# eslint-plugin-unused-imports@4.4.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:16:31.000Z
- Files reviewed: 2
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/eslint-plugin-unused-imports
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eslint-plugin-unused-imports@4.4.1 on Oct 6, 2026. An AI review of 2 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic module loading

Finding ID: `NPS-7DB7332CFE09`

File: `dist/index.js:89`

The code uses module.createRequire with importMetaUrl to conditionally load @typescript-eslint/eslint-plugin, typescript-eslint, or eslint at runtime. This is a legitimate pattern used by ESLint rule plugins to resolve peer dependencies and is not exploited with external or user-controlled input.

### [low] Regex construction from variable input

Finding ID: `NPS-4FCFDD4AEE21`

File: `dist/index.mjs:10`

Builds a RegExp from identifierName interpolated into a template string. The identifier comes from ESLint's own AST (variable names in analyzed source), not from untrusted network input, and is used only for matching JSDoc comments. Low risk but technically a regex-injection surface if unusual identifiers are present.

### [low] Dynamic module loading

Finding ID: `NPS-2F8C9E86C37B`

File: `dist/index.mjs:130`

Uses createRequire and require() to dynamically load '@typescript-eslint/eslint-plugin', 'typescript-eslint', 'eslint', and 'eslint/use-at-your-own-risk' at runtime. This is expected behavior for an ESLint plugin that needs to delegate to a base rule, but dynamic requires are worth noting as a minor supply-chain consideration.

## Files reviewed

- `dist/index.js` (safe): The package is a legitimate ESLint plugin (unused-imports) that only conditionally resolves ESLint-related peer dependencies at runtime; no malicious patterns were detected.
- `dist/index.mjs` (safe): This is the legitimate eslint-plugin-unused-imports package; no exfiltration, credential harvesting, obfuscation, process spawning, or backdoor patterns were detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
