Summary
Togoder Security scanned the npm package eslint-plugin-jsx-a11y@6.10.2 on Oct 6, 2026. An AI review of 112 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| __mocks__/IdentifierMock.js | safe | Cleared by Jev triage; no further analysis needed |
| __mocks__/JSXAttributeMock.js | safe | No malicious patterns detected in JSXAttributeMock.js; it is a benign test mock utility for building JSX attribute AST nodes. |
| __mocks__/JSXElementMock.js | safe | Cleared by Jev triage; no further analysis needed |
| __mocks__/JSXExpressionContainerMock.js | safe | Cleared by Jev triage; no further analysis needed |
| __mocks__/JSXSpreadAttributeMock.js | safe | Cleared by Jev triage; no further analysis needed |
| __mocks__/JSXTextMock.js | safe | Cleared by Jev triage; no further analysis needed |
| __mocks__/LiteralMock.js | safe | Cleared by Jev triage; no further analysis needed |
| __mocks__/genInteractives.js | safe | No malicious patterns detected; the file contains only static mock data generation for ARIA/JSX testing utilities. |
| lib/configs/flat-config-base.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/configs/legacy-config-base.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | This is the standard entry point for the eslint-plugin-jsx-a11y package, containing only rule definitions and configuration exports with no malicious patterns. |
| lib/rules/accessible-emoji.js | safe | No malicious patterns detected |
| lib/rules/alt-text.js | safe | No malicious patterns detected |
| lib/rules/anchor-ambiguous-text.js | safe | This is a legitimate ESLint accessibility rule implementation with no malicious patterns, network activity, process execution, or data exfiltration. |
| lib/rules/anchor-has-content.js | safe | No malicious patterns detected; this is a legitimate ESLint accessibility rule for enforcing anchor content. |
| lib/rules/anchor-is-valid.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation for validating anchor elements. |
| lib/rules/aria-activedescendant-has-tabindex.js | safe | This is a standard ESLint accessibility rule from eslint-plugin-jsx-a11y with no malicious patterns detected. |
| lib/rules/aria-props.js | safe | This is a standard ESLint rule implementation for validating ARIA attributes with no malicious patterns, network requests, process execution, or obfuscated code. |
| lib/rules/aria-proptypes.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation for validating JSX ARIA attribute types with no network, filesystem, process, or dynamic code execution behavior. |
| lib/rules/aria-role.js | safe | This is a standard ESLint rule implementation for validating ARIA roles with no malicious patterns, external calls, or dynamic code execution. |
| lib/rules/aria-unsupported-elements.js | safe | This is a legitimate ESLint rule from eslint-plugin-jsx-a11y that checks for unsupported ARIA attributes; no malicious patterns detected. |
| lib/rules/autocomplete-valid.js | safe | No malicious patterns detected; the code is a standard ESLint rule for validating the autocomplete attribute using axe-core and jsx-ast-utils. |
| lib/rules/click-events-have-key-events.js | safe | No malicious patterns detected; this is a standard eslint-plugin-jsx-a11y accessibility rule with no network, filesystem, or code execution activity. |
| lib/rules/control-has-associated-label.js | safe | No malicious patterns detected |
| lib/rules/heading-has-content.js | safe | No malicious patterns detected; this is a standard ESLint accessibility rule implementation. |
Show 87 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/rules/html-has-lang.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation enforcing the lang attribute on <html> elements. |
| lib/rules/iframe-has-title.js | safe | No malicious patterns detected; this is a standard ESLint accessibility rule enforcing title attributes on iframe elements. |
| lib/rules/img-redundant-alt.js | safe | No malicious patterns detected; this is a legitimate ESLint rule for jsx-a11y that checks redundant alt text. |
| lib/rules/interactive-supports-focus.js | safe | No malicious patterns detected; the file is a legitimate ESLint accessibility rule with only static requires and no dynamic execution, network, filesystem, or process activity. |
| lib/rules/label-has-associated-control.js | safe | No malicious patterns detected; this is a standard ESLint rule implementation for jsx-a11y that performs static AST analysis without network, filesystem, process, or dynamic code execution. |
| lib/rules/label-has-for.js | safe | This is a legitimate ESLint accessibility rule implementation with no malicious patterns, external network calls, credential access, or dynamic code execution. |
| lib/rules/lang.js | safe | This is a standard ESLint rule from jsx-a11y that validates lang attributes and contains no malicious patterns. |
| lib/rules/media-has-caption.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation for enforcing captions on media elements. |
| lib/rules/mouse-events-have-key-events.js | safe | No malicious patterns detected; the code is a standard ESLint accessibility rule with no network, filesystem, or code execution concerns. |
| lib/rules/no-access-key.js | safe | No malicious patterns detected |
| lib/rules/no-aria-hidden-on-focusable.js | safe | This is a standard ESLint accessibility rule implementation with no malicious patterns, network activity, filesystem access, or dynamic code execution. |
| lib/rules/no-autofocus.js | safe | This is a standard ESLint rule implementation for the jsx-a11y plugin that enforces the autoFocus prop is not used; it contains no malicious patterns, network activity, filesystem access, or code execution. |
| lib/rules/no-distracting-elements.js | safe | No malicious patterns detected; this is a legitimate ESLint rule implementation for detecting distracting HTML elements. |
| lib/rules/no-interactive-element-to-noninteractive-role.js | safe | This is a legitimate ESLint rule implementation from jsx-a11y that checks JSX role attributes for accessibility violations, with no malicious patterns detected. |
| lib/rules/no-noninteractive-element-interactions.js | safe | No malicious patterns detected |
| lib/rules/no-noninteractive-element-to-interactive-role.js | safe | No malicious patterns detected; the file is a standard ESLint rule implementation from jsx-a11y with no network, filesystem, process, or dynamic code execution behavior. |
| lib/rules/no-noninteractive-tabindex.js | safe | No malicious patterns detected; the code is a standard ESLint rule implementation for jsx-a11y with no network, filesystem, process, or dynamic execution concerns. |
| lib/rules/no-onchange.js | safe | This is a legitimate ESLint accessibility rule with no malicious patterns detected. |
| lib/rules/no-redundant-roles.js | safe | No malicious patterns detected; this is a legitimate ESLint rule implementation for jsx-a11y that performs static analysis without any network, filesystem, or execution primitives. |
| lib/rules/no-static-element-interactions.js | safe | No malicious patterns detected; this is a legitimate ESLint accessibility rule implementation with no network, filesystem, process, or dynamic code execution behavior. |
| lib/rules/prefer-tag-over-role.js | safe | No malicious patterns detected; this file is a standard ESLint rule implementation for jsx-a11y with no network, filesystem, process, or dynamic code execution activity. |
| lib/rules/role-has-required-aria-props.js | safe | This is a legitimate ESLint rule from eslint-plugin-jsx-a11y that enforces required ARIA attributes on JSX elements, with no malicious patterns detected. |
| lib/rules/role-supports-aria-props.js | safe | No malicious patterns detected; this is a legitimate ESLint rule for checking ARIA attributes. |
| lib/rules/scope.js | safe | This is a standard ESLint accessibility rule implementation with no malicious patterns, network requests, file system access, or dynamic code execution. |
| lib/rules/tabindex-no-positive.js | safe | This is a standard ESLint accessibility rule implementation with no malicious patterns, external calls, or suspicious behavior. |
| lib/util/attributesComparator.js | safe | The file contains a simple utility function for comparing JSX attributes and shows no malicious patterns or security concerns. |
| lib/util/getAccessibleChildText.js | safe | No malicious patterns detected; the code is a legitimate utility for extracting accessible text from JSX AST nodes without network, filesystem, or process operations. |
| lib/util/getComputedRole.js | safe | No malicious patterns detected |
| lib/util/getElementType.js | safe | The code is a standard utility for extracting and resolving JSX element types based on ESLint settings, with no malicious patterns, network activity, credential access, or dynamic code execution. |
| lib/util/getExplicitRole.js | safe | No malicious patterns detected; the code only imports aria-query and jsx-ast-utils and performs role normalization without suspicious behavior. |
| lib/util/getImplicitRole.js | safe | No malicious patterns detected |
| lib/util/getSuggestion.js | safe | No malicious patterns detected |
| lib/util/getTabIndex.js | safe | No malicious patterns detected; the file is a benign utility function for extracting tabIndex values using the jsx-ast-utils library. |
| lib/util/hasAccessibleChild.js | safe | No malicious patterns detected; the file is a benign React accessibility linting utility that only inspects AST nodes. |
| lib/util/implicitRoles/a.js | safe | The file contains a simple utility function that determines the implicit ARIA role for anchor elements based on the presence of an href prop, with no network, filesystem, process, or dynamic execution activity. |
| lib/util/implicitRoles/area.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/article.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/aside.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/body.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/button.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/datalist.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/details.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/dialog.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/form.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/h1.js | safe | The file is a simple utility that returns the implicit ARIA role for an h1 tag with no malicious patterns. |
| lib/util/implicitRoles/h2.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/h3.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/h4.js | safe | No malicious patterns detected; the file only defines a simple function returning the implicit ARIA role for h4 elements. |
| lib/util/implicitRoles/h5.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/h6.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/hr.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/img.js | safe | No malicious patterns detected; the code is a benign utility for determining implicit ARIA roles for img tags in JSX/ESLint contexts. |
| lib/util/implicitRoles/index.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/input.js | safe | No malicious patterns detected; the module is a simple ARIA implicit-role helper for JSX input elements. |
| lib/util/implicitRoles/li.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/link.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/menu.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/menuitem.js | safe | No malicious patterns detected; the code is a standard accessibility utility function for determining implicit ARIA roles. |
| lib/util/implicitRoles/meter.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/nav.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/ol.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/option.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/output.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/progress.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/section.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/select.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/tbody.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/textarea.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/tfoot.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/thead.js | safe | No malicious patterns detected |
| lib/util/implicitRoles/ul.js | safe | No malicious patterns detected; the file only exports a pure function returning the implicit ARIA role 'list' for a ul tag. |
| lib/util/isAbstractRole.js | safe | No malicious patterns detected; the code is a benign utility for checking abstract ARIA roles. |
| lib/util/isContentEditable.js | safe | This is a benign utility function that checks if a JSX element has a contentEditable attribute set to 'true', with no malicious patterns detected. |
| lib/util/isDOMElement.js | safe | No malicious patterns detected |
| lib/util/isDisabledElement.js | safe | No malicious patterns detected; the file only contains a utility function for checking JSX disabled/aria-disabled attributes using jsx-ast-utils. |
| lib/util/isFocusable.js | safe | No malicious patterns detected; the code is a simple utility for determining if a JSX element is focusable. |
| lib/util/isHiddenFromScreenReader.js | safe | No malicious patterns detected; the code is a simple utility for detecting screen-reader-hidden JSX elements. |
| lib/util/isInteractiveElement.js | safe | No malicious patterns detected; the code is a standard utility for determining interactive DOM elements using aria-query and axobject-query libraries. |
| lib/util/isInteractiveRole.js | safe | No malicious patterns detected; the code is a standard utility for checking interactive ARIA roles with no network, filesystem, process, or dynamic execution activity. |
| lib/util/isNonInteractiveElement.js | safe | No malicious patterns detected |
| lib/util/isNonInteractiveRole.js | safe | No malicious patterns detected; the code is a standard accessibility utility for checking ARIA non-interactive roles. |
| lib/util/isNonLiteralProperty.js | safe | No malicious patterns detected; the file is a small utility function that checks JSX AST attribute types using jsx-ast-utils and performs no network, filesystem, process, or dynamic code operations. |
| lib/util/isPresentationRole.js | safe | No malicious patterns detected |
| lib/util/isSemanticRoleElement.js | safe | No malicious patterns detected |
| lib/util/mayContainChildComponent.js | safe | The code is a legitimate utility for checking if a JSX element may contain a child component, using only standard AST traversal and pattern matching, with no malicious patterns detected. |
| lib/util/mayHaveAccessibleLabel.js | safe | The code is a utility function for accessibility linting that checks JSX elements for labelling props and contains no malicious patterns. |
| lib/util/schemas.js | safe | No malicious patterns detected |
Frequently asked questions
Is eslint-plugin-jsx-a11y safe to use?
Our AI source review of eslint-plugin-jsx-a11y@6.10.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does eslint-plugin-jsx-a11y contain malware?
No malware was identified in eslint-plugin-jsx-a11y@6.10.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was eslint-plugin-jsx-a11y checked?
Togoder Security downloaded the published npm package and had an AI model read its 112 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan eslint-plugin-jsx-a11y together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eslint-plugin-jsx-a11y@6.10.2, cost nothing.