Togoder security

npm package security report

esquery npm package: is it safe?

No malicious code found.

No issues Version 1.7.0 Files reviewed 1 Size 455.6 KB Scanned

Summary

Togoder Security scanned the npm package esquery@1.7.0 on Oct 6, 2026. An AI review of 1 source file produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Dynamic RegExp construction

NPS-A4CC0A2869C4

The parser constructs a RegExp object from user-supplied pattern and flags (peg$c76). This is standard for CSS/selector parsers and is not inherently malicious, but if the parser output is consumed without validation, a crafted regex could cause ReDoS. No other risky patterns were found.

parser.js:846

Files reviewed

FileVerdictWhat the reviewer saw
parser.js safe This is a standard PEG.js-generated selector parser with no malicious patterns; only a benign dynamically constructed RegExp from parsed input was noted.

Scanned versions of esquery

VersionVerdictFilesScanned
1.7.0 No issues 1 Oct 6, 2026

Frequently asked questions

Is esquery safe to use?

Our AI source review of esquery@1.7.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does esquery contain malware?

No malware was identified in esquery@1.7.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was esquery checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan esquery together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in esquery@1.7.0, cost nothing.

Related security reports