# java-properties@1.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:17:01.000Z
- Files reviewed: 2
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/java-properties
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package java-properties@1.0.2 on Oct 6, 2026. An AI review of 2 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] File system access

Finding ID: `NPS-418A0ED8E943`

File: `dist-src/index.js:68`

The package reads arbitrary files from the filesystem via fs.readFileSync when callers pass file paths to of() or addFile(). This is the documented behavior of a properties-file parser, but it means the module can read any file the process has permission to access, including sensitive files such as .env, .npmrc, SSH keys, etc., if a caller passes such a path.

### [low] Use of deprecated/dangerous global function

Finding ID: `NPS-1CEC8EBB694B`

File: `dist-src/index.js:56`

The code uses the deprecated global unescape() function after JSON.parse() on values read from files. While the JSON.parse wrapping mitigates classic unescape injection, use of unescape() is deprecated and can produce unexpected characters. This is a robustness/code-quality concern rather than direct RCE, but it is a known risky pattern.

## Files reviewed

- `dist-src/index.js` (medium): No malicious behavior detected; the code is a legitimate properties-file parser, but it reads arbitrary files by design and uses the deprecated unescape() function, which are minor concerns rather than active threats.
- `dist-node/index.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
