Togoder security

npm package security report

java-properties npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.0.2 Files reviewed 2 Size 9.3 KB Scanned

Summary

Togoder Security scanned the npm package java-properties@1.0.2 on Oct 6, 2026. An AI review of 2 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
1
low

Findings 2

medium

File system access

NPS-418A0ED8E943

The package reads arbitrary files from the filesystem via fs.readFileSync when callers pass file paths to of() or addFile(). This is the documented behavior of a properties-file parser, but it means the module can read any file the process has permission to access, including sensitive files such as .env, .npmrc, SSH keys, etc., if a caller passes such a path.

dist-src/index.js:68
low

Use of deprecated/dangerous global function

NPS-1CEC8EBB694B

The code uses the deprecated global unescape() function after JSON.parse() on values read from files. While the JSON.parse wrapping mitigates classic unescape injection, use of unescape() is deprecated and can produce unexpected characters. This is a robustness/code-quality concern rather than direct RCE, but it is a known risky pattern.

dist-src/index.js:56

Files reviewed

FileVerdictWhat the reviewer saw
dist-src/index.js medium No malicious behavior detected; the code is a legitimate properties-file parser, but it reads arbitrary files by design and uses the deprecated unescape() function, which are minor concerns rather than active threats.
dist-node/index.js safe No malicious patterns detected

Scanned versions of java-properties

VersionVerdictFilesScanned
1.0.2 Needs review 2 Oct 6, 2026

Frequently asked questions

Is java-properties safe to use?

No confirmed malware was found in java-properties@1.0.2, but the review flagged 1 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does java-properties contain malware?

No malware was identified in java-properties@1.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was java-properties checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan java-properties together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in java-properties@1.0.2, cost nothing.

Related security reports