# fdir@6.5.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:35.000Z
- Files reviewed: 2
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/fdir
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package fdir@6.5.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic module loading

Finding ID: `NPS-160D5790A17A`

File: `dist/index.cjs`

The code attempts to require('picomatch') inside a try/catch block. This is a normal optional dependency loading pattern for the fdir package, not malicious dynamic loading. The resolved module name is a literal string and not user-controlled.

### [low] dynamic-module-loading

Finding ID: `NPS-A1F83205B871`

File: `dist/index.mjs:372`

The code attempts to resolve and load the 'picomatch' module at import time using createRequire. While this is a legitimate optional dependency pattern for glob matching, it constitutes dynamic module loading at import time based on available modules.

## Files reviewed

- `dist/index.cjs` (safe): This is a directory traversal/walking library (fdir) with standard filesystem operations; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning were detected.
- `dist/index.mjs` (safe): This is the fdir directory traversal library with no malicious patterns; only a benign optional picomatch dependency load at module initialization.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
