# jsdom@30.1.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:17:38.000Z
- Files reviewed: 653
- Findings: 10 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/jsdom
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package jsdom@30.1.1 on Oct 6, 2026. An AI review of 653 source files produced 10 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-6C790DFAC53A`

File: `lib/jsdom/living/helpers/create-event-accessor.js:100`

Uses new Function()/Function() to dynamically compile JavaScript from strings (event handler content attributes) and executes it via .call() on event dispatch. While this is intentional and spec-compliant for jsdom's event handler attribute emulation, dynamic code execution from string content is a notable risk pattern.

### [medium] Dynamic code execution

Finding ID: `NPS-C9E222206C28`

File: `lib/jsdom/living/helpers/create-event-accessor.js:130`

Constructs functions via document.defaultView.Function with generated `with` scope-chain wrapper code and invokes them. The `body` variable is derived from attribute content, effectively evaluating attacker-controllable strings.

### [medium] javascript_url_execution

Finding ID: `NPS-4F57CD3AC65B`

File: `lib/jsdom/living/nodes/HTMLFrameElement-impl.js:139`

The loadFrame function explicitly handles URLs with the 'javascript:' scheme and calls evaluateJavaScriptURL(contentWindow, url). This executes arbitrary JavaScript supplied via a frame's src attribute (e.g. <iframe src="javascript:...">). While this mimics browser behavior and is constrained to the jsdom window context, it constitutes dynamic code execution from user-controlled input and is a known XSS-style vector if jsdom content is ever treated as trusted or if scripts are enabled.

### [medium] dynamic_code_execution

Finding ID: `NPS-104C3B9CF4FD`

File: `lib/jsdom/living/nodes/HTMLFrameElement-impl.js:139`

evaluateJavaScriptURL from ../window/navigation is invoked with a URL object derived from the frame's src attribute. Depending on its implementation, this can lead to eval/new Function-style execution of attacker-influenced script. This is the only dynamic code-execution sink in the file.

### [medium] Network request with dynamic URL

Finding ID: `NPS-015A638FB436`

File: `lib/jsdom/living/nodes/HTMLScriptElement-impl.js:119`

External scripts are fetched via resourceLoader.fetch() using a URL derived from the 'src' attribute. The URL is parsed and serialized, but the fetch itself can load arbitrary remote content that is then executed via vm.runInContext().

### [medium] Dynamic code execution

Finding ID: `NPS-D0CCCC12C6EF`

File: `lib/jsdom/living/nodes/HTMLScriptElement-impl.js:263`

The code uses vm.runInContext() to execute JavaScript from script elements, including external scripts fetched over the network. While this is expected behavior for a DOM implementation like jsdom, executing untrusted script content is inherently risky if the library is used to process untrusted HTML.

### [medium] Potential security bypass via URL decoding

Finding ID: `NPS-C68FB7994729`

File: `lib/jsdom/living/window/navigation.js:10`

The function percent-decodes the javascript: URL payload and then UTF-8 decodes it before evaluation. Decoding before execution can bypass naive filters and allows encoded payloads (e.g. percent-encoded alert() or fetch() calls) to be executed, increasing the risk if callers rely on simple string checks on the URL.

### [medium] Dynamic code execution

Finding ID: `NPS-2CBF439AAE9F`

File: `lib/jsdom/living/window/navigation.js:13`

The evaluateJavaScriptURL function decodes a javascript: URL and runs it via window.eval(). While this is gated behind runScripts === 'dangerously' (an explicit opt-in that jsdom documents as unsafe), it is still a dynamic code execution primitive that can execute arbitrary script if untrusted input reaches a navigation call.

### [medium] Navigation sink for javascript: URLs

Finding ID: `NPS-1DB47F680C34`

File: `lib/jsdom/living/window/navigation.js:57`

navigate() dispatches javascript: scheme URLs to evaluateJavaScriptURL via a queued task. Any caller that can influence navigation (e.g. window.location assignment driven by user input) can trigger arbitrary script evaluation when runScripts is set to 'dangerously'.

### [medium] Prototype pollution potential

Finding ID: `NPS-5FF62DEB3CD3`

File: `lib/jsdom/utils.js:11`

The 'define' and 'mixin' functions copy property descriptors from a source object to a target. The mixin function skips keys already in target, but define does not. If untrusted input is passed as the 'properties' or 'source' argument, an attacker could inject '__proto__' or 'constructor' descriptors, potentially leading to prototype pollution.

### [low] Dynamic code execution

Finding ID: `NPS-01616F545C67`

File: `lib/generated/idl/utils.js:51`

The code uses globalObject.eval("(async function* () {})..." ) inside a try/catch to obtain the %AsyncIteratorPrototype% intrinsic. This is a functional necessity, not an obfuscated payload, and the evaluated string is a fixed constant with no external input.

### [low] malicious executable content in XML parsing

Finding ID: `NPS-B878676B32D1`

File: `lib/jsdom/living/domparsing/DOMParser-impl.js`

XML content types (text/xml, application/xml, application/xhtml+xml, image/svg+xml) are parsed with scripting disabled. While this prevents script execution, XML entities and other parser features could still be used for data exfiltration or denial-of-service. However, since scripting is disabled and the parser is controlled by jsdom, this is a standard, non-malicious implementation.

### [low] Use of with statement / scope chain manipulation

Finding ID: `NPS-60790F545D2F`

File: `lib/jsdom/living/helpers/create-event-accessor.js:120`

Wraps dynamically generated function bodies in nested `with (arguments[0]) { ... }` blocks, which alters lexical scope resolution and is a legacy pattern that can introduce scope confusion vulnerabilities.

### [low] Script execution gated by settings

Finding ID: `NPS-6E6A98CF072C`

File: `lib/jsdom/living/nodes/HTMLScriptElement-impl.js:84`

Script execution requires document._defaultView._settings.runScripts === 'dangerously', which is a security control that limits execution unless explicitly enabled. This is a mitigating factor rather than a vulnerability.

### [low] Dynamic module loading

Finding ID: `NPS-8C8521161DA2`

File: `lib/jsdom/utils.js:32`

The module attempts to require('canvas') at import time. While this is a common optional dependency pattern, it loads an external native module dynamically. If the 'canvas' package is compromised or replaced, this could execute arbitrary native code. The try/catch prevents failure if not installed.

## Files reviewed

- `lib/jsdom/living/helpers/create-event-accessor.js` (medium): This is a legitimate jsdom helper implementing HTML event handler accessors; it uses new Function/eval-like dynamic compilation to emulate content attribute handlers, which is expected behavior but represents an inherent code-execution surface without malicious intent.
- `lib/jsdom/living/nodes/HTMLFrameElement-impl.js` (medium): This jsdom HTMLFrameElement implementation is a legitimate part of the library and contains no exfiltration, credential harvesting, obfuscation, or process-spawning behavior; the only noteworthy concern is its intended support for javascript: URLs, which executes attacker-supplied script in the frame context.
- `lib/jsdom/living/nodes/HTMLScriptElement-impl.js` (medium): This is a legitimate jsdom HTMLScriptElement implementation that executes scripts via vm.runInContext() and fetches external scripts, which is expected functionality but carries inherent risk when processing untrusted content.
- `lib/jsdom/living/window/navigation.js` (medium): This is the jsdom navigation module; it contains no exfiltration, credential harvesting, install-time, or process-spawning behavior, but it does deliberately eval javascript: URLs and should be treated as dangerous only when runScripts is enabled on untrusted content.
- `lib/jsdom/utils.js` (medium): No overtly malicious code detected, but the module has potential prototype pollution risks in its property-copying utilities and dynamically loads an optional native module at import time.
- `lib/api.js` (safe): This is the legitimate jsdom library API code with no malicious patterns detected.
- `lib/generated/css-property-computed-value-resolvers.js` (safe): No malicious patterns detected; the file only imports internal CSS property resolvers and exports a Map of computed value functions.
- `lib/generated/css-property-resolved-value-resolvers.js` (safe): No malicious patterns detected
- `lib/generated/event-sets.js` (safe): No malicious patterns detected
- `lib/generated/idl/AbortController.js` (safe): This is a standard jsdom-generated WebIDL wrapper for AbortController with no malicious patterns, network access, file system manipulation, or dynamic code execution.
- `lib/generated/idl/AbortSignal.js` (safe): This is standard WebIDL-generated binding code for AbortSignal from jsdom, containing no malicious patterns, network activity, credential harvesting, or dynamic code execution.
- `lib/generated/idl/AbstractRange.js` (safe): No malicious patterns detected
- `lib/generated/idl/AddEventListenerOptions.js` (safe): No malicious patterns detected; the file is a standard webidl-conversions-based converter for AddEventListenerOptions.
- `lib/generated/idl/AssignedNodesOptions.js` (safe): This file is a standard WebIDL dictionary converter for AssignedNodesOptions with no malicious patterns, network calls, filesystem access, or dynamic code execution.
- `lib/generated/idl/Attr.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated Web IDL wrapper for the Attr interface with no network, file system, process execution, or obfuscated code.
- `lib/generated/idl/BarProp.js` (safe): The code is a standard WebIDL interface implementation for BarProp with no malicious patterns detected.
- `lib/generated/idl/BeforeUnloadEvent.js` (safe): This is standard jsdom-generated WebIDL wrapper code for the BeforeUnloadEvent interface with no malicious patterns detected.
- `lib/generated/idl/BinaryType.js` (safe): No malicious patterns detected
- `lib/generated/idl/Blob.js` (safe): No malicious patterns detected; this is a standard WebIDL-generated Blob interface binding for jsdom with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/BlobCallback.js` (safe): No malicious patterns detected; the file is a standard WebIDL callback converter with no network, filesystem, or process activity.
- `lib/generated/idl/BlobEvent.js` (safe): No malicious patterns detected; the file is a standard WebIDL-generated BlobEvent wrapper for jsdom with no network, filesystem, process, or dynamic-code-execution behavior.
- `lib/generated/idl/BlobEventInit.js` (safe): This is a standard WebIDL conversion file for the BlobEventInit dictionary, containing no malicious patterns.
- `lib/generated/idl/BlobPropertyBag.js` (safe): No malicious patterns detected; the file is a standard WebIDL-generated converter for BlobPropertyBag with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/CDATASection.js` (safe): This is a standard WebIDL-generated binding for the CDATASection DOM interface from jsdom, with no malicious patterns, obfuscation, network activity, or process execution.
- `lib/generated/idl/CSS.js` (safe): No malicious patterns detected; the file is a standard WebIDL binding for the CSS namespace with no network, filesystem, process, or dynamic execution behavior.
- `lib/generated/idl/CSSConditionRule.js` (safe): No malicious patterns detected; this is a standard jsdom WebIDL-generated interface wrapper for CSSConditionRule with no network, file system, process, or dynamic execution behavior.
- `lib/generated/idl/CSSContainerRule.js` (safe): No malicious patterns detected; the file is a standard jsdom WebIDL interface implementation for CSSContainerRule with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/CSSCounterStyleRule.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for the CSSCounterStyleRule interface with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/CSSFontFaceRule.js` (safe): No malicious patterns detected
- `lib/generated/idl/CSSGroupingRule.js` (safe): No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for the CSSGroupingRule interface with no external network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/CSSImportRule.js` (safe): No malicious patterns detected; the file is standard jsdom WebIDL-generated wrapper code for CSSImportRule with no network, filesystem, process spawning, or dynamic code execution concerns.
- `lib/generated/idl/CSSKeyframeRule.js` (safe): No malicious patterns detected; this is standard jsdom WebIDL-generated wrapper code for CSSKeyframeRule.
- `lib/generated/idl/CSSKeyframesRule.js` (safe): This is standard jsdom/webidl2js-generated DOM binding code for CSSKeyframesRule with no malicious patterns detected.
- `lib/generated/idl/CSSLayerBlockRule.js` (safe): No malicious patterns detected; the file is standard jsdom-generated WebIDL wrapper code for CSSLayerBlockRule.
- `lib/generated/idl/CSSLayerStatementRule.js` (safe): No malicious patterns detected; this is a standard WebIDL-generated wrapper module for the CSSLayerStatementRule interface in jsdom.
- `lib/generated/idl/CSSMediaRule.js` (safe): No malicious patterns detected
- `lib/generated/idl/CSSNamespaceRule.js` (safe): No malicious patterns detected; this is a standard generated WebIDL wrapper for CSSNamespaceRule from jsdom.
- `lib/generated/idl/CSSNestedDeclarations.js` (safe): No malicious patterns detected
- `lib/generated/idl/CSSPageRule.js` (safe): No malicious patterns detected
- `lib/generated/idl/CSSRule.js` (safe): No malicious patterns detected; the file is standard jsdom-generated WebIDL wrapper code for CSSRule with no network, exec, or filesystem activity.
- `lib/generated/idl/CSSRuleList.js` (safe): No malicious patterns detected
- `lib/generated/idl/CSSScopeRule.js` (safe): No malicious patterns detected; this is standard WebIDL-generated boilerplate for the CSSScopeRule interface with no network, filesystem, process, or dynamic execution activity.
- `lib/generated/idl/CSSStyleDeclaration.js` (safe): This is a standard jsdom WebIDL-generated wrapper for CSSStyleDeclaration with no malicious patterns, network calls, filesystem access, process spawning, or dynamic code execution.
- `lib/generated/idl/CSSStyleRule.js` (safe): This is a standard WebIDL-generated interface binding for CSSStyleRule from jsdom; no malicious patterns, dynamic code execution, network access, or filesystem manipulation are present.
- `lib/generated/idl/CSSStyleSheet.js` (safe): This is standard jsdom-generated WebIDL wrapper code for CSSStyleSheet with no malicious patterns detected.
- `lib/generated/idl/CSSStyleSheetInit.js` (safe): No malicious patterns detected
- `lib/generated/idl/CSSSupportsRule.js` (safe): No malicious patterns detected
- `lib/generated/idl/CanPlayTypeResult.js` (safe): No malicious patterns detected
- `lib/generated/idl/CharacterData.js` (safe): No malicious patterns detected; the code is a standard Web IDL generated wrapper for the CharacterData interface in jsdom, with no data exfiltration, dynamic code execution, or other suspicious behaviors.
- `lib/generated/idl/CloseEvent.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for the CloseEvent interface with no network, filesystem, process, or dynamic code execution capabilities.
- `lib/generated/idl/CloseEventInit.js` (safe): No malicious patterns detected
- `lib/generated/idl/Comment.js` (safe): This is a standard WebIDL-generated interface file for the Comment DOM node with no malicious patterns detected.
- `lib/generated/idl/CompositionEvent.js` (safe): No malicious patterns detected
- `lib/generated/idl/CompositionEventInit.js` (safe): No malicious patterns detected; this is a standard webidl-conversions-based type converter for the CompositionEventInit WebIDL dictionary with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/Crypto.js` (safe): This is a standard WebIDL-generated interface binding for the Crypto API (getRandomValues/randomUUID) with no malicious patterns, network activity, or suspicious code execution.
- `lib/generated/idl/CustomElementConstructor.js` (safe): No malicious patterns detected; the code is a standard WebIDL custom element constructor wrapper that validates input and applies the provided function without any exfiltration, obfuscation, or system access.
- `lib/generated/idl/CustomElementRegistry.js` (safe): No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for the CustomElementRegistry interface with no exfiltration, obfuscation, or process/network activity.
- `lib/generated/idl/CustomEvent.js` (safe): This is a standard jsdom Web IDL-generated wrapper for CustomEvent with no malicious patterns, no network, filesystem, process, or dynamic execution activity.
- `lib/generated/idl/CustomEventInit.js` (safe): No malicious patterns detected; the file is a standard WebIDL type-conversion module for CustomEventInit with no network, filesystem, process, or dynamic execution activity.
- `lib/generated/idl/DOMException.js` (safe): No malicious patterns detected; this is standard jsdom WebIDL wrapper code for the DOMException interface with no network, filesystem, process, or dynamic code execution activity.
- `lib/generated/idl/DOMImplementation.js` (safe): This is a standard Web IDL-generated wrapper for the DOMImplementation interface from the jsdom project, containing no malicious patterns.
- `lib/generated/idl/DOMParser.js` (safe): No malicious patterns detected; this is a standard WebIDL-generated DOMParser binding with no network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/DOMRect.js` (safe): No malicious patterns detected; this is standard generated DOM binding code for jsdom's DOMRect interface.
- `lib/generated/idl/DOMRectInit.js` (safe): No malicious patterns detected; the code is a standard WebIDL dictionary converter for DOMRectInit with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/DOMRectReadOnly.js` (safe): No malicious patterns detected; this is standard WebIDL-generated DOMRectReadOnly binding code for jsdom with only internal module requires and no network, filesystem, process, or dynamic code execution.
- `lib/generated/idl/DOMStringMap.js` (safe): No malicious patterns detected
- `lib/generated/idl/DOMTokenList.js` (safe): No malicious patterns detected; the file is standard jsdom WebIDL-generated wrapper code for DOMTokenList with no network, filesystem, process, or dynamic execution behavior.
- `lib/generated/idl/DeviceMotionEvent.js` (safe): No malicious patterns detected; the file is a standard WebIDL-generated interface wrapper for DeviceMotionEvent with no data exfiltration, environment harvesting, dynamic code execution, or other suspicious behavior.
- `lib/generated/idl/DeviceMotionEventAcceleration.js` (safe): This is a standard jsdom-generated WebIDL wrapper for DeviceMotionEventAcceleration; no malicious patterns detected.
- `lib/generated/idl/DeviceMotionEventAccelerationInit.js` (safe): No malicious patterns detected; the file is a standard WebIDL-generated converter for DeviceMotionEventAccelerationInit with only type-checking and value conversion logic.
- `lib/generated/idl/DeviceMotionEventInit.js` (safe): No malicious patterns detected
- `lib/generated/idl/DeviceMotionEventRotationRate.js` (safe): No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for DeviceMotionEventRotationRate.
- `lib/generated/idl/DeviceMotionEventRotationRateInit.js` (safe): No malicious patterns detected; the file contains standard WebIDL type conversion logic for DeviceMotionEventRotationRateInit with no network, filesystem, process, or dynamic execution behavior.
- `lib/generated/idl/DeviceOrientationEvent.js` (safe): No malicious patterns detected in the DeviceOrientationEvent interface wrapper; the code appears to be a standard generated WebIDL binding for jsdom.
- `lib/generated/idl/DeviceOrientationEventInit.js` (safe): No malicious patterns detected
- `lib/generated/idl/DocumentFragment.js` (safe): This is a standard generated WebIDL wrapper for the DocumentFragment interface in jsdom, containing no malicious patterns, network activity, or dangerous code execution.
- `lib/generated/idl/DocumentReadyState.js` (safe): No malicious patterns detected
- `lib/generated/idl/DocumentType.js` (safe): This is a standard jsdom-generated WebIDL wrapper for DocumentType with no malicious patterns, network calls, or dynamic code execution.
- `lib/generated/idl/ElementCreationOptions.js` (safe): No malicious patterns detected; the file is a standard WebIDL converter for ElementCreationOptions with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/ElementDefinitionOptions.js` (safe): No malicious patterns detected in this WebIDL conversion helper; it only performs standard type coercion using webidl-conversions.
- `lib/generated/idl/ElementInternals.js` (safe): This is standard jsdom-generated WebIDL wrapper code for the ElementInternals interface with no malicious patterns detected.
- `lib/generated/idl/EndingType.js` (safe): No malicious patterns detected
- `lib/generated/idl/ErrorEvent.js` (safe): This is a standard auto-generated WebIDL binding file for the ErrorEvent interface in jsdom; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, network requests, process spawning, or dynamic code execution were detected.
- `lib/generated/idl/ErrorEventInit.js` (safe): This is a standard WebIDL type conversion module for ErrorEventInit with no malicious patterns; it only performs data validation and normalization.
- `lib/generated/idl/Event.js` (safe): No malicious patterns detected; the file is standard generated WebIDL boilerplate for a DOM Event interface with no obfuscation, network, filesystem, process, credential, or dynamic-code risks.
- `lib/generated/idl/EventHandlerNonNull.js` (safe): No malicious patterns detected; the code is a standard WebIDL callback converter with no network, filesystem, process, or dynamic code execution activity.
- `lib/generated/idl/EventInit.js` (safe): No malicious patterns detected; the file is a standard WebIDL dictionary converter for EventInit that performs only local, type-checked property conversion.
- `lib/generated/idl/EventListener.js` (safe): No malicious patterns detected; the code is a standard WebIDL EventListener converter with no exfiltration, credential harvesting, obfuscation, or network/process activity.
- `lib/generated/idl/EventListenerOptions.js` (safe): No malicious patterns detected
- `lib/generated/idl/EventModifierInit.js` (safe): No malicious patterns detected; the file is a standard WebIDL conversion utility for event modifier initialization with no network, filesystem, or code execution activity.
- `lib/generated/idl/EventTarget.js` (safe): This is standard generated WebIDL binding code for the EventTarget interface with no malicious patterns, network calls, file system access, or dynamic code execution.
- `lib/generated/idl/External.js` (safe): This file is a standard jsdom-generated WebIDL binding for the External interface, containing only normal interface plumbing and no malicious patterns.
- `lib/generated/idl/File.js` (safe): This is standard WebIDL-generated binding code for the File interface from jsdom; no malicious patterns detected.
- `lib/generated/idl/FileList.js` (safe): This is standard jsdom-generated WebIDL binding code for the FileList interface with no malicious patterns, network activity, filesystem access, or dynamic code execution.
- `lib/generated/idl/FilePropertyBag.js` (safe): No malicious patterns detected; the code is a standard WebIDL type conversion helper with no network, filesystem, process, or dynamic execution activity.
- `lib/generated/idl/FileReader.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for FileReader with no network, filesystem, process, or dynamic code execution activity.
- `lib/generated/idl/FocusEvent.js` (safe): This is a standard jsdom-generated WebIDL wrapper for FocusEvent with no malicious patterns, network activity, or dynamic code execution detected.
- `lib/generated/idl/FocusEventInit.js` (safe): No malicious patterns detected
- `lib/generated/idl/FormData.js` (safe): No malicious patterns detected; this is standard webidl2js-generated FormData wrapper code with no network, filesystem, process, or dynamic execution concerns.
- `lib/generated/idl/Function.js` (safe): No malicious patterns detected; the code is a standard WebIDL function converter wrapper with no exfiltration, obfuscation, or dynamic execution.
- `lib/generated/idl/GetRootNodeOptions.js` (safe): No malicious patterns detected; the file contains standard WebIDL dictionary conversion logic with no network, filesystem, process, or dynamic code execution activity.
- `lib/generated/idl/HTMLAnchorElement.js` (safe): No malicious patterns detected in this auto-generated WebIDL wrapper for HTMLAnchorElement; it contains only standard DOM property accessors and reflection helpers.
- `lib/generated/idl/HTMLAreaElement.js` (safe): The code is a standard WebIDL-generated wrapper for the HTMLAreaElement interface from jsdom; no malicious patterns, exfiltration, obfuscation, or installation hooks were detected.
- `lib/generated/idl/HTMLAudioElement.js` (safe): This is a standard jsdom WebIDL wrapper for HTMLAudioElement with no malicious patterns detected.
- `lib/generated/idl/HTMLBRElement.js` (safe): This is a standard jsdom WebIDL wrapper for HTMLBRElement with no malicious patterns detected.
- `lib/generated/idl/HTMLBaseElement.js` (safe): No malicious patterns detected; the code is standard jsdom-generated WebIDL wrapper code for HTMLBaseElement with no data exfiltration, process spawning, or dynamic execution.
- `lib/generated/idl/HTMLBodyElement.js` (safe): This is standard jsdom-generated WebIDL bindings for HTMLBodyElement, containing only DOM property accessors, event handler registration, and constructor logic with no malicious patterns.
- `lib/generated/idl/HTMLButtonElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLButtonElement with no exfiltration, obfuscation, process spawning, or dynamic code execution.
- `lib/generated/idl/HTMLCanvasElement.js` (safe): This is a standard webidl-conversions generated wrapper for HTMLCanvasElement in the jsdom library, containing no malicious patterns, network activity, dynamic code execution, or process spawning.
- `lib/generated/idl/HTMLCollection.js` (safe): This is standard WebIDL-generated binding code for the HTMLCollection interface with no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or backdoors.
- `lib/generated/idl/HTMLDListElement.js` (safe): No malicious patterns detected; the file is standard jsdom-generated WebIDL binding code for HTMLDListElement with no network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/HTMLDataElement.js` (safe): No malicious patterns detected; the file is a standard jsdom WebIDL-generated wrapper for HTMLDataElement with no exfiltration, dynamic execution, process spawning, or install-time behavior.
- `lib/generated/idl/HTMLDataListElement.js` (safe): This is a standard jsdom IDL wrapper for HTMLDataListElement with no malicious patterns, network access, dynamic code execution, or credential harvesting.
- `lib/generated/idl/HTMLDetailsElement.js` (safe): No malicious patterns detected; the file contains standard jsdom-generated WebIDL bindings for HTMLDetailsElement with no network, FS, process, or dynamic execution behavior.
- `lib/generated/idl/HTMLDialogElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLDirectoryElement.js` (safe): No malicious patterns detected; the file is a standard generated WebIDL wrapper for the obsolete HTMLDirectoryElement interface in jsdom with no network, filesystem, process, or dynamic code execution activity.
- `lib/generated/idl/HTMLDivElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated IDL wrapper for HTMLDivElement with no network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/HTMLEmbedElement.js` (safe): No malicious patterns detected; this is a standard jsdom generated WebIDL wrapper for HTMLEmbedElement with no network, filesystem, process, or dynamic execution behavior.
- `lib/generated/idl/HTMLFieldSetElement.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for the HTMLFieldSetElement interface.
- `lib/generated/idl/HTMLFontElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLFontElement with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/HTMLFormControlsCollection.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLFormControlsCollection with no malicious patterns, network access, environment harvesting, or dynamic code execution.
- `lib/generated/idl/HTMLFormElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLFormElement with no malicious patterns, network activity, filesystem access, or code execution.
- `lib/generated/idl/HTMLFrameElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLFrameElement with no network, filesystem, or dynamic code execution behavior.
- `lib/generated/idl/HTMLFrameSetElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for the HTMLFrameSetElement interface with no malicious patterns, network calls, dynamic code execution, or install-time behavior.
- `lib/generated/idl/HTMLHRElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLHeadElement.js` (safe): This is a standard generated WebIDL wrapper for HTMLHeadElement in jsdom with no malicious patterns, external calls, or suspicious behavior.
- `lib/generated/idl/HTMLHeadingElement.js` (safe): No malicious patterns detected in this jsdom-generated interface file; it only implements standard DOM HTMLHeadingElement bindings.
- `lib/generated/idl/HTMLHtmlElement.js` (safe): No malicious patterns detected; the code is a standard jsdom-generated WebIDL wrapper for HTMLHtmlElement with no network, filesystem, process, or dynamic execution activity.
- `lib/generated/idl/HTMLIFrameElement.js` (safe): This is a standard generated WebIDL wrapper for HTMLIFrameElement from jsdom; no malicious patterns, exfiltration, dynamic code execution, or install-time behavior were detected.
- `lib/generated/idl/HTMLImageElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLImageElement with no malicious patterns, network activity, process spawning, or dynamic code execution.
- `lib/generated/idl/HTMLInputElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLLIElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLLabelElement.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for HTMLLabelElement with no network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/HTMLLegendElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for the HTMLLegendElement interface with no malicious patterns detected.
- `lib/generated/idl/HTMLLinkElement.js` (safe): This is a standard jsdom-generated WebIDL binding file for HTMLLinkElement with no malicious patterns, network activity, credential access, or dynamic code execution.
- `lib/generated/idl/HTMLMapElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLMarqueeElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLMediaElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLMenuElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLMenuElement with no malicious patterns, network activity, dynamic code execution, or filesystem access.
- `lib/generated/idl/HTMLMetaElement.js` (safe): This file is a standard jsdom-generated WebIDL wrapper for HTMLMetaElement with no malicious patterns, network access, process spawning, or code execution beyond normal property accessors.
- `lib/generated/idl/HTMLMeterElement.js` (safe): No malicious patterns detected; this is standard jsdom WebIDL wrapper code for HTMLMeterElement with no network, filesystem, process, or dynamic execution activity.
- `lib/generated/idl/HTMLModElement.js` (safe): This is standard jsdom-generated WebIDL wrapper code for HTMLModElement with no malicious patterns, network calls, process spawning, or credential access.
- `lib/generated/idl/HTMLOListElement.js` (safe): This is a legitimate jsdom WebIDL-generated wrapper for HTMLOListElement with no malicious patterns detected.
- `lib/generated/idl/HTMLObjectElement.js` (safe): No malicious patterns detected; this is a standard auto-generated jsdom WebIDL wrapper for HTMLObjectElement with only expected DOM property reflection and validation logic.
- `lib/generated/idl/HTMLOptGroupElement.js` (safe): No malicious patterns detected; this is standard jsdom HTMLOptGroupElement IDL wrapper code with no network, filesystem, process, or dynamic execution concerns.
- `lib/generated/idl/HTMLOptionElement.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated Web IDL wrapper for HTMLOptionElement with no external network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/HTMLOptionsCollection.js` (safe): No malicious patterns detected; the file is a standard jsdom WebIDL-generated wrapper for HTMLOptionsCollection with no exfiltration, obfuscation, process spawning, or unexpected side effects.
- `lib/generated/idl/HTMLOutputElement.js` (safe): This file is a standard jsdom WebIDL-generated wrapper for HTMLOutputElement with no malicious patterns, network requests, dynamic code execution, or file system manipulation.
- `lib/generated/idl/HTMLParagraphElement.js` (safe): This file is a standard jsdom WebIDL-generated wrapper for HTMLParagraphElement with no malicious patterns, network activity, filesystem access, or dynamic code execution.
- `lib/generated/idl/HTMLParamElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for the HTMLParamElement interface with no malicious patterns detected.
- `lib/generated/idl/HTMLPictureElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLPictureElement with only benign DOM-related operations and local module imports.
- `lib/generated/idl/HTMLPreElement.js` (safe): This is a standard generated WebIDL wrapper for the HTMLPreElement interface in jsdom, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/generated/idl/HTMLProgressElement.js` (safe): No malicious patterns detected; the code is a standard WebIDL-generated wrapper for HTMLProgressElement with no network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/HTMLQuoteElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLQuoteElement with no malicious patterns, network activity, credential access, or dynamic code execution.
- `lib/generated/idl/HTMLScriptElement.js` (safe): This is a standard generated WebIDL binding for HTMLScriptElement in jsdom, containing only DOM property accessors and no malicious patterns.
- `lib/generated/idl/HTMLSelectElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLSelectElement.
- `lib/generated/idl/HTMLSlotElement.js` (safe): This file is a standard jsdom generated WebIDL wrapper for HTMLSlotElement with no malicious patterns, network activity, file system access, or dynamic code execution.
- `lib/generated/idl/HTMLSourceElement.js` (safe): This file is a standard jsdom-generated WebIDL wrapper for HTMLSourceElement with no malicious patterns, network calls, credential access, or dynamic code execution.
- `lib/generated/idl/HTMLSpanElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLSpanElement with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/HTMLStyleElement.js` (safe): This is a standard jsdom DOM interface wrapper for HTMLStyleElement with no network, filesystem, process, or dynamic execution patterns.
- `lib/generated/idl/HTMLTableCaptionElement.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLTableCaptionElement with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/HTMLTableCellElement.js` (safe): No malicious patterns detected; this is a standard generated WebIDL binding for HTMLTableCellElement from jsdom.
- `lib/generated/idl/HTMLTableColElement.js` (safe): No malicious patterns detected
- `lib/generated/idl/HTMLTableElement.js` (safe): No malicious patterns detected; the file contains standard jsdom-generated wrapper code for HTMLTableElement with no data exfiltration, dynamic code execution, or process spawning.
- `lib/generated/idl/HTMLTableRowElement.js` (safe): No malicious patterns detected; the file is a standard generated WebIDL implementation for HTMLTableRowElement in jsdom.
- `lib/generated/idl/HTMLTableSectionElement.js` (safe): The code is a standard jsdom WebIDL-generated wrapper for HTMLTableSectionElement with no malicious patterns, network calls, dynamic code execution, or filesystem access.
- `lib/generated/idl/HTMLTemplateElement.js` (safe): This file is a standard jsdom WebIDL-generated wrapper for HTMLTemplateElement with no malicious patterns: it only performs type conversions, wrapper registration, and constructor installation without network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/HTMLTextAreaElement.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for HTMLTextAreaElement with no network, filesystem, process, or dynamic code execution activity.
- `lib/generated/idl/HTMLTimeElement.js` (safe): This file is a standard jsdom-generated WebIDL wrapper for the HTMLTimeElement interface with no malicious patterns, no network or filesystem access, and no dynamic code execution.
- `lib/generated/idl/HTMLTitleElement.js` (safe): No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for HTMLTitleElement with no exfiltration, obfuscation, or dynamic execution.
- `lib/generated/idl/HTMLTrackElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLTrackElement with no malicious patterns, network calls, or suspicious code execution.
- `lib/generated/idl/HTMLUListElement.js` (safe): No malicious patterns detected; the code is a standard jsdom IDL-generated wrapper for HTMLUListElement with no exfiltration, obfuscation, or process/file system abuse.
- `lib/generated/idl/HTMLUnknownElement.js` (safe): This is a standard generated WebIDL wrapper for the HTMLUnknownElement interface in jsdom, with no malicious patterns, network activity, filesystem access, or dynamic code execution.
- `lib/generated/idl/HTMLVideoElement.js` (safe): This is a standard jsdom-generated WebIDL wrapper for HTMLVideoElement with no malicious patterns, external network calls, credential harvesting, dynamic code execution, or other security concerns.
- `lib/generated/idl/HashChangeEvent.js` (safe): No malicious patterns detected
- `lib/generated/idl/HashChangeEventInit.js` (safe): This is a standard WebIDL dictionary converter for HashChangeEventInit with no malicious patterns, network calls, filesystem access, or code execution.
- `lib/generated/idl/Headers.js` (safe): This is standard auto-generated WebIDL bindings for the Headers interface with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
- `lib/generated/idl/History.js` (safe): No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for the History interface with no exfiltration, code execution, or filesystem/network access.
- `lib/generated/idl/InputEvent.js` (safe): This file is a standard auto-generated WebIDL wrapper for the InputEvent interface from jsdom, containing no malicious patterns, network calls, dynamic execution, or file system access.
- `lib/generated/idl/InputEventInit.js` (safe): The code is a standard WebIDL type conversion utility with no malicious patterns, network access, file system operations, or dynamic code execution.
- `lib/generated/idl/KeyboardEvent.js` (safe): No malicious patterns detected; the code is a standard jsdom-generated WebIDL binding for KeyboardEvent.
- `lib/generated/idl/KeyboardEventInit.js` (safe): The file is a standard WebIDL dictionary converter for KeyboardEventInit with only safe type conversions and default value assignments; no malicious patterns detected.
- `lib/generated/idl/Location.js` (safe): This is standard jsdom-generated WebIDL binding code for the DOM Location interface with no malicious patterns, network activity, credential access, or dynamic code execution.
- `lib/generated/idl/MediaList.js` (safe): No malicious patterns detected; this is standard jsdom WebIDL-generated wrapper code for the MediaList interface.
- `lib/generated/idl/MessageEvent.js` (safe): No malicious patterns detected
- `lib/generated/idl/MessageEventInit.js` (safe): No malicious patterns detected
- `lib/generated/idl/MimeType.js` (safe): This is a standard generated WebIDL wrapper for the MimeType interface (likely from jsdom), containing no network, filesystem, process, credential, or dynamic code execution patterns.
- `lib/generated/idl/MimeTypeArray.js` (safe): No malicious patterns detected; this is a standard WebIDL-generated binding file for the MimeTypeArray interface with no network, filesystem, process, or dynamic code execution behavior.
- `lib/generated/idl/MouseEvent.js` (safe): No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for MouseEvent with only local module imports and no network, filesystem, process, or dynamic code execution concerns.
- `lib/generated/idl/MouseEventInit.js` (safe): No malicious patterns detected; the code is standard WebIDL dictionary conversion logic for MouseEventInit with no network, filesystem, process, or code execution behavior.
- `lib/generated/idl/MutationCallback.js` (safe): No malicious patterns detected; the code is a standard WebIDL callback wrapper generated for the MutationObserver API.
- `lib/generated/idl/MutationObserver.js` (safe): This is standard jsdom-generated WebIDL binding code for MutationObserver with no malicious patterns, external calls, or dynamic code execution.
- `lib/generated/idl/MutationObserverInit.js` (safe): This is generated WebIDL type-conversion boilerplate for MutationObserverInit with no malicious patterns, network access, file system operations, or dynamic code execution.
- `lib/generated/idl/MutationRecord.js` (safe): No malicious patterns detected
- `lib/generated/idl/NamedNodeMap.js` (safe): No malicious patterns detected; this is standard generated WebIDL wrapper code for jsdom's NamedNodeMap interface.
- `lib/generated/idl/Navigator.js` (safe): This is a standard jsdom WebIDL wrapper for the Navigator interface with no malicious patterns, network calls, dynamic code execution, or install-time behavior.
- `lib/generated/idl/Node.js` (safe): This is a standard jsdom-generated WebIDL wrapper for the Node interface; all requires, method definitions, and prototypes are conventional, with no exfiltration, obfuscation, dynamic execution, shell/process spawning, or install-time hooks.
- `lib/generated/idl/NodeFilter.js` (safe): This is a standard Web IDL converter for NodeFilter with no malicious patterns, network calls, file access, or dynamic code execution.
- `lib/generated/idl/NodeIterator.js` (safe): This is a standard jsdom WebIDL-generated interface wrapper for NodeIterator with no malicious patterns, external calls, or suspicious behavior.
- `lib/generated/idl/NodeList.js` (safe): This is a generated WebIDL binding for the DOM NodeList interface (likely from jsdom) with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious network/file system access.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
