Togoder security

npm package security report

file-entry-cache@11.1.5 security report

Risky patterns found that deserve a look.

Needs review Version 11.1.5 Files reviewed 2 Size 34.4 KB Scanned

Summary

Togoder Security scanned the npm package file-entry-cache@11.1.5 on Oct 6, 2026. An AI review of 2 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

File system access

NPS-5FD0E7030B99

The module reads and stats arbitrary file paths from disk (fs.statSync, fs.readFileSync) for cache validation purposes. While this is the intended functionality of a file-entry-cache library, the default configuration (restrictAccessToCwd: false) allows reading files outside the working directory, which could be abused if untrusted paths are passed to the API.

dist/index.cjs
low

Path traversal mitigation present but disabled by default

NPS-4E90D64DE2BB

A path traversal protection mechanism exists (getAbsolutePath / getAbsolutePathWithCwd) but the restrictAccessToCwd flag defaults to false, meaning the boundary check is opt-in. The code does sanitize null bytes from paths before resolution, which is a positive defensive measure.

dist/index.cjs
low

Cryptographic hashing of file contents

NPS-2A52A7122EF7

Uses node:crypto createHash with a configurable algorithm (default md5) to hash file contents when useCheckSum is enabled. This is legitimate cache-invalidation functionality, not data exfiltration or credential theft.

dist/index.cjs
low

Cache file write to disk

NPS-2C3E9A96236C

Writes cache metadata (file paths, sizes, mtimes, hashes) to a flat-cache file on disk via flat-cache library. This is expected library behavior, but it persists filesystem metadata that could leak path information if the cache file is shared.

dist/index.cjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs medium This appears to be a legitimate file-entry-cache library implementing file change detection via stat/hash comparisons; no exfiltration, credential harvesting, code execution, or backdoor patterns were found, though it performs unrestricted filesystem reads by default with path-traversal protection disabled unless explicitly enabled.
dist/index.mjs safe No malicious patterns detected; the code is a legitimate file-entry caching utility with no network, credential, obfuscation, or process execution behavior.

Frequently asked questions

Is file-entry-cache safe to use?

No confirmed malware was found in file-entry-cache@11.1.5, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does file-entry-cache contain malware?

No malware was identified in file-entry-cache@11.1.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was file-entry-cache checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan file-entry-cache together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in file-entry-cache@11.1.5, cost nothing.

Related security reports