# hermes-parser@0.25.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:17:00.000Z
- Files reviewed: 22
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/hermes-parser
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package hermes-parser@0.25.1 on Oct 6, 2026. An AI review of 22 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic WASM loading

Finding ID: `NPS-0D34E9ED6696`

File: `dist/HermesParser.js:45`

The code initializes a WebAssembly module (HermesParserWASM) and uses emscripten cwrap bindings for parsing. While dynamic code execution via WASM is present, it is a legitimate parser implementation, not obfuscated malware. The WASM module is imported from a relative file (./HermesParserWASM).

### [low] Memory manipulation

Finding ID: `NPS-4456BAC11492`

File: `dist/HermesParser.js:87`

Uses _malloc and _free to allocate/free WASM heap memory for source text. This is normal for WASM interop and does not involve file system or process manipulation.

## Files reviewed

- `dist/HermesASTAdapter.js` (safe): No malicious patterns detected; the code is a clean AST transformation adapter with no network, filesystem, process, or dynamic execution behavior.
- `dist/HermesParser.js` (safe): The code is a legitimate JavaScript parser wrapper around a Hermes WASM module, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning.
- `dist/HermesParserDecodeUTF8String.js` (safe): No malicious patterns detected; the code is a straightforward UTF-8 string decoder with no network, filesystem, process, or dynamic execution behavior.
- `dist/HermesParserDeserializer.js` (safe): No malicious patterns detected
- `dist/HermesParserNodeDeserializers.js` (safe): This generated AST deserializer file contains only pure data transformation functions with no network, filesystem, process, or dynamic code execution patterns.
- `dist/HermesToESTreeAdapter.js` (safe): No malicious patterns detected in this AST adapter code; it performs pure AST transformations without network, filesystem, process, or dynamic code execution.
- `dist/ParserOptions.js` (safe): No malicious patterns detected
- `dist/babel/TransformESTreeToBabel.js` (safe): This file is a standard AST transformer from Meta's Hermes parser that converts ESTree to Babel AST format without any suspicious or malicious behavior.
- `dist/estree/StripComponentSyntax.js` (safe): This is a legitimate Flow-to-ESTree AST transform from Meta's Flow toolchain that performs only pure syntax tree manipulation with no I/O, network, process, or dynamic code execution.
- `dist/estree/StripFlowTypes.js` (safe): No malicious patterns detected; the code is a benign AST transform that strips Flow type annotations.
- `dist/estree/StripFlowTypesForBabel.js` (safe): No malicious patterns detected
- `dist/generated/ESTreeVisitorKeys.js` (safe): No malicious patterns detected
- `dist/generated/ParserVisitorKeys.js` (safe): This generated file contains only a static data structure of AST visitor keys and exports constants, with no executable logic or malicious patterns.
- `dist/getModuleDocblock.js` (safe): No malicious patterns detected; code only parses docblock comments and directives from a provided AST without network, filesystem, process, or dynamic execution behavior.
- `dist/index.js` (safe): No malicious patterns detected
- `dist/transform/SimpleTransform.js` (safe): No malicious patterns detected; the file is a legitimate AST transformation utility with no network, filesystem, process, or dynamic execution activity.
- `dist/transform/astArrayMutationHelpers.js` (safe): No malicious patterns detected; the file contains only pure array manipulation utility functions with bounds checking and no network, filesystem, process, or dynamic code execution behavior.
- `dist/transform/astNodeMutationHelpers.js` (safe): No malicious patterns detected; the file contains benign AST mutation helper functions with no network, filesystem, process execution, or obfuscated code.
- `dist/traverse/SimpleTraverser.js` (safe): No malicious patterns detected
- `dist/traverse/getVisitorKeys.js` (safe): No malicious patterns detected; the code only provides visitor key lookup utilities for an AST traversal library.
- `dist/utils/createSyntaxError.js` (safe): No malicious patterns detected
- `dist/utils/mutateESTreeASTForPrettier.js` (safe): No malicious patterns detected; the code is a legitimate AST transformation utility for Prettier compatibility in Flow/Hermes tooling with no network, filesystem, process, or dynamic execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
