# event-target-shim@5.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:30:15.000Z
- Files reviewed: 3
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/event-target-shim
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package event-target-shim@5.0.1 on Oct 4, 2026. An AI review of 3 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Dynamic code execution

Finding ID: `NPS-1D3DE343A808`

File: `dist/event-target-shim.umd.js:1`

The code uses the Function constructor ('Function("return this")()') to obtain a reference to the global object. While this is a common UMD pattern and not inherently malicious, use of dynamic code generation (new Function/eval) is a potential risk indicator and may be disallowed in strict CSP environments.

### [low] Top-level side effects / global pollution

Finding ID: `NPS-B603AC659F08`

File: `dist/event-target-shim.umd.js:1`

The UMD wrapper executes immediately on load, attaches to the global object, and mutates window.Event and window.EventTarget prototypes via Object.setPrototypeOf. This runs at import time and modifies global built-ins, which could affect other code in unexpected ways.

## Files reviewed

- `dist/event-target-shim.umd.js` (medium): This appears to be a legitimate, non-malicious polyfill/shim for EventTarget; the only minor concern is use of the Function constructor for global object detection, a common UMD pattern.
- `dist/event-target-shim.js` (safe): This is the well-known event-target-shim polyfill library; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or suspicious behavior were detected.
- `dist/event-target-shim.mjs` (safe): No malicious patterns detected; the code is a legitimate event-target shim library with no network, filesystem, process, or obfuscated behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
