# entities@8.1.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:17:34.000Z
- Files reviewed: 20
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/entities
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package entities@8.1.0 on Oct 6, 2026. An AI review of 20 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Data file

Finding ID: `NPS-86A660673805`

File: `src/generated/encode-html.ts`

This file is a generated static lookup table mapping numeric entity codes to HTML entity names. It contains no executable code, no imports, no function calls, no network access, and no file system operations. The long string is a compressed encoding of the HTML entity table, not an obfuscated payload.

## Files reviewed

- `dist/decode-codepoint.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/decode.js` (safe): This is a legitimate HTML/XML entity decoder from the entities package; it contains only pure string parsing logic with no network, filesystem, process, or dynamic code execution capabilities.
- `dist/encode.js` (safe): The code is a legitimate HTML entity encoder implementation with no malicious patterns, no external calls, no file system access, no environment variable harvesting, and no dynamic code execution.
- `dist/escape.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/generated/decode-data-html.js` (safe): No malicious patterns detected; the file contains a generated, static trie data string for HTML entity decoding with no executable or suspicious behavior.
- `dist/generated/decode-data-xml.js` (safe): No malicious patterns detected; the file only contains a static Uint16Array of numeric trie data for XML decoding.
- `dist/generated/encode-html.js` (safe): No malicious patterns detected; the file is a static, generated HTML entity encoding map with no executable code or security concerns.
- `dist/index.js` (safe): No malicious patterns detected; the file is a standard entity encoding/decoding library with no network, filesystem, process, or dynamic code execution behavior.
- `dist/internal/bin-trie-flags.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/internal/decode-shared.js` (safe): The code is a pure decoding utility for a custom base91 trie dictionary format; it performs no network, filesystem, process, or dynamic code execution operations and contains no malicious patterns.
- `src/decode-codepoint.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/decode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/encode.ts` (safe): No malicious patterns detected; this is a legitimate HTML/XML entity encoder with no network, filesystem, process, or dynamic code execution activity.
- `src/escape.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/generated/decode-data-html.ts` (safe): The file contains only generated, packed trie data for HTML entity decoding and imports a benign internal decoder; no malicious patterns detected.
- `src/generated/decode-data-xml.ts` (safe): No malicious patterns detected; the file only exports a static Uint16Array of packed XML decode trie data generated by a build script.
- `src/generated/encode-html.ts` (safe): The file is a benign generated HTML entity encoding table containing only a static string export with no executable code or network/file/process operations.
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/internal/bin-trie-flags.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/internal/decode-shared.ts` (safe): No malicious patterns detected; the code is a pure, self-contained decoder for a packed trie format with no I/O, network, filesystem, process, or dynamic execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
