# file-entry-cache@11.1.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:40.000Z
- Files reviewed: 2
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/file-entry-cache
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package file-entry-cache@11.1.5 on Oct 6, 2026. An AI review of 2 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] File system access

Finding ID: `NPS-5FD0E7030B99`

File: `dist/index.cjs`

The module reads and stats arbitrary file paths from disk (fs.statSync, fs.readFileSync) for cache validation purposes. While this is the intended functionality of a file-entry-cache library, the default configuration (restrictAccessToCwd: false) allows reading files outside the working directory, which could be abused if untrusted paths are passed to the API.

### [low] Path traversal mitigation present but disabled by default

Finding ID: `NPS-4E90D64DE2BB`

File: `dist/index.cjs`

A path traversal protection mechanism exists (getAbsolutePath / getAbsolutePathWithCwd) but the restrictAccessToCwd flag defaults to false, meaning the boundary check is opt-in. The code does sanitize null bytes from paths before resolution, which is a positive defensive measure.

### [low] Cryptographic hashing of file contents

Finding ID: `NPS-2A52A7122EF7`

File: `dist/index.cjs`

Uses node:crypto createHash with a configurable algorithm (default md5) to hash file contents when useCheckSum is enabled. This is legitimate cache-invalidation functionality, not data exfiltration or credential theft.

### [low] Cache file write to disk

Finding ID: `NPS-2C3E9A96236C`

File: `dist/index.cjs`

Writes cache metadata (file paths, sizes, mtimes, hashes) to a flat-cache file on disk via flat-cache library. This is expected library behavior, but it persists filesystem metadata that could leak path information if the cache file is shared.

## Files reviewed

- `dist/index.cjs` (medium): This appears to be a legitimate file-entry-cache library implementing file change detection via stat/hash comparisons; no exfiltration, credential harvesting, code execution, or backdoor patterns were found, though it performs unrestricted filesystem reads by default with path-traversal protection disabled unless explicitly enabled.
- `dist/index.mjs` (safe): No malicious patterns detected; the code is a legitimate file-entry caching utility with no network, credential, obfuscation, or process execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
