Summary
Togoder Security scanned the npm package estraverse@5.3.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Dependency on External Packages
NPS-380E51628FD3
The script relies on several third-party gulp plugins (gulp-git, gulp-bump, gulp-filter, gulp-tag-version). These packages could introduce vulnerabilities or malicious behavior if they are compromised or typosquatted. However, the code itself does not contain malicious patterns.
Automated Version Bumping and Tagging
NPS-B3E421305135
The gulpfile uses gulp-git and gulp-tag-version to automatically commit version bumps and create git tags. While not inherently malicious, this could be exploited if the build environment is compromised to push malicious tags or commits to the repository. It also requires git credentials in the environment, which could be a target for exfiltration if the build process is compromised.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| gulpfile.js | medium | The gulpfile.js contains no direct malicious patterns but uses git automation that could be risky if the build environment is compromised. |
| estraverse.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of estraverse
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 5.3.0 | Needs review | 2 | Oct 6, 2026 |
Frequently asked questions
Is estraverse safe to use?
No confirmed malware was found in estraverse@5.3.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does estraverse contain malware?
No malware was identified in estraverse@5.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was estraverse checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan estraverse together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in estraverse@5.3.0, cost nothing.