# eslint-plugin-jsx-a11y@6.10.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:16:27.000Z
- Files reviewed: 112
- Findings: no findings
- Report: https://security.togoder.click/npm/eslint-plugin-jsx-a11y
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eslint-plugin-jsx-a11y@6.10.2 on Oct 6, 2026. An AI review of 112 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `__mocks__/IdentifierMock.js` (safe): Cleared by Jev triage; no further analysis needed
- `__mocks__/JSXAttributeMock.js` (safe): No malicious patterns detected in JSXAttributeMock.js; it is a benign test mock utility for building JSX attribute AST nodes.
- `__mocks__/JSXElementMock.js` (safe): Cleared by Jev triage; no further analysis needed
- `__mocks__/JSXExpressionContainerMock.js` (safe): Cleared by Jev triage; no further analysis needed
- `__mocks__/JSXSpreadAttributeMock.js` (safe): Cleared by Jev triage; no further analysis needed
- `__mocks__/JSXTextMock.js` (safe): Cleared by Jev triage; no further analysis needed
- `__mocks__/LiteralMock.js` (safe): Cleared by Jev triage; no further analysis needed
- `__mocks__/genInteractives.js` (safe): No malicious patterns detected; the file contains only static mock data generation for ARIA/JSX testing utilities.
- `lib/configs/flat-config-base.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/configs/legacy-config-base.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): This is the standard entry point for the eslint-plugin-jsx-a11y package, containing only rule definitions and configuration exports with no malicious patterns.
- `lib/rules/accessible-emoji.js` (safe): No malicious patterns detected
- `lib/rules/alt-text.js` (safe): No malicious patterns detected
- `lib/rules/anchor-ambiguous-text.js` (safe): This is a legitimate ESLint accessibility rule implementation with no malicious patterns, network activity, process execution, or data exfiltration.
- `lib/rules/anchor-has-content.js` (safe): No malicious patterns detected; this is a legitimate ESLint accessibility rule for enforcing anchor content.
- `lib/rules/anchor-is-valid.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation for validating anchor elements.
- `lib/rules/aria-activedescendant-has-tabindex.js` (safe): This is a standard ESLint accessibility rule from eslint-plugin-jsx-a11y with no malicious patterns detected.
- `lib/rules/aria-props.js` (safe): This is a standard ESLint rule implementation for validating ARIA attributes with no malicious patterns, network requests, process execution, or obfuscated code.
- `lib/rules/aria-proptypes.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation for validating JSX ARIA attribute types with no network, filesystem, process, or dynamic code execution behavior.
- `lib/rules/aria-role.js` (safe): This is a standard ESLint rule implementation for validating ARIA roles with no malicious patterns, external calls, or dynamic code execution.
- `lib/rules/aria-unsupported-elements.js` (safe): This is a legitimate ESLint rule from eslint-plugin-jsx-a11y that checks for unsupported ARIA attributes; no malicious patterns detected.
- `lib/rules/autocomplete-valid.js` (safe): No malicious patterns detected; the code is a standard ESLint rule for validating the autocomplete attribute using axe-core and jsx-ast-utils.
- `lib/rules/click-events-have-key-events.js` (safe): No malicious patterns detected; this is a standard eslint-plugin-jsx-a11y accessibility rule with no network, filesystem, or code execution activity.
- `lib/rules/control-has-associated-label.js` (safe): No malicious patterns detected
- `lib/rules/heading-has-content.js` (safe): No malicious patterns detected; this is a standard ESLint accessibility rule implementation.
- `lib/rules/html-has-lang.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation enforcing the lang attribute on <html> elements.
- `lib/rules/iframe-has-title.js` (safe): No malicious patterns detected; this is a standard ESLint accessibility rule enforcing title attributes on iframe elements.
- `lib/rules/img-redundant-alt.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule for jsx-a11y that checks redundant alt text.
- `lib/rules/interactive-supports-focus.js` (safe): No malicious patterns detected; the file is a legitimate ESLint accessibility rule with only static requires and no dynamic execution, network, filesystem, or process activity.
- `lib/rules/label-has-associated-control.js` (safe): No malicious patterns detected; this is a standard ESLint rule implementation for jsx-a11y that performs static AST analysis without network, filesystem, process, or dynamic code execution.
- `lib/rules/label-has-for.js` (safe): This is a legitimate ESLint accessibility rule implementation with no malicious patterns, external network calls, credential access, or dynamic code execution.
- `lib/rules/lang.js` (safe): This is a standard ESLint rule from jsx-a11y that validates lang attributes and contains no malicious patterns.
- `lib/rules/media-has-caption.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation for enforcing captions on media elements.
- `lib/rules/mouse-events-have-key-events.js` (safe): No malicious patterns detected; the code is a standard ESLint accessibility rule with no network, filesystem, or code execution concerns.
- `lib/rules/no-access-key.js` (safe): No malicious patterns detected
- `lib/rules/no-aria-hidden-on-focusable.js` (safe): This is a standard ESLint accessibility rule implementation with no malicious patterns, network activity, filesystem access, or dynamic code execution.
- `lib/rules/no-autofocus.js` (safe): This is a standard ESLint rule implementation for the jsx-a11y plugin that enforces the autoFocus prop is not used; it contains no malicious patterns, network activity, filesystem access, or code execution.
- `lib/rules/no-distracting-elements.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule implementation for detecting distracting HTML elements.
- `lib/rules/no-interactive-element-to-noninteractive-role.js` (safe): This is a legitimate ESLint rule implementation from jsx-a11y that checks JSX role attributes for accessibility violations, with no malicious patterns detected.
- `lib/rules/no-noninteractive-element-interactions.js` (safe): No malicious patterns detected
- `lib/rules/no-noninteractive-element-to-interactive-role.js` (safe): No malicious patterns detected; the file is a standard ESLint rule implementation from jsx-a11y with no network, filesystem, process, or dynamic code execution behavior.
- `lib/rules/no-noninteractive-tabindex.js` (safe): No malicious patterns detected; the code is a standard ESLint rule implementation for jsx-a11y with no network, filesystem, process, or dynamic execution concerns.
- `lib/rules/no-onchange.js` (safe): This is a legitimate ESLint accessibility rule with no malicious patterns detected.
- `lib/rules/no-redundant-roles.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule implementation for jsx-a11y that performs static analysis without any network, filesystem, or execution primitives.
- `lib/rules/no-static-element-interactions.js` (safe): No malicious patterns detected; this is a legitimate ESLint accessibility rule implementation with no network, filesystem, process, or dynamic code execution behavior.
- `lib/rules/prefer-tag-over-role.js` (safe): No malicious patterns detected; this file is a standard ESLint rule implementation for jsx-a11y with no network, filesystem, process, or dynamic code execution activity.
- `lib/rules/role-has-required-aria-props.js` (safe): This is a legitimate ESLint rule from eslint-plugin-jsx-a11y that enforces required ARIA attributes on JSX elements, with no malicious patterns detected.
- `lib/rules/role-supports-aria-props.js` (safe): No malicious patterns detected; this is a legitimate ESLint rule for checking ARIA attributes.
- `lib/rules/scope.js` (safe): This is a standard ESLint accessibility rule implementation with no malicious patterns, network requests, file system access, or dynamic code execution.
- `lib/rules/tabindex-no-positive.js` (safe): This is a standard ESLint accessibility rule implementation with no malicious patterns, external calls, or suspicious behavior.
- `lib/util/attributesComparator.js` (safe): The file contains a simple utility function for comparing JSX attributes and shows no malicious patterns or security concerns.
- `lib/util/getAccessibleChildText.js` (safe): No malicious patterns detected; the code is a legitimate utility for extracting accessible text from JSX AST nodes without network, filesystem, or process operations.
- `lib/util/getComputedRole.js` (safe): No malicious patterns detected
- `lib/util/getElementType.js` (safe): The code is a standard utility for extracting and resolving JSX element types based on ESLint settings, with no malicious patterns, network activity, credential access, or dynamic code execution.
- `lib/util/getExplicitRole.js` (safe): No malicious patterns detected; the code only imports aria-query and jsx-ast-utils and performs role normalization without suspicious behavior.
- `lib/util/getImplicitRole.js` (safe): No malicious patterns detected
- `lib/util/getSuggestion.js` (safe): No malicious patterns detected
- `lib/util/getTabIndex.js` (safe): No malicious patterns detected; the file is a benign utility function for extracting tabIndex values using the jsx-ast-utils library.
- `lib/util/hasAccessibleChild.js` (safe): No malicious patterns detected; the file is a benign React accessibility linting utility that only inspects AST nodes.
- `lib/util/implicitRoles/a.js` (safe): The file contains a simple utility function that determines the implicit ARIA role for anchor elements based on the presence of an href prop, with no network, filesystem, process, or dynamic execution activity.
- `lib/util/implicitRoles/area.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/article.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/aside.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/body.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/button.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/datalist.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/details.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/dialog.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/form.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/h1.js` (safe): The file is a simple utility that returns the implicit ARIA role for an h1 tag with no malicious patterns.
- `lib/util/implicitRoles/h2.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/h3.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/h4.js` (safe): No malicious patterns detected; the file only defines a simple function returning the implicit ARIA role for h4 elements.
- `lib/util/implicitRoles/h5.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/h6.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/hr.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/img.js` (safe): No malicious patterns detected; the code is a benign utility for determining implicit ARIA roles for img tags in JSX/ESLint contexts.
- `lib/util/implicitRoles/index.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/input.js` (safe): No malicious patterns detected; the module is a simple ARIA implicit-role helper for JSX input elements.
- `lib/util/implicitRoles/li.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/link.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/menu.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/menuitem.js` (safe): No malicious patterns detected; the code is a standard accessibility utility function for determining implicit ARIA roles.
- `lib/util/implicitRoles/meter.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/nav.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/ol.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/option.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/output.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/progress.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/section.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/select.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/tbody.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/textarea.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/tfoot.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/thead.js` (safe): No malicious patterns detected
- `lib/util/implicitRoles/ul.js` (safe): No malicious patterns detected; the file only exports a pure function returning the implicit ARIA role 'list' for a ul tag.
- `lib/util/isAbstractRole.js` (safe): No malicious patterns detected; the code is a benign utility for checking abstract ARIA roles.
- `lib/util/isContentEditable.js` (safe): This is a benign utility function that checks if a JSX element has a contentEditable attribute set to 'true', with no malicious patterns detected.
- `lib/util/isDOMElement.js` (safe): No malicious patterns detected
- `lib/util/isDisabledElement.js` (safe): No malicious patterns detected; the file only contains a utility function for checking JSX disabled/aria-disabled attributes using jsx-ast-utils.
- `lib/util/isFocusable.js` (safe): No malicious patterns detected; the code is a simple utility for determining if a JSX element is focusable.
- `lib/util/isHiddenFromScreenReader.js` (safe): No malicious patterns detected; the code is a simple utility for detecting screen-reader-hidden JSX elements.
- `lib/util/isInteractiveElement.js` (safe): No malicious patterns detected; the code is a standard utility for determining interactive DOM elements using aria-query and axobject-query libraries.
- `lib/util/isInteractiveRole.js` (safe): No malicious patterns detected; the code is a standard utility for checking interactive ARIA roles with no network, filesystem, process, or dynamic execution activity.
- `lib/util/isNonInteractiveElement.js` (safe): No malicious patterns detected
- `lib/util/isNonInteractiveRole.js` (safe): No malicious patterns detected; the code is a standard accessibility utility for checking ARIA non-interactive roles.
- `lib/util/isNonLiteralProperty.js` (safe): No malicious patterns detected; the file is a small utility function that checks JSX AST attribute types using jsx-ast-utils and performs no network, filesystem, process, or dynamic code operations.
- `lib/util/isPresentationRole.js` (safe): No malicious patterns detected
- `lib/util/isSemanticRoleElement.js` (safe): No malicious patterns detected
- `lib/util/mayContainChildComponent.js` (safe): The code is a legitimate utility for checking if a JSX element may contain a child component, using only standard AST traversal and pattern matching, with no malicious patterns detected.
- `lib/util/mayHaveAccessibleLabel.js` (safe): The code is a utility function for accessibility linting that checks JSX elements for labelling props and contains no malicious patterns.
- `lib/util/schemas.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
