Togoder security

npm package security report

eslint-plugin-unused-imports npm package: is it safe?

No malicious code found.

No issues Version 4.4.1 Files reviewed 2 Size 12.4 KB Scanned

Summary

Togoder Security scanned the npm package eslint-plugin-unused-imports@4.4.1 on Oct 6, 2026. An AI review of 2 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
3
low

Findings 3

low

Dynamic module loading

NPS-7DB7332CFE09

The code uses module.createRequire with importMetaUrl to conditionally load @typescript-eslint/eslint-plugin, typescript-eslint, or eslint at runtime. This is a legitimate pattern used by ESLint rule plugins to resolve peer dependencies and is not exploited with external or user-controlled input.

dist/index.js:89
low

Regex construction from variable input

NPS-4FCFDD4AEE21

Builds a RegExp from identifierName interpolated into a template string. The identifier comes from ESLint's own AST (variable names in analyzed source), not from untrusted network input, and is used only for matching JSDoc comments. Low risk but technically a regex-injection surface if unusual identifiers are present.

dist/index.mjs:10
low

Dynamic module loading

NPS-2F8C9E86C37B

Uses createRequire and require() to dynamically load '@typescript-eslint/eslint-plugin', 'typescript-eslint', 'eslint', and 'eslint/use-at-your-own-risk' at runtime. This is expected behavior for an ESLint plugin that needs to delegate to a base rule, but dynamic requires are worth noting as a minor supply-chain consideration.

dist/index.mjs:130

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.js safe The package is a legitimate ESLint plugin (unused-imports) that only conditionally resolves ESLint-related peer dependencies at runtime; no malicious patterns were detected.
dist/index.mjs safe This is the legitimate eslint-plugin-unused-imports package; no exfiltration, credential harvesting, obfuscation, process spawning, or backdoor patterns were detected.

Scanned versions of eslint-plugin-unused-imports

VersionVerdictFilesScanned
4.4.1 No issues 2 Oct 6, 2026

Frequently asked questions

Is eslint-plugin-unused-imports safe to use?

Our AI source review of eslint-plugin-unused-imports@4.4.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does eslint-plugin-unused-imports contain malware?

No malware was identified in eslint-plugin-unused-imports@4.4.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was eslint-plugin-unused-imports checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan eslint-plugin-unused-imports together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in eslint-plugin-unused-imports@4.4.1, cost nothing.

Related security reports