Summary
Togoder Security scanned the npm package eslint-plugin-unused-imports@4.4.1 on Oct 6, 2026. An AI review of 2 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 3
Dynamic module loading
NPS-7DB7332CFE09
The code uses module.createRequire with importMetaUrl to conditionally load @typescript-eslint/eslint-plugin, typescript-eslint, or eslint at runtime. This is a legitimate pattern used by ESLint rule plugins to resolve peer dependencies and is not exploited with external or user-controlled input.
Regex construction from variable input
NPS-4FCFDD4AEE21
Builds a RegExp from identifierName interpolated into a template string. The identifier comes from ESLint's own AST (variable names in analyzed source), not from untrusted network input, and is used only for matching JSDoc comments. Low risk but technically a regex-injection surface if unusual identifiers are present.
Dynamic module loading
NPS-2F8C9E86C37B
Uses createRequire and require() to dynamically load '@typescript-eslint/eslint-plugin', 'typescript-eslint', 'eslint', and 'eslint/use-at-your-own-risk' at runtime. This is expected behavior for an ESLint plugin that needs to delegate to a base rule, but dynamic requires are worth noting as a minor supply-chain consideration.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.js | safe | The package is a legitimate ESLint plugin (unused-imports) that only conditionally resolves ESLint-related peer dependencies at runtime; no malicious patterns were detected. |
| dist/index.mjs | safe | This is the legitimate eslint-plugin-unused-imports package; no exfiltration, credential harvesting, obfuscation, process spawning, or backdoor patterns were detected. |
Scanned versions of eslint-plugin-unused-imports
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 4.4.1 | No issues | 2 | Oct 6, 2026 |
Frequently asked questions
Is eslint-plugin-unused-imports safe to use?
Our AI source review of eslint-plugin-unused-imports@4.4.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does eslint-plugin-unused-imports contain malware?
No malware was identified in eslint-plugin-unused-imports@4.4.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was eslint-plugin-unused-imports checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan eslint-plugin-unused-imports together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eslint-plugin-unused-imports@4.4.1, cost nothing.