Togoder security

npm package security report

estraverse@5.3.0 security report

Risky patterns found that deserve a look.

Needs review Version 5.3.0 Files reviewed 2 Size 29.0 KB Scanned

Summary

Togoder Security scanned the npm package estraverse@5.3.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

Dependency on External Packages

NPS-380E51628FD3

The script relies on several third-party gulp plugins (gulp-git, gulp-bump, gulp-filter, gulp-tag-version). These packages could introduce vulnerabilities or malicious behavior if they are compromised or typosquatted. However, the code itself does not contain malicious patterns.

gulpfile.js:28
low

Automated Version Bumping and Tagging

NPS-B3E421305135

The gulpfile uses gulp-git and gulp-tag-version to automatically commit version bumps and create git tags. While not inherently malicious, this could be exploited if the build environment is compromised to push malicious tags or commits to the repository. It also requires git credentials in the environment, which could be a target for exfiltration if the build process is compromised.

gulpfile.js:53

Files reviewed

FileVerdictWhat the reviewer saw
gulpfile.js medium The gulpfile.js contains no direct malicious patterns but uses git automation that could be risky if the build environment is compromised.
estraverse.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is estraverse safe to use?

No confirmed malware was found in estraverse@5.3.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does estraverse contain malware?

No malware was identified in estraverse@5.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was estraverse checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan estraverse together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in estraverse@5.3.0, cost nothing.

Related security reports