Summary
Togoder Security scanned the npm package file-entry-cache@11.1.5 on Oct 6, 2026. An AI review of 2 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
File system access
NPS-5FD0E7030B99
The module reads and stats arbitrary file paths from disk (fs.statSync, fs.readFileSync) for cache validation purposes. While this is the intended functionality of a file-entry-cache library, the default configuration (restrictAccessToCwd: false) allows reading files outside the working directory, which could be abused if untrusted paths are passed to the API.
Path traversal mitigation present but disabled by default
NPS-4E90D64DE2BB
A path traversal protection mechanism exists (getAbsolutePath / getAbsolutePathWithCwd) but the restrictAccessToCwd flag defaults to false, meaning the boundary check is opt-in. The code does sanitize null bytes from paths before resolution, which is a positive defensive measure.
Cryptographic hashing of file contents
NPS-2A52A7122EF7
Uses node:crypto createHash with a configurable algorithm (default md5) to hash file contents when useCheckSum is enabled. This is legitimate cache-invalidation functionality, not data exfiltration or credential theft.
Cache file write to disk
NPS-2C3E9A96236C
Writes cache metadata (file paths, sizes, mtimes, hashes) to a flat-cache file on disk via flat-cache library. This is expected library behavior, but it persists filesystem metadata that could leak path information if the cache file is shared.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs | medium | This appears to be a legitimate file-entry-cache library implementing file change detection via stat/hash comparisons; no exfiltration, credential harvesting, code execution, or backdoor patterns were found, though it performs unrestricted filesystem reads by default with path-traversal protection disabled unless explicitly enabled. |
| dist/index.mjs | safe | No malicious patterns detected; the code is a legitimate file-entry caching utility with no network, credential, obfuscation, or process execution behavior. |
Scanned versions of file-entry-cache
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 11.1.5 | Needs review | 2 | Oct 6, 2026 |
Frequently asked questions
Is file-entry-cache safe to use?
No confirmed malware was found in file-entry-cache@11.1.5, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does file-entry-cache contain malware?
No malware was identified in file-entry-cache@11.1.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was file-entry-cache checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan file-entry-cache together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in file-entry-cache@11.1.5, cost nothing.