# eslint-plugin-import@2.32.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:21.000Z
- Files reviewed: 76
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/eslint-plugin-import
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eslint-plugin-import@2.32.0 on Oct 6, 2026. An AI review of 76 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-4F90B9C9DF7F`

File: `lib/rules/dynamic-import-chunkname.js:110`

Uses vm.runInNewContext to evaluate a string constructed from ESLint block comment contents. While the intent is to mirror webpack's comment parsing, invoking a VM on comment text is a dynamic code execution pattern. The generated code is wrapped in an object literal, but the input is file content controlled by the project being linted, so it is an unnecessary and risk-prone use of a sandbox evaluator in a lint rule.

### [low] No malicious patterns detected

Finding ID: `NPS-90008CDD6017`

File: `lib/core/importType.js`

This file is part of eslint-plugin-import and contains only legitimate module import type resolution logic. It uses standard Node.js path utilities and package resolution helpers. No data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, network requests, process spawning, or install-time hooks are present.

### [low] ESLint rule definition

Finding ID: `NPS-DAE185BAAE44`

File: `lib/rules/no-nodejs-modules.js`

This file is a standard ESLint rule implementation for forbidding Node.js builtin module imports. It uses common ESLint patterns: requiring utility modules, defining meta/schema, and reporting lint violations with context.report. No network, filesystem, process, eval, or credential access is present.

## Files reviewed

- `lib/rules/dynamic-import-chunkname.js` (medium): No exfiltration, credential harvesting, network, or process execution behavior, but the rule uses vm.runInNewContext on comment text, a dynamic execution pattern that warrants review.
- `config/electron.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/flat/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/flat/react.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/flat/recommended.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/flat/warnings.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/react-native.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/react.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/recommended.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/stage-0.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/typescript.js` (safe): Cleared by Jev triage; no further analysis needed
- `config/warnings.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/importType.js` (safe): The code is a standard ESLint plugin utility for classifying import types with no security concerns.
- `lib/core/packagePath.js` (safe): No malicious patterns detected
- `lib/core/sourceType.js` (safe): No malicious patterns detected
- `lib/core/staticRequire.js` (safe): No malicious patterns detected; the code is a benign AST utility that checks for static require() calls.
- `lib/docsUrl.js` (safe): No malicious patterns detected; the file is a simple utility that generates documentation URLs from the package version.
- `lib/exportMap/builder.js` (safe): No malicious patterns detected; this is a standard ESLint plugin module for building export maps of JavaScript/TypeScript files.
- `lib/exportMap/captureDependency.js` (safe): No malicious patterns detected; this is legitimate dependency-tracking code from a static analysis tool that only parses and stores import metadata.
- `lib/exportMap/childContext.js` (safe): The code is a legitimate ESLint utility for computing cache keys from parser/settings context, with no malicious patterns detected.
- `lib/exportMap/doc.js` (safe): No malicious patterns detected
- `lib/exportMap/index.js` (safe): No malicious patterns detected; the file is a Babel-compiled ES module for an ESLint import resolver, containing no network, filesystem, process, or dynamic-eval functionality.
- `lib/exportMap/namespace.js` (safe): No malicious patterns detected; the code implements a namespace resolver using local relative imports and no network, filesystem, or process execution.
- `lib/exportMap/patternCapture.js` (safe): No malicious patterns detected; the code is a benign AST pattern traversal utility with no network, filesystem, or process activity.
- `lib/exportMap/remotePath.js` (safe): No malicious patterns detected
- `lib/exportMap/specifier.js` (safe): No malicious patterns detected; the code is a standard ES module specifier processor for building export maps.
- `lib/exportMap/typescript.js` (safe): No malicious patterns detected; the file legitimately reads TypeScript configuration and caches the result for the ESLint import plugin.
- `lib/exportMap/visitor.js` (safe): This is a legitimate ESLint import/export analysis module with no malicious patterns detected.
- `lib/importDeclaration.js` (safe): No malicious patterns detected; the file is a simple ESLint helper that returns the last ancestor of a node.
- `lib/index.js` (safe): No malicious patterns detected; the file is a standard ESLint plugin entry point that statically requires local rule and config modules.
- `lib/rules/consistent-type-specifier-style.js` (safe): This is a standard ESLint rule implementation for consistent type specifier style; no malicious patterns, network activity, credential access, or dynamic code execution were detected.
- `lib/rules/default.js` (safe): No malicious patterns detected; the file is a legitimate ESLint rule definition that checks for default exports.
- `lib/rules/enforce-node-protocol-usage.js` (safe): No malicious patterns detected
- `lib/rules/export.js` (safe): No malicious patterns detected; the code is a standard ESLint rule for validating exports and contains only expected logic for processing AST nodes.
- `lib/rules/exports-last.js` (safe): No malicious patterns detected
- `lib/rules/extensions.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation with no data exfiltration, obfuscation, or suspicious behavior.
- `lib/rules/first.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation for enforcing import ordering with no network, file system, or process execution activity.
- `lib/rules/group-exports.js` (safe): No malicious patterns detected in this ESLint rule implementation for grouping exports.
- `lib/rules/imports-first.js` (safe): No malicious patterns detected; the file is a simple ESLint rule deprecation wrapper with no network, filesystem, or execution risks.
- `lib/rules/max-dependencies.js` (safe): No malicious patterns detected
- `lib/rules/named.js` (safe): No malicious patterns detected
- `lib/rules/namespace.js` (safe): No malicious patterns detected in this ESLint rule implementation; the code performs static analysis of import namespaces and contains no network, filesystem, process, or dynamic execution activities.
- `lib/rules/newline-after-import.js` (safe): This is a standard ESLint rule for enforcing newlines after import statements, with no network, filesystem, process, or obfuscation patterns indicating malicious behavior.
- `lib/rules/no-absolute-path.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation with only benign path manipulation and static analysis logic.
- `lib/rules/no-amd.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule that forbids AMD require/define calls.
- `lib/rules/no-anonymous-default-export.js` (safe): No malicious patterns detected
- `lib/rules/no-commonjs.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation for forbidding CommonJS syntax.
- `lib/rules/no-cycle.js` (safe): This is a legitimate ESLint rule implementation for detecting circular dependencies, with no malicious patterns detected.
- `lib/rules/no-default-export.js` (safe): This is a benign ESLint rule implementation for forbidding default exports, with no malicious patterns detected.
- `lib/rules/no-deprecated.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation for flagging deprecated imports.
- `lib/rules/no-duplicates.js` (safe): No malicious patterns detected
- `lib/rules/no-dynamic-require.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation that forbids dynamic require() calls.
- `lib/rules/no-empty-named-blocks.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation with no network, filesystem, process, or obfuscation concerns.
- `lib/rules/no-extraneous-dependencies.js` (safe): This is a standard ESLint rule implementation for checking extraneous dependencies; no malicious patterns, data exfiltration, credential harvesting, obfuscated code, or suspicious behavior was detected.
- `lib/rules/no-import-module-exports.js` (safe): No malicious patterns detected
- `lib/rules/no-internal-modules.js` (safe): This is a standard ESLint rule implementation for enforcing module import boundaries with no malicious patterns detected.
- `lib/rules/no-mutable-exports.js` (safe): No malicious patterns detected
- `lib/rules/no-named-as-default-member.js` (safe): This is a standard ESLint rule implementation from eslint-plugin-import that analyzes import statements for helpful warnings; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution were detected.
- `lib/rules/no-named-as-default.js` (safe): No malicious patterns detected
- `lib/rules/no-named-default.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation with no network, filesystem, or dynamic code execution activity.
- `lib/rules/no-named-export.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation for forbidding named exports.
- `lib/rules/no-namespace.js` (safe): This is a standard ESLint rule implementation with no malicious patterns; it performs static AST analysis and text fixes only.
- `lib/rules/no-nodejs-modules.js` (safe): Legitimate ESLint rule implementation with no malicious patterns detected.
- `lib/rules/no-relative-packages.js` (safe): No malicious patterns detected; the file is a standard ESLint rule for enforcing package import best practices.
- `lib/rules/no-relative-parent-imports.js` (safe): No malicious patterns detected
- `lib/rules/no-restricted-paths.js` (safe): No malicious patterns detected; the file is a standard ESLint rule for restricting import paths with no network, filesystem, process execution, or obfuscated code.
- `lib/rules/no-self-import.js` (safe): No malicious patterns detected
- `lib/rules/no-unassigned-import.js` (safe): No malicious patterns detected
- `lib/rules/no-unresolved.js` (safe): No malicious patterns detected; the code is a standard ESLint rule that resolves import paths and checks filesystem casing.
- `lib/rules/no-useless-path-segments.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule implementation for detecting useless path segments in imports.
- `lib/rules/no-webpack-loader-syntax.js` (safe): No malicious patterns detected
- `lib/rules/prefer-default-export.js` (safe): This is a standard ESLint rule implementation with no malicious patterns, network requests, credential harvesting, or dynamic code execution.
- `lib/rules/unambiguous.js` (safe): No malicious patterns detected
- `lib/scc.js` (safe): No malicious patterns detected; the code is a standard ESLint module dependency graph builder with caching and no network, file system, or process manipulation.
- `memo-parser/index.js` (safe): No malicious patterns detected; the code is a legitimate ESLint parser cache wrapper that uses hashing and module loading without any suspicious behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
