | safe | No malicious patterns detected; the file is a static, generated HTML entity encoding map with no executable code or security concerns. |
| dist/index.js | safe | No malicious patterns detected; the file is a standard entity encoding/decoding library with no network, filesystem, process, or dynamic code execution behavior. |
| dist/internal/bin-trie-flags.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/internal/decode-shared.js | safe | The code is a pure decoding utility for a custom base91 trie dictionary format; it performs no network, filesystem, process, or dynamic code execution operations and contains no malicious patterns. |
| src/decode-codepoint.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/decode.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/encode.ts | safe | No malicious patterns detected; this is a legitimate HTML/XML entity encoder with no network, filesystem, process, or dynamic code execution activity. |
| src/escape.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/generated/decode-data-html.ts | safe | The file contains only generated, packed trie data for HTML entity decoding and imports a benign internal decoder; no malicious patterns detected. |
| src/generated/decode-data-xml.ts | safe | No malicious patterns detected; the file only exports a static Uint16Array of packed XML decode trie data generated by a build script. |
| src/generated/encode-html.ts | safe | The file is a benign generated HTML entity encoding table containing only a static string export with no executable code or network/file/process operations. |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/internal/bin-trie-flags.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/internal/decode-shared.ts | safe | No malicious patterns detected; the code is a pure, self-contained decoder for a packed trie format with no I/O, network, filesystem, process, or dynamic execution behavior. |
Scanned versions of entities
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 8.1.0 | No issues | 20 | Oct 6, 2026 |
Frequently asked questions
Is entities safe to use?
Our AI source review of entities@8.1.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does entities contain malware?
No malware was identified in entities@8.1.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was entities checked?
Togoder Security downloaded the published npm package and had an AI model read its 20 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan entities together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in entities@8.1.0, cost nothing.