Togoder security

npm package security report

eslint-plugin-import npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.32.0 Files reviewed 76 Size 1.1 MB Scanned

Summary

Togoder Security scanned the npm package eslint-plugin-import@2.32.0 on Oct 6, 2026. An AI review of 76 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

Dynamic code execution

NPS-4F90B9C9DF7F

Uses vm.runInNewContext to evaluate a string constructed from ESLint block comment contents. While the intent is to mirror webpack's comment parsing, invoking a VM on comment text is a dynamic code execution pattern. The generated code is wrapped in an object literal, but the input is file content controlled by the project being linted, so it is an unnecessary and risk-prone use of a sandbox evaluator in a lint rule.

lib/rules/dynamic-import-chunkname.js:110
low

No malicious patterns detected

NPS-90008CDD6017

This file is part of eslint-plugin-import and contains only legitimate module import type resolution logic. It uses standard Node.js path utilities and package resolution helpers. No data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, network requests, process spawning, or install-time hooks are present.

lib/core/importType.js
low

ESLint rule definition

NPS-DAE185BAAE44

This file is a standard ESLint rule implementation for forbidding Node.js builtin module imports. It uses common ESLint patterns: requiring utility modules, defining meta/schema, and reporting lint violations with context.report. No network, filesystem, process, eval, or credential access is present.

lib/rules/no-nodejs-modules.js

Files reviewed

FileVerdictWhat the reviewer saw
lib/rules/dynamic-import-chunkname.js medium No exfiltration, credential harvesting, network, or process execution behavior, but the rule uses vm.runInNewContext on comment text, a dynamic execution pattern that warrants review.
config/electron.js safe Cleared by Jev triage; no further analysis needed
config/errors.js safe Cleared by Jev triage; no further analysis needed
config/flat/errors.js safe Cleared by Jev triage; no further analysis needed
config/flat/react.js safe Cleared by Jev triage; no further analysis needed
config/flat/recommended.js safe Cleared by Jev triage; no further analysis needed
config/flat/warnings.js safe Cleared by Jev triage; no further analysis needed
config/react-native.js safe Cleared by Jev triage; no further analysis needed
config/react.js safe Cleared by Jev triage; no further analysis needed
config/recommended.js safe Cleared by Jev triage; no further analysis needed
config/stage-0.js safe Cleared by Jev triage; no further analysis needed
config/typescript.js safe Cleared by Jev triage; no further analysis needed
config/warnings.js safe Cleared by Jev triage; no further analysis needed
lib/core/importType.js safe The code is a standard ESLint plugin utility for classifying import types with no security concerns.
lib/core/packagePath.js safe No malicious patterns detected
lib/core/sourceType.js safe No malicious patterns detected
lib/core/staticRequire.js safe No malicious patterns detected; the code is a benign AST utility that checks for static require() calls.
lib/docsUrl.js safe No malicious patterns detected; the file is a simple utility that generates documentation URLs from the package version.
lib/exportMap/builder.js safe No malicious patterns detected; this is a standard ESLint plugin module for building export maps of JavaScript/TypeScript files.
lib/exportMap/captureDependency.js safe No malicious patterns detected; this is legitimate dependency-tracking code from a static analysis tool that only parses and stores import metadata.
lib/exportMap/childContext.js safe The code is a legitimate ESLint utility for computing cache keys from parser/settings context, with no malicious patterns detected.
lib/exportMap/doc.js safe No malicious patterns detected
lib/exportMap/index.js safe No malicious patterns detected; the file is a Babel-compiled ES module for an ESLint import resolver, containing no network, filesystem, process, or dynamic-eval functionality.
lib/exportMap/namespace.js safe No malicious patterns detected; the code implements a namespace resolver using local relative imports and no network, filesystem, or process execution.
lib/exportMap/patternCapture.js safe No malicious patterns detected; the code is a benign AST pattern traversal utility with no network, filesystem, or process activity.
Show 51 more files
FileVerdictWhat the reviewer saw
lib/exportMap/remotePath.js safe No malicious patterns detected
lib/exportMap/specifier.js safe No malicious patterns detected; the code is a standard ES module specifier processor for building export maps.
lib/exportMap/typescript.js safe No malicious patterns detected; the file legitimately reads TypeScript configuration and caches the result for the ESLint import plugin.
lib/exportMap/visitor.js safe This is a legitimate ESLint import/export analysis module with no malicious patterns detected.
lib/importDeclaration.js safe No malicious patterns detected; the file is a simple ESLint helper that returns the last ancestor of a node.
lib/index.js safe No malicious patterns detected; the file is a standard ESLint plugin entry point that statically requires local rule and config modules.
lib/rules/consistent-type-specifier-style.js safe This is a standard ESLint rule implementation for consistent type specifier style; no malicious patterns, network activity, credential access, or dynamic code execution were detected.
lib/rules/default.js safe No malicious patterns detected; the file is a legitimate ESLint rule definition that checks for default exports.
lib/rules/enforce-node-protocol-usage.js safe No malicious patterns detected
lib/rules/export.js safe No malicious patterns detected; the code is a standard ESLint rule for validating exports and contains only expected logic for processing AST nodes.
lib/rules/exports-last.js safe No malicious patterns detected
lib/rules/extensions.js safe No malicious patterns detected; the code is a standard ESLint rule implementation with no data exfiltration, obfuscation, or suspicious behavior.
lib/rules/first.js safe No malicious patterns detected; the code is a standard ESLint rule implementation for enforcing import ordering with no network, file system, or process execution activity.
lib/rules/group-exports.js safe No malicious patterns detected in this ESLint rule implementation for grouping exports.
lib/rules/imports-first.js safe No malicious patterns detected; the file is a simple ESLint rule deprecation wrapper with no network, filesystem, or execution risks.
lib/rules/max-dependencies.js safe No malicious patterns detected
lib/rules/named.js safe No malicious patterns detected
lib/rules/namespace.js safe No malicious patterns detected in this ESLint rule implementation; the code performs static analysis of import namespaces and contains no network, filesystem, process, or dynamic execution activities.
lib/rules/newline-after-import.js safe This is a standard ESLint rule for enforcing newlines after import statements, with no network, filesystem, process, or obfuscation patterns indicating malicious behavior.
lib/rules/no-absolute-path.js safe No malicious patterns detected; the code is a standard ESLint rule implementation with only benign path manipulation and static analysis logic.
lib/rules/no-amd.js safe No malicious patterns detected; this is a legitimate ESLint rule that forbids AMD require/define calls.
lib/rules/no-anonymous-default-export.js safe No malicious patterns detected
lib/rules/no-commonjs.js safe No malicious patterns detected; the file is a standard ESLint rule implementation for forbidding CommonJS syntax.
lib/rules/no-cycle.js safe This is a legitimate ESLint rule implementation for detecting circular dependencies, with no malicious patterns detected.
lib/rules/no-default-export.js safe This is a benign ESLint rule implementation for forbidding default exports, with no malicious patterns detected.
lib/rules/no-deprecated.js safe No malicious patterns detected; the file is a standard ESLint rule implementation for flagging deprecated imports.
lib/rules/no-duplicates.js safe No malicious patterns detected
lib/rules/no-dynamic-require.js safe No malicious patterns detected; the code is a standard ESLint rule implementation that forbids dynamic require() calls.
lib/rules/no-empty-named-blocks.js safe No malicious patterns detected; the code is a standard ESLint rule implementation with no network, filesystem, process, or obfuscation concerns.
lib/rules/no-extraneous-dependencies.js safe This is a standard ESLint rule implementation for checking extraneous dependencies; no malicious patterns, data exfiltration, credential harvesting, obfuscated code, or suspicious behavior was detected.
lib/rules/no-import-module-exports.js safe No malicious patterns detected
lib/rules/no-internal-modules.js safe This is a standard ESLint rule implementation for enforcing module import boundaries with no malicious patterns detected.
lib/rules/no-mutable-exports.js safe No malicious patterns detected
lib/rules/no-named-as-default-member.js safe This is a standard ESLint rule implementation from eslint-plugin-import that analyzes import statements for helpful warnings; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution were detected.
lib/rules/no-named-as-default.js safe No malicious patterns detected
lib/rules/no-named-default.js safe No malicious patterns detected; the file is a standard ESLint rule implementation with no network, filesystem, or dynamic code execution activity.
lib/rules/no-named-export.js safe No malicious patterns detected; the code is a standard ESLint rule implementation for forbidding named exports.
lib/rules/no-namespace.js safe This is a standard ESLint rule implementation with no malicious patterns; it performs static AST analysis and text fixes only.
lib/rules/no-nodejs-modules.js safe Legitimate ESLint rule implementation with no malicious patterns detected.
lib/rules/no-relative-packages.js safe No malicious patterns detected; the file is a standard ESLint rule for enforcing package import best practices.
lib/rules/no-relative-parent-imports.js safe No malicious patterns detected
lib/rules/no-restricted-paths.js safe No malicious patterns detected; the file is a standard ESLint rule for restricting import paths with no network, filesystem, process execution, or obfuscated code.
lib/rules/no-self-import.js safe No malicious patterns detected
lib/rules/no-unassigned-import.js safe No malicious patterns detected
lib/rules/no-unresolved.js safe No malicious patterns detected; the code is a standard ESLint rule that resolves import paths and checks filesystem casing.
lib/rules/no-useless-path-segments.js safe No malicious patterns detected; this is a legitimate ESLint rule implementation for detecting useless path segments in imports.
lib/rules/no-webpack-loader-syntax.js safe No malicious patterns detected
lib/rules/prefer-default-export.js safe This is a standard ESLint rule implementation with no malicious patterns, network requests, credential harvesting, or dynamic code execution.
lib/rules/unambiguous.js safe No malicious patterns detected
lib/scc.js safe No malicious patterns detected; the code is a standard ESLint module dependency graph builder with caching and no network, file system, or process manipulation.
memo-parser/index.js safe No malicious patterns detected; the code is a legitimate ESLint parser cache wrapper that uses hashing and module loading without any suspicious behavior.

Scanned versions of eslint-plugin-import

VersionVerdictFilesScanned
2.32.0 Needs review 76 Oct 6, 2026

Frequently asked questions

Is eslint-plugin-import safe to use?

No confirmed malware was found in eslint-plugin-import@2.32.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does eslint-plugin-import contain malware?

No malware was identified in eslint-plugin-import@2.32.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was eslint-plugin-import checked?

Togoder Security downloaded the published npm package and had an AI model read its 76 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan eslint-plugin-import together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eslint-plugin-import@2.32.0, cost nothing.

Related security reports