# eventemitter2@6.4.9 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:30:40.000Z
- Files reviewed: 2
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/eventemitter2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eventemitter2@6.4.9 on Oct 4, 2026. An AI review of 2 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Potential prototype pollution / unsafe property access

Finding ID: `NPS-5427C2F85106`

File: `lib/eventemitter2.js`

The wildcard `growListenerTree` and `searchListenerTree` functions write to `tree[name]` using event-name segments (split by delimiter) without validating that segments are safe property names such as `__proto__`, `constructor`, or `prototype`. Event names like `__proto__` could pollute `Object.prototype` on the internal tree object. However, this is a known behavioral characteristic of this library and not actively exploited in the code.

### [low] Dynamic import / module loading

Finding ID: `NPS-E7FCD8B3EA4B`

File: `lib/eventemitter2.js`

No dynamic imports, require() of computed paths, or external module loading present.

### [low] No install/build time hooks

Finding ID: `NPS-E703F07A3860`

File: `lib/eventemitter2.js`

The file only defines an event emitter; no npm lifecycle scripts, no top-level network/file/process operations are executed on import besides assigning `module.exports` or a global. `new Function` is invoked only in the non-module/browser fallback path.

### [low] Dynamic code execution

Finding ID: `NPS-C6CB47376F0C`

File: `lib/eventemitter2.js:1310`

Uses `new Function('','return this')()` to obtain the global object in the non-AMD/non-CommonJS fallback branch. This is a form of dynamic code generation/execution and can violate Content Security Policy (CSP) and bypass certain sandboxing. While the intent is to obtain the global `this`, `new Function` constructs code at runtime.

## Files reviewed

- `lib/eventemitter2.js` (medium): This is the legitimate EventEmitter2 library; the only notable concern is the `new Function` global-object retrieval fallback, which is low risk and standard practice for UMD wrappers.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
