# isexe@2.0.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:17:00.000Z
- Files reviewed: 3
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/isexe@2.0.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package isexe@2.0.0 on Oct 6, 2026. An AI review of 3 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic module loading

Finding ID: `NPS-CB69BAA284B9`

File: `index.js:4`

The code conditionally requires './windows.js' or './mode.js' based on platform. This is a common pattern and not malicious, but it does involve dynamic module selection.

## Files reviewed

- `index.js` (safe): The code implements a cross-platform file executable check utility with no malicious patterns, data exfiltration, or suspicious behavior.
- `mode.js` (safe): The module is a benign implementation of the isexe utility from the npm 'isexe' package, containing no malicious patterns.
- `windows.js` (safe): This is a legitimate, widely-used npm package (isexe) implementation for checking executable status on Windows; no malicious patterns detected.

## Version ranges

None of the 2 scanned versions of isexe are flagged high or critical. The latest scanned version, 4.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.0.0 (`4.0.0`): clean
- 3.1.1 (`3.1.1`): not scanned
- 2.0.0 (`2.0.0`): clean

## Scanned versions

- [4.0.0](https://security.togoder.click/npm/isexe@4.0.0): safe, 2026-10-06T14:22:44.000Z
- [2.0.0](https://security.togoder.click/npm/isexe@2.0.0): safe, 2026-10-06T14:17:00.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
