# iron-webcrypto@1.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:33:23.000Z
- Files reviewed: 3
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/iron-webcrypto
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package iron-webcrypto@1.2.1 on Oct 4, 2026. An AI review of 3 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] weak cryptography (SHA-1 in PBKDF2)

Finding ID: `NPS-3ACF378AE9E6`

File: `dist/index.js`

PBKDF2 is invoked with the hardcoded hash 'SHA-1' in generateKey. Although this module appears to be a faithful re-implementation of @hapi/iron's browser-compatible sealing/unsealing logic, using SHA-1 inside PBKDF2 is cryptographically weak and may be flagged by security scanners. Note also that the default iterations is 1, which is far too low for password-based key derivation.

### [low] non-constant-time behavior / timing side-channel in fixedTimeComparison

Finding ID: `NPS-E6D141FC26F1`

File: `dist/index.js`

fixedTimeComparison short-circuits when lengths differ (setting b = a) but the loop itself is constant-time over a.length. This is similar to the well-known hapi/iron implementation. No data exfiltration or malicious behavior is present; the loop is intended to be constant-time, though JS engines make true constant-time guarantees impossible.

## Files reviewed

- `dist/index.js` (medium): This is a browser/WebCrypto reimplementation of @hapi/iron seal/unseal (base64url, AES-CBC/CTR, HMAC, PBKDF2) with no exfiltration, shell, eval, or credential-harvesting code, but it uses SHA-1 in PBKDF2 and a default iteration count of 1, which are cryptographic weaknesses.
- `dist/example.js` (safe): No malicious patterns detected; the code demonstrates legitimate use of iron-webcrypto for sealing and unsealing data with no exfiltration, obfuscation, or suspicious behavior.
- `dist/index.cjs` (safe): No malicious patterns detected; the code implements a legitimate cryptographic sealing utility with no data exfiltration, credential harvesting, obfuscation, or other security red flags.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
