# fast-json-stable-stringify@2.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:38.000Z
- Files reviewed: 6
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/fast-json-stable-stringify
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package fast-json-stable-stringify@2.1.0 on Oct 6, 2026. An AI review of 6 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic module loading

Finding ID: `NPS-B255C430D67F`

File: `benchmark/index.js:17`

The code uses require(name) where 'name' is a computed value from the stringifyPackages object keys. While the keys are currently hardcoded to known package names, this pattern could allow loading arbitrary modules if the object were modified or if the file were tampered with. It is a potential supply chain risk if an attacker can influence the package names.

### [low] top-level code execution

Finding ID: `NPS-12E45A92FB0B`

File: `benchmark/index.js:27`

The benchmark suite runs immediately upon import (suite.run()), which could cause unexpected side effects if the module is imported by other code. However, this is typical for benchmark scripts and not inherently malicious.

## Files reviewed

- `benchmark/index.js` (medium): The benchmark script dynamically loads packages based on a hardcoded list and runs a performance test at import time; while not overtly malicious, the dynamic require pattern and top-level execution pose minor supply chain and side-effect risks.
- `example/key_cmp.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/nested.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/str.js` (safe): Cleared by Jev triage; no further analysis needed
- `example/value_cmp.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
