# estraverse@5.3.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:32.000Z
- Files reviewed: 2
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/estraverse
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package estraverse@5.3.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Dependency on External Packages

Finding ID: `NPS-380E51628FD3`

File: `gulpfile.js:28`

The script relies on several third-party gulp plugins (gulp-git, gulp-bump, gulp-filter, gulp-tag-version). These packages could introduce vulnerabilities or malicious behavior if they are compromised or typosquatted. However, the code itself does not contain malicious patterns.

### [low] Automated Version Bumping and Tagging

Finding ID: `NPS-B3E421305135`

File: `gulpfile.js:53`

The gulpfile uses gulp-git and gulp-tag-version to automatically commit version bumps and create git tags. While not inherently malicious, this could be exploited if the build environment is compromised to push malicious tags or commits to the repository. It also requires git credentials in the environment, which could be a target for exfiltration if the build process is compromised.

## Files reviewed

- `gulpfile.js` (medium): The gulpfile.js contains no direct malicious patterns but uses git automation that could be risky if the build environment is compromised.
- `estraverse.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
