# immer@11.1.18 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:16:54.000Z
- Files reviewed: 22
- Findings: no findings
- Report: https://security.togoder.click/npm/immer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package immer@11.1.18 on Oct 6, 2026. An AI review of 22 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/cjs/immer.cjs.development.js` (safe): No malicious patterns detected; the code is a legitimate, unmodified build of the Immer immutability library.
- `dist/cjs/immer.cjs.production.js` (safe): No malicious patterns detected; this is the legitimate Immer library production bundle with no signs of data exfiltration, obfuscation, or unauthorized system access.
- `dist/cjs/index.js` (safe): No malicious patterns detected
- `dist/immer.legacy-esm.js` (safe): No malicious patterns detected; the code is the legitimate Immer library implementation for immutable state management with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns.
- `dist/immer.mjs` (safe): No malicious patterns detected; this is a legitimate build of the Immer immutability library with no data exfiltration, credential harvesting, obfuscated payloads, or dynamic code execution.
- `dist/immer.production.mjs` (safe): This is a legitimate minified production build of the Immer immutable state library; no malicious patterns, data exfiltration, credential harvesting, obfuscated payloads, process spawning, or other security concerns were detected.
- `src/core/current.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/core/finalize.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/core/immerClass.ts` (safe): No malicious patterns detected; the code is a legitimate implementation of the Immer immutable state library with no external data exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
- `src/core/proxy.ts` (safe): No malicious patterns detected
- `src/core/scope.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/immer.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/internal.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/plugins/arrayMethods.ts` (safe): No malicious patterns detected; the file is a legitimate Immer plugin implementing optimized array method handling for draft proxies.
- `src/plugins/mapset.ts` (safe): This is the legitimate Immer MapSet plugin implementation with no malicious patterns detected.
- `src/plugins/patches.ts` (safe): No malicious patterns detected; the code is part of the Immer patch plugin and contains only legitimate patching logic with built-in prototype pollution protections.
- `src/types/types-external.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/types/types-internal.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/common.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/env.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/errors.ts` (safe): No malicious patterns detected; the file is a standard Immer error-message utility with no network, filesystem, process, or dynamic-execution behavior.
- `src/utils/plugins.ts` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
