Togoder security

npm package security report

entities npm package: is it safe?

No malicious code found.

No issues Version 8.1.0 Files reviewed 20 Size 229.4 KB Scanned

Summary

Togoder Security scanned the npm package entities@8.1.0 on Oct 6, 2026. An AI review of 20 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Data file

NPS-86A660673805

This file is a generated static lookup table mapping numeric entity codes to HTML entity names. It contains no executable code, no imports, no function calls, no network access, and no file system operations. The long string is a compressed encoding of the HTML entity table, not an obfuscated payload.

src/generated/encode-html.ts

Files reviewed

FileVerdictWhat the reviewer saw
dist/decode-codepoint.js safe Cleared by Jev triage; no further analysis needed
dist/decode.js safe This is a legitimate HTML/XML entity decoder from the entities package; it contains only pure string parsing logic with no network, filesystem, process, or dynamic code execution capabilities.
dist/encode.js safe The code is a legitimate HTML entity encoder implementation with no malicious patterns, no external calls, no file system access, no environment variable harvesting, and no dynamic code execution.
dist/escape.js safe Cleared by Jev triage; no further analysis needed
dist/generated/decode-data-html.js safe No malicious patterns detected; the file contains a generated, static trie data string for HTML entity decoding with no executable or suspicious behavior.
dist/generated/decode-data-xml.js safe No malicious patterns detected; the file only contains a static Uint16Array of numeric trie data for XML decoding.
dist/generated/encode-html.js safe No malicious patterns detected; the file is a static, generated HTML entity encoding map with no executable code or security concerns.
dist/index.js safe No malicious patterns detected; the file is a standard entity encoding/decoding library with no network, filesystem, process, or dynamic code execution behavior.
dist/internal/bin-trie-flags.js safe Cleared by Jev triage; no further analysis needed
dist/internal/decode-shared.js safe The code is a pure decoding utility for a custom base91 trie dictionary format; it performs no network, filesystem, process, or dynamic code execution operations and contains no malicious patterns.
src/decode-codepoint.ts safe Cleared by Jev triage; no further analysis needed
src/decode.ts safe Cleared by Jev triage; no further analysis needed
src/encode.ts safe No malicious patterns detected; this is a legitimate HTML/XML entity encoder with no network, filesystem, process, or dynamic code execution activity.
src/escape.ts safe Cleared by Jev triage; no further analysis needed
src/generated/decode-data-html.ts safe The file contains only generated, packed trie data for HTML entity decoding and imports a benign internal decoder; no malicious patterns detected.
src/generated/decode-data-xml.ts safe No malicious patterns detected; the file only exports a static Uint16Array of packed XML decode trie data generated by a build script.
src/generated/encode-html.ts safe The file is a benign generated HTML entity encoding table containing only a static string export with no executable code or network/file/process operations.
src/index.ts safe Cleared by Jev triage; no further analysis needed
src/internal/bin-trie-flags.ts safe Cleared by Jev triage; no further analysis needed
src/internal/decode-shared.ts safe No malicious patterns detected; the code is a pure, self-contained decoder for a packed trie format with no I/O, network, filesystem, process, or dynamic execution behavior.

Scanned versions of entities

VersionVerdictFilesScanned
8.1.0 No issues 20 Oct 6, 2026

Frequently asked questions

Is entities safe to use?

Our AI source review of entities@8.1.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does entities contain malware?

No malware was identified in entities@8.1.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was entities checked?

Togoder Security downloaded the published npm package and had an AI model read its 20 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan entities together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in entities@8.1.0, cost nothing.

Related security reports