Togoder security

npm package security report

jsdom@30.1.1 security report

Risky patterns found that deserve a look.

Needs review Version 30.1.1 Files reviewed 653 Size 4.5 MB Scanned

Summary

Togoder Security scanned the npm package jsdom@30.1.1 on Oct 6, 2026. An AI review of 653 source files produced 10 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
10
medium
5
low

Findings 15

medium

Dynamic code execution

NPS-6C790DFAC53A

Uses new Function()/Function() to dynamically compile JavaScript from strings (event handler content attributes) and executes it via .call() on event dispatch. While this is intentional and spec-compliant for jsdom's event handler attribute emulation, dynamic code execution from string content is a notable risk pattern.

lib/jsdom/living/helpers/create-event-accessor.js:100
medium

Dynamic code execution

NPS-C9E222206C28

Constructs functions via document.defaultView.Function with generated with scope-chain wrapper code and invokes them. The body variable is derived from attribute content, effectively evaluating attacker-controllable strings.

lib/jsdom/living/helpers/create-event-accessor.js:130
medium

javascript_url_execution

NPS-4F57CD3AC65B

The loadFrame function explicitly handles URLs with the 'javascript:' scheme and calls evaluateJavaScriptURL(contentWindow, url). This executes arbitrary JavaScript supplied via a frame's src attribute (e.g. <iframe src="javascript:...">). While this mimics browser behavior and is constrained to the jsdom window context, it constitutes dynamic code execution from user-controlled input and is a known XSS-style vector if jsdom content is ever treated as trusted or if scripts are enabled.

lib/jsdom/living/nodes/HTMLFrameElement-impl.js:139
medium

dynamic_code_execution

NPS-104C3B9CF4FD

evaluateJavaScriptURL from ../window/navigation is invoked with a URL object derived from the frame's src attribute. Depending on its implementation, this can lead to eval/new Function-style execution of attacker-influenced script. This is the only dynamic code-execution sink in the file.

lib/jsdom/living/nodes/HTMLFrameElement-impl.js:139
medium

Network request with dynamic URL

NPS-015A638FB436

External scripts are fetched via resourceLoader.fetch() using a URL derived from the 'src' attribute. The URL is parsed and serialized, but the fetch itself can load arbitrary remote content that is then executed via vm.runInContext().

lib/jsdom/living/nodes/HTMLScriptElement-impl.js:119
medium

Dynamic code execution

NPS-D0CCCC12C6EF

The code uses vm.runInContext() to execute JavaScript from script elements, including external scripts fetched over the network. While this is expected behavior for a DOM implementation like jsdom, executing untrusted script content is inherently risky if the library is used to process untrusted HTML.

lib/jsdom/living/nodes/HTMLScriptElement-impl.js:263
medium

Potential security bypass via URL decoding

NPS-C68FB7994729

The function percent-decodes the javascript: URL payload and then UTF-8 decodes it before evaluation. Decoding before execution can bypass naive filters and allows encoded payloads (e.g. percent-encoded alert() or fetch() calls) to be executed, increasing the risk if callers rely on simple string checks on the URL.

lib/jsdom/living/window/navigation.js:10
medium

Dynamic code execution

NPS-2CBF439AAE9F

The evaluateJavaScriptURL function decodes a javascript: URL and runs it via window.eval(). While this is gated behind runScripts === 'dangerously' (an explicit opt-in that jsdom documents as unsafe), it is still a dynamic code execution primitive that can execute arbitrary script if untrusted input reaches a navigation call.

lib/jsdom/living/window/navigation.js:13
medium

Navigation sink for javascript: URLs

NPS-1DB47F680C34

navigate() dispatches javascript: scheme URLs to evaluateJavaScriptURL via a queued task. Any caller that can influence navigation (e.g. window.location assignment driven by user input) can trigger arbitrary script evaluation when runScripts is set to 'dangerously'.

lib/jsdom/living/window/navigation.js:57
medium

Prototype pollution potential

NPS-5FF62DEB3CD3

The 'define' and 'mixin' functions copy property descriptors from a source object to a target. The mixin function skips keys already in target, but define does not. If untrusted input is passed as the 'properties' or 'source' argument, an attacker could inject '__proto__' or 'constructor' descriptors, potentially leading to prototype pollution.

lib/jsdom/utils.js:11
low

Dynamic code execution

NPS-01616F545C67

The code uses globalObject.eval("(async function* () {})..." ) inside a try/catch to obtain the %AsyncIteratorPrototype% intrinsic. This is a functional necessity, not an obfuscated payload, and the evaluated string is a fixed constant with no external input.

lib/generated/idl/utils.js:51
low

malicious executable content in XML parsing

NPS-B878676B32D1

XML content types (text/xml, application/xml, application/xhtml+xml, image/svg+xml) are parsed with scripting disabled. While this prevents script execution, XML entities and other parser features could still be used for data exfiltration or denial-of-service. However, since scripting is disabled and the parser is controlled by jsdom, this is a standard, non-malicious implementation.

lib/jsdom/living/domparsing/DOMParser-impl.js
low

Use of with statement / scope chain manipulation

NPS-60790F545D2F

Wraps dynamically generated function bodies in nested with (arguments[0]) { ... } blocks, which alters lexical scope resolution and is a legacy pattern that can introduce scope confusion vulnerabilities.

lib/jsdom/living/helpers/create-event-accessor.js:120
low

Script execution gated by settings

NPS-6E6A98CF072C

Script execution requires document._defaultView._settings.runScripts === 'dangerously', which is a security control that limits execution unless explicitly enabled. This is a mitigating factor rather than a vulnerability.

lib/jsdom/living/nodes/HTMLScriptElement-impl.js:84
low

Dynamic module loading

NPS-8C8521161DA2

The module attempts to require('canvas') at import time. While this is a common optional dependency pattern, it loads an external native module dynamically. If the 'canvas' package is compromised or replaced, this could execute arbitrary native code. The try/catch prevents failure if not installed.

lib/jsdom/utils.js:32

Files reviewed

FileVerdictWhat the reviewer saw
lib/jsdom/living/helpers/create-event-accessor.js medium This is a legitimate jsdom helper implementing HTML event handler accessors; it uses new Function/eval-like dynamic compilation to emulate content attribute handlers, which is expected behavior but represents an inherent code-execution surface without malicious intent.
lib/jsdom/living/nodes/HTMLFrameElement-impl.js medium This jsdom HTMLFrameElement implementation is a legitimate part of the library and contains no exfiltration, credential harvesting, obfuscation, or process-spawning behavior; the only noteworthy concern is its intended support for javascript: URLs, which executes attacker-supplied script in the frame context.
lib/jsdom/living/nodes/HTMLScriptElement-impl.js medium This is a legitimate jsdom HTMLScriptElement implementation that executes scripts via vm.runInContext() and fetches external scripts, which is expected functionality but carries inherent risk when processing untrusted content.
lib/jsdom/living/window/navigation.js medium This is the jsdom navigation module; it contains no exfiltration, credential harvesting, install-time, or process-spawning behavior, but it does deliberately eval javascript: URLs and should be treated as dangerous only when runScripts is enabled on untrusted content.
lib/jsdom/utils.js medium No overtly malicious code detected, but the module has potential prototype pollution risks in its property-copying utilities and dynamically loads an optional native module at import time.
lib/api.js safe This is the legitimate jsdom library API code with no malicious patterns detected.
lib/generated/css-property-computed-value-resolvers.js safe No malicious patterns detected; the file only imports internal CSS property resolvers and exports a Map of computed value functions.
lib/generated/css-property-resolved-value-resolvers.js safe No malicious patterns detected
lib/generated/event-sets.js safe No malicious patterns detected
lib/generated/idl/AbortController.js safe This is a standard jsdom-generated WebIDL wrapper for AbortController with no malicious patterns, network access, file system manipulation, or dynamic code execution.
lib/generated/idl/AbortSignal.js safe This is standard WebIDL-generated binding code for AbortSignal from jsdom, containing no malicious patterns, network activity, credential harvesting, or dynamic code execution.
lib/generated/idl/AbstractRange.js safe No malicious patterns detected
lib/generated/idl/AddEventListenerOptions.js safe No malicious patterns detected; the file is a standard webidl-conversions-based converter for AddEventListenerOptions.
lib/generated/idl/AssignedNodesOptions.js safe This file is a standard WebIDL dictionary converter for AssignedNodesOptions with no malicious patterns, network calls, filesystem access, or dynamic code execution.
lib/generated/idl/Attr.js safe No malicious patterns detected; the file is a standard jsdom-generated Web IDL wrapper for the Attr interface with no network, file system, process execution, or obfuscated code.
lib/generated/idl/BarProp.js safe The code is a standard WebIDL interface implementation for BarProp with no malicious patterns detected.
lib/generated/idl/BeforeUnloadEvent.js safe This is standard jsdom-generated WebIDL wrapper code for the BeforeUnloadEvent interface with no malicious patterns detected.
lib/generated/idl/BinaryType.js safe No malicious patterns detected
lib/generated/idl/Blob.js safe No malicious patterns detected; this is a standard WebIDL-generated Blob interface binding for jsdom with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/BlobCallback.js safe No malicious patterns detected; the file is a standard WebIDL callback converter with no network, filesystem, or process activity.
lib/generated/idl/BlobEvent.js safe No malicious patterns detected; the file is a standard WebIDL-generated BlobEvent wrapper for jsdom with no network, filesystem, process, or dynamic-code-execution behavior.
lib/generated/idl/BlobEventInit.js safe This is a standard WebIDL conversion file for the BlobEventInit dictionary, containing no malicious patterns.
lib/generated/idl/BlobPropertyBag.js safe No malicious patterns detected; the file is a standard WebIDL-generated converter for BlobPropertyBag with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/CDATASection.js safe This is a standard WebIDL-generated binding for the CDATASection DOM interface from jsdom, with no malicious patterns, obfuscation, network activity, or process execution.
lib/generated/idl/CSS.js safe No malicious patterns detected; the file is a standard WebIDL binding for the CSS namespace with no network, filesystem, process, or dynamic execution behavior.
Show 628 more files
FileVerdictWhat the reviewer saw
lib/generated/idl/CSSConditionRule.js safe No malicious patterns detected; this is a standard jsdom WebIDL-generated interface wrapper for CSSConditionRule with no network, file system, process, or dynamic execution behavior.
lib/generated/idl/CSSContainerRule.js safe No malicious patterns detected; the file is a standard jsdom WebIDL interface implementation for CSSContainerRule with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/CSSCounterStyleRule.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for the CSSCounterStyleRule interface with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/CSSFontFaceRule.js safe No malicious patterns detected
lib/generated/idl/CSSGroupingRule.js safe No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for the CSSGroupingRule interface with no external network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/CSSImportRule.js safe No malicious patterns detected; the file is standard jsdom WebIDL-generated wrapper code for CSSImportRule with no network, filesystem, process spawning, or dynamic code execution concerns.
lib/generated/idl/CSSKeyframeRule.js safe No malicious patterns detected; this is standard jsdom WebIDL-generated wrapper code for CSSKeyframeRule.
lib/generated/idl/CSSKeyframesRule.js safe This is standard jsdom/webidl2js-generated DOM binding code for CSSKeyframesRule with no malicious patterns detected.
lib/generated/idl/CSSLayerBlockRule.js safe No malicious patterns detected; the file is standard jsdom-generated WebIDL wrapper code for CSSLayerBlockRule.
lib/generated/idl/CSSLayerStatementRule.js safe No malicious patterns detected; this is a standard WebIDL-generated wrapper module for the CSSLayerStatementRule interface in jsdom.
lib/generated/idl/CSSMediaRule.js safe No malicious patterns detected
lib/generated/idl/CSSNamespaceRule.js safe No malicious patterns detected; this is a standard generated WebIDL wrapper for CSSNamespaceRule from jsdom.
lib/generated/idl/CSSNestedDeclarations.js safe No malicious patterns detected
lib/generated/idl/CSSPageRule.js safe No malicious patterns detected
lib/generated/idl/CSSRule.js safe No malicious patterns detected; the file is standard jsdom-generated WebIDL wrapper code for CSSRule with no network, exec, or filesystem activity.
lib/generated/idl/CSSRuleList.js safe No malicious patterns detected
lib/generated/idl/CSSScopeRule.js safe No malicious patterns detected; this is standard WebIDL-generated boilerplate for the CSSScopeRule interface with no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/CSSStyleDeclaration.js safe This is a standard jsdom WebIDL-generated wrapper for CSSStyleDeclaration with no malicious patterns, network calls, filesystem access, process spawning, or dynamic code execution.
lib/generated/idl/CSSStyleRule.js safe This is a standard WebIDL-generated interface binding for CSSStyleRule from jsdom; no malicious patterns, dynamic code execution, network access, or filesystem manipulation are present.
lib/generated/idl/CSSStyleSheet.js safe This is standard jsdom-generated WebIDL wrapper code for CSSStyleSheet with no malicious patterns detected.
lib/generated/idl/CSSStyleSheetInit.js safe No malicious patterns detected
lib/generated/idl/CSSSupportsRule.js safe No malicious patterns detected
lib/generated/idl/CanPlayTypeResult.js safe No malicious patterns detected
lib/generated/idl/CharacterData.js safe No malicious patterns detected; the code is a standard Web IDL generated wrapper for the CharacterData interface in jsdom, with no data exfiltration, dynamic code execution, or other suspicious behaviors.
lib/generated/idl/CloseEvent.js safe No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for the CloseEvent interface with no network, filesystem, process, or dynamic code execution capabilities.
lib/generated/idl/CloseEventInit.js safe No malicious patterns detected
lib/generated/idl/Comment.js safe This is a standard WebIDL-generated interface file for the Comment DOM node with no malicious patterns detected.
lib/generated/idl/CompositionEvent.js safe No malicious patterns detected
lib/generated/idl/CompositionEventInit.js safe No malicious patterns detected; this is a standard webidl-conversions-based type converter for the CompositionEventInit WebIDL dictionary with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/Crypto.js safe This is a standard WebIDL-generated interface binding for the Crypto API (getRandomValues/randomUUID) with no malicious patterns, network activity, or suspicious code execution.
lib/generated/idl/CustomElementConstructor.js safe No malicious patterns detected; the code is a standard WebIDL custom element constructor wrapper that validates input and applies the provided function without any exfiltration, obfuscation, or system access.
lib/generated/idl/CustomElementRegistry.js safe No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for the CustomElementRegistry interface with no exfiltration, obfuscation, or process/network activity.
lib/generated/idl/CustomEvent.js safe This is a standard jsdom Web IDL-generated wrapper for CustomEvent with no malicious patterns, no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/CustomEventInit.js safe No malicious patterns detected; the file is a standard WebIDL type-conversion module for CustomEventInit with no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/DOMException.js safe No malicious patterns detected; this is standard jsdom WebIDL wrapper code for the DOMException interface with no network, filesystem, process, or dynamic code execution activity.
lib/generated/idl/DOMImplementation.js safe This is a standard Web IDL-generated wrapper for the DOMImplementation interface from the jsdom project, containing no malicious patterns.
lib/generated/idl/DOMParser.js safe No malicious patterns detected; this is a standard WebIDL-generated DOMParser binding with no network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/DOMRect.js safe No malicious patterns detected; this is standard generated DOM binding code for jsdom's DOMRect interface.
lib/generated/idl/DOMRectInit.js safe No malicious patterns detected; the code is a standard WebIDL dictionary converter for DOMRectInit with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/DOMRectReadOnly.js safe No malicious patterns detected; this is standard WebIDL-generated DOMRectReadOnly binding code for jsdom with only internal module requires and no network, filesystem, process, or dynamic code execution.
lib/generated/idl/DOMStringMap.js safe No malicious patterns detected
lib/generated/idl/DOMTokenList.js safe No malicious patterns detected; the file is standard jsdom WebIDL-generated wrapper code for DOMTokenList with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/DeviceMotionEvent.js safe No malicious patterns detected; the file is a standard WebIDL-generated interface wrapper for DeviceMotionEvent with no data exfiltration, environment harvesting, dynamic code execution, or other suspicious behavior.
lib/generated/idl/DeviceMotionEventAcceleration.js safe This is a standard jsdom-generated WebIDL wrapper for DeviceMotionEventAcceleration; no malicious patterns detected.
lib/generated/idl/DeviceMotionEventAccelerationInit.js safe No malicious patterns detected; the file is a standard WebIDL-generated converter for DeviceMotionEventAccelerationInit with only type-checking and value conversion logic.
lib/generated/idl/DeviceMotionEventInit.js safe No malicious patterns detected
lib/generated/idl/DeviceMotionEventRotationRate.js safe No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for DeviceMotionEventRotationRate.
lib/generated/idl/DeviceMotionEventRotationRateInit.js safe No malicious patterns detected; the file contains standard WebIDL type conversion logic for DeviceMotionEventRotationRateInit with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/DeviceOrientationEvent.js safe No malicious patterns detected in the DeviceOrientationEvent interface wrapper; the code appears to be a standard generated WebIDL binding for jsdom.
lib/generated/idl/DeviceOrientationEventInit.js safe No malicious patterns detected
lib/generated/idl/DocumentFragment.js safe This is a standard generated WebIDL wrapper for the DocumentFragment interface in jsdom, containing no malicious patterns, network activity, or dangerous code execution.
lib/generated/idl/DocumentReadyState.js safe No malicious patterns detected
lib/generated/idl/DocumentType.js safe This is a standard jsdom-generated WebIDL wrapper for DocumentType with no malicious patterns, network calls, or dynamic code execution.
lib/generated/idl/ElementCreationOptions.js safe No malicious patterns detected; the file is a standard WebIDL converter for ElementCreationOptions with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/ElementDefinitionOptions.js safe No malicious patterns detected in this WebIDL conversion helper; it only performs standard type coercion using webidl-conversions.
lib/generated/idl/ElementInternals.js safe This is standard jsdom-generated WebIDL wrapper code for the ElementInternals interface with no malicious patterns detected.
lib/generated/idl/EndingType.js safe No malicious patterns detected
lib/generated/idl/ErrorEvent.js safe This is a standard auto-generated WebIDL binding file for the ErrorEvent interface in jsdom; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, network requests, process spawning, or dynamic code execution were detected.
lib/generated/idl/ErrorEventInit.js safe This is a standard WebIDL type conversion module for ErrorEventInit with no malicious patterns; it only performs data validation and normalization.
lib/generated/idl/Event.js safe No malicious patterns detected; the file is standard generated WebIDL boilerplate for a DOM Event interface with no obfuscation, network, filesystem, process, credential, or dynamic-code risks.
lib/generated/idl/EventHandlerNonNull.js safe No malicious patterns detected; the code is a standard WebIDL callback converter with no network, filesystem, process, or dynamic code execution activity.
lib/generated/idl/EventInit.js safe No malicious patterns detected; the file is a standard WebIDL dictionary converter for EventInit that performs only local, type-checked property conversion.
lib/generated/idl/EventListener.js safe No malicious patterns detected; the code is a standard WebIDL EventListener converter with no exfiltration, credential harvesting, obfuscation, or network/process activity.
lib/generated/idl/EventListenerOptions.js safe No malicious patterns detected
lib/generated/idl/EventModifierInit.js safe No malicious patterns detected; the file is a standard WebIDL conversion utility for event modifier initialization with no network, filesystem, or code execution activity.
lib/generated/idl/EventTarget.js safe This is standard generated WebIDL binding code for the EventTarget interface with no malicious patterns, network calls, file system access, or dynamic code execution.
lib/generated/idl/External.js safe This file is a standard jsdom-generated WebIDL binding for the External interface, containing only normal interface plumbing and no malicious patterns.
lib/generated/idl/File.js safe This is standard WebIDL-generated binding code for the File interface from jsdom; no malicious patterns detected.
lib/generated/idl/FileList.js safe This is standard jsdom-generated WebIDL binding code for the FileList interface with no malicious patterns, network activity, filesystem access, or dynamic code execution.
lib/generated/idl/FilePropertyBag.js safe No malicious patterns detected; the code is a standard WebIDL type conversion helper with no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/FileReader.js safe No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for FileReader with no network, filesystem, process, or dynamic code execution activity.
lib/generated/idl/FocusEvent.js safe This is a standard jsdom-generated WebIDL wrapper for FocusEvent with no malicious patterns, network activity, or dynamic code execution detected.
lib/generated/idl/FocusEventInit.js safe No malicious patterns detected
lib/generated/idl/FormData.js safe No malicious patterns detected; this is standard webidl2js-generated FormData wrapper code with no network, filesystem, process, or dynamic execution concerns.
lib/generated/idl/Function.js safe No malicious patterns detected; the code is a standard WebIDL function converter wrapper with no exfiltration, obfuscation, or dynamic execution.
lib/generated/idl/GetRootNodeOptions.js safe No malicious patterns detected; the file contains standard WebIDL dictionary conversion logic with no network, filesystem, process, or dynamic code execution activity.
lib/generated/idl/HTMLAnchorElement.js safe No malicious patterns detected in this auto-generated WebIDL wrapper for HTMLAnchorElement; it contains only standard DOM property accessors and reflection helpers.
lib/generated/idl/HTMLAreaElement.js safe The code is a standard WebIDL-generated wrapper for the HTMLAreaElement interface from jsdom; no malicious patterns, exfiltration, obfuscation, or installation hooks were detected.
lib/generated/idl/HTMLAudioElement.js safe This is a standard jsdom WebIDL wrapper for HTMLAudioElement with no malicious patterns detected.
lib/generated/idl/HTMLBRElement.js safe This is a standard jsdom WebIDL wrapper for HTMLBRElement with no malicious patterns detected.
lib/generated/idl/HTMLBaseElement.js safe No malicious patterns detected; the code is standard jsdom-generated WebIDL wrapper code for HTMLBaseElement with no data exfiltration, process spawning, or dynamic execution.
lib/generated/idl/HTMLBodyElement.js safe This is standard jsdom-generated WebIDL bindings for HTMLBodyElement, containing only DOM property accessors, event handler registration, and constructor logic with no malicious patterns.
lib/generated/idl/HTMLButtonElement.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLButtonElement with no exfiltration, obfuscation, process spawning, or dynamic code execution.
lib/generated/idl/HTMLCanvasElement.js safe This is a standard webidl-conversions generated wrapper for HTMLCanvasElement in the jsdom library, containing no malicious patterns, network activity, dynamic code execution, or process spawning.
lib/generated/idl/HTMLCollection.js safe This is standard WebIDL-generated binding code for the HTMLCollection interface with no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or backdoors.
lib/generated/idl/HTMLDListElement.js safe No malicious patterns detected; the file is standard jsdom-generated WebIDL binding code for HTMLDListElement with no network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/HTMLDataElement.js safe No malicious patterns detected; the file is a standard jsdom WebIDL-generated wrapper for HTMLDataElement with no exfiltration, dynamic execution, process spawning, or install-time behavior.
lib/generated/idl/HTMLDataListElement.js safe This is a standard jsdom IDL wrapper for HTMLDataListElement with no malicious patterns, network access, dynamic code execution, or credential harvesting.
lib/generated/idl/HTMLDetailsElement.js safe No malicious patterns detected; the file contains standard jsdom-generated WebIDL bindings for HTMLDetailsElement with no network, FS, process, or dynamic execution behavior.
lib/generated/idl/HTMLDialogElement.js safe No malicious patterns detected
lib/generated/idl/HTMLDirectoryElement.js safe No malicious patterns detected; the file is a standard generated WebIDL wrapper for the obsolete HTMLDirectoryElement interface in jsdom with no network, filesystem, process, or dynamic code execution activity.
lib/generated/idl/HTMLDivElement.js safe No malicious patterns detected; this is a standard jsdom-generated IDL wrapper for HTMLDivElement with no network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/HTMLEmbedElement.js safe No malicious patterns detected; this is a standard jsdom generated WebIDL wrapper for HTMLEmbedElement with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/HTMLFieldSetElement.js safe No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for the HTMLFieldSetElement interface.
lib/generated/idl/HTMLFontElement.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLFontElement with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/HTMLFormControlsCollection.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLFormControlsCollection with no malicious patterns, network access, environment harvesting, or dynamic code execution.
lib/generated/idl/HTMLFormElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLFormElement with no malicious patterns, network activity, filesystem access, or code execution.
lib/generated/idl/HTMLFrameElement.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLFrameElement with no network, filesystem, or dynamic code execution behavior.
lib/generated/idl/HTMLFrameSetElement.js safe This is a standard jsdom-generated WebIDL wrapper for the HTMLFrameSetElement interface with no malicious patterns, network calls, dynamic code execution, or install-time behavior.
lib/generated/idl/HTMLHRElement.js safe No malicious patterns detected
lib/generated/idl/HTMLHeadElement.js safe This is a standard generated WebIDL wrapper for HTMLHeadElement in jsdom with no malicious patterns, external calls, or suspicious behavior.
lib/generated/idl/HTMLHeadingElement.js safe No malicious patterns detected in this jsdom-generated interface file; it only implements standard DOM HTMLHeadingElement bindings.
lib/generated/idl/HTMLHtmlElement.js safe No malicious patterns detected; the code is a standard jsdom-generated WebIDL wrapper for HTMLHtmlElement with no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/HTMLIFrameElement.js safe This is a standard generated WebIDL wrapper for HTMLIFrameElement from jsdom; no malicious patterns, exfiltration, dynamic code execution, or install-time behavior were detected.
lib/generated/idl/HTMLImageElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLImageElement with no malicious patterns, network activity, process spawning, or dynamic code execution.
lib/generated/idl/HTMLInputElement.js safe No malicious patterns detected
lib/generated/idl/HTMLLIElement.js safe No malicious patterns detected
lib/generated/idl/HTMLLabelElement.js safe No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for HTMLLabelElement with no network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/HTMLLegendElement.js safe This is a standard jsdom-generated WebIDL wrapper for the HTMLLegendElement interface with no malicious patterns detected.
lib/generated/idl/HTMLLinkElement.js safe This is a standard jsdom-generated WebIDL binding file for HTMLLinkElement with no malicious patterns, network activity, credential access, or dynamic code execution.
lib/generated/idl/HTMLMapElement.js safe No malicious patterns detected
lib/generated/idl/HTMLMarqueeElement.js safe No malicious patterns detected
lib/generated/idl/HTMLMediaElement.js safe No malicious patterns detected
lib/generated/idl/HTMLMenuElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLMenuElement with no malicious patterns, network activity, dynamic code execution, or filesystem access.
lib/generated/idl/HTMLMetaElement.js safe This file is a standard jsdom-generated WebIDL wrapper for HTMLMetaElement with no malicious patterns, network access, process spawning, or code execution beyond normal property accessors.
lib/generated/idl/HTMLMeterElement.js safe No malicious patterns detected; this is standard jsdom WebIDL wrapper code for HTMLMeterElement with no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/HTMLModElement.js safe This is standard jsdom-generated WebIDL wrapper code for HTMLModElement with no malicious patterns, network calls, process spawning, or credential access.
lib/generated/idl/HTMLOListElement.js safe This is a legitimate jsdom WebIDL-generated wrapper for HTMLOListElement with no malicious patterns detected.
lib/generated/idl/HTMLObjectElement.js safe No malicious patterns detected; this is a standard auto-generated jsdom WebIDL wrapper for HTMLObjectElement with only expected DOM property reflection and validation logic.
lib/generated/idl/HTMLOptGroupElement.js safe No malicious patterns detected; this is standard jsdom HTMLOptGroupElement IDL wrapper code with no network, filesystem, process, or dynamic execution concerns.
lib/generated/idl/HTMLOptionElement.js safe No malicious patterns detected; the file is a standard jsdom-generated Web IDL wrapper for HTMLOptionElement with no external network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/HTMLOptionsCollection.js safe No malicious patterns detected; the file is a standard jsdom WebIDL-generated wrapper for HTMLOptionsCollection with no exfiltration, obfuscation, process spawning, or unexpected side effects.
lib/generated/idl/HTMLOutputElement.js safe This file is a standard jsdom WebIDL-generated wrapper for HTMLOutputElement with no malicious patterns, network requests, dynamic code execution, or file system manipulation.
lib/generated/idl/HTMLParagraphElement.js safe This file is a standard jsdom WebIDL-generated wrapper for HTMLParagraphElement with no malicious patterns, network activity, filesystem access, or dynamic code execution.
lib/generated/idl/HTMLParamElement.js safe This is a standard jsdom-generated WebIDL wrapper for the HTMLParamElement interface with no malicious patterns detected.
lib/generated/idl/HTMLPictureElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLPictureElement with only benign DOM-related operations and local module imports.
lib/generated/idl/HTMLPreElement.js safe This is a standard generated WebIDL wrapper for the HTMLPreElement interface in jsdom, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
lib/generated/idl/HTMLProgressElement.js safe No malicious patterns detected; the code is a standard WebIDL-generated wrapper for HTMLProgressElement with no network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/HTMLQuoteElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLQuoteElement with no malicious patterns, network activity, credential access, or dynamic code execution.
lib/generated/idl/HTMLScriptElement.js safe This is a standard generated WebIDL binding for HTMLScriptElement in jsdom, containing only DOM property accessors and no malicious patterns.
lib/generated/idl/HTMLSelectElement.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLSelectElement.
lib/generated/idl/HTMLSlotElement.js safe This file is a standard jsdom generated WebIDL wrapper for HTMLSlotElement with no malicious patterns, network activity, file system access, or dynamic code execution.
lib/generated/idl/HTMLSourceElement.js safe This file is a standard jsdom-generated WebIDL wrapper for HTMLSourceElement with no malicious patterns, network calls, credential access, or dynamic code execution.
lib/generated/idl/HTMLSpanElement.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLSpanElement with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/HTMLStyleElement.js safe This is a standard jsdom DOM interface wrapper for HTMLStyleElement with no network, filesystem, process, or dynamic execution patterns.
lib/generated/idl/HTMLTableCaptionElement.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for HTMLTableCaptionElement with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/HTMLTableCellElement.js safe No malicious patterns detected; this is a standard generated WebIDL binding for HTMLTableCellElement from jsdom.
lib/generated/idl/HTMLTableColElement.js safe No malicious patterns detected
lib/generated/idl/HTMLTableElement.js safe No malicious patterns detected; the file contains standard jsdom-generated wrapper code for HTMLTableElement with no data exfiltration, dynamic code execution, or process spawning.
lib/generated/idl/HTMLTableRowElement.js safe No malicious patterns detected; the file is a standard generated WebIDL implementation for HTMLTableRowElement in jsdom.
lib/generated/idl/HTMLTableSectionElement.js safe The code is a standard jsdom WebIDL-generated wrapper for HTMLTableSectionElement with no malicious patterns, network calls, dynamic code execution, or filesystem access.
lib/generated/idl/HTMLTemplateElement.js safe This file is a standard jsdom WebIDL-generated wrapper for HTMLTemplateElement with no malicious patterns: it only performs type conversions, wrapper registration, and constructor installation without network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/HTMLTextAreaElement.js safe No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for HTMLTextAreaElement with no network, filesystem, process, or dynamic code execution activity.
lib/generated/idl/HTMLTimeElement.js safe This file is a standard jsdom-generated WebIDL wrapper for the HTMLTimeElement interface with no malicious patterns, no network or filesystem access, and no dynamic code execution.
lib/generated/idl/HTMLTitleElement.js safe No malicious patterns detected; this is standard jsdom-generated WebIDL wrapper code for HTMLTitleElement with no exfiltration, obfuscation, or dynamic execution.
lib/generated/idl/HTMLTrackElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLTrackElement with no malicious patterns, network calls, or suspicious code execution.
lib/generated/idl/HTMLUListElement.js safe No malicious patterns detected; the code is a standard jsdom IDL-generated wrapper for HTMLUListElement with no exfiltration, obfuscation, or process/file system abuse.
lib/generated/idl/HTMLUnknownElement.js safe This is a standard generated WebIDL wrapper for the HTMLUnknownElement interface in jsdom, with no malicious patterns, network activity, filesystem access, or dynamic code execution.
lib/generated/idl/HTMLVideoElement.js safe This is a standard jsdom-generated WebIDL wrapper for HTMLVideoElement with no malicious patterns, external network calls, credential harvesting, dynamic code execution, or other security concerns.
lib/generated/idl/HashChangeEvent.js safe No malicious patterns detected
lib/generated/idl/HashChangeEventInit.js safe This is a standard WebIDL dictionary converter for HashChangeEventInit with no malicious patterns, network calls, filesystem access, or code execution.
lib/generated/idl/Headers.js safe This is standard auto-generated WebIDL bindings for the Headers interface with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
lib/generated/idl/History.js safe No malicious patterns detected; this is a standard jsdom-generated WebIDL wrapper for the History interface with no exfiltration, code execution, or filesystem/network access.
lib/generated/idl/InputEvent.js safe This file is a standard auto-generated WebIDL wrapper for the InputEvent interface from jsdom, containing no malicious patterns, network calls, dynamic execution, or file system access.
lib/generated/idl/InputEventInit.js safe The code is a standard WebIDL type conversion utility with no malicious patterns, network access, file system operations, or dynamic code execution.
lib/generated/idl/KeyboardEvent.js safe No malicious patterns detected; the code is a standard jsdom-generated WebIDL binding for KeyboardEvent.
lib/generated/idl/KeyboardEventInit.js safe The file is a standard WebIDL dictionary converter for KeyboardEventInit with only safe type conversions and default value assignments; no malicious patterns detected.
lib/generated/idl/Location.js safe This is standard jsdom-generated WebIDL binding code for the DOM Location interface with no malicious patterns, network activity, credential access, or dynamic code execution.
lib/generated/idl/MediaList.js safe No malicious patterns detected; this is standard jsdom WebIDL-generated wrapper code for the MediaList interface.
lib/generated/idl/MessageEvent.js safe No malicious patterns detected
lib/generated/idl/MessageEventInit.js safe No malicious patterns detected
lib/generated/idl/MimeType.js safe This is a standard generated WebIDL wrapper for the MimeType interface (likely from jsdom), containing no network, filesystem, process, credential, or dynamic code execution patterns.
lib/generated/idl/MimeTypeArray.js safe No malicious patterns detected; this is a standard WebIDL-generated binding file for the MimeTypeArray interface with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/MouseEvent.js safe No malicious patterns detected; the file is a standard jsdom-generated WebIDL wrapper for MouseEvent with only local module imports and no network, filesystem, process, or dynamic code execution concerns.
lib/generated/idl/MouseEventInit.js safe No malicious patterns detected; the code is standard WebIDL dictionary conversion logic for MouseEventInit with no network, filesystem, process, or code execution behavior.
lib/generated/idl/MutationCallback.js safe No malicious patterns detected; the code is a standard WebIDL callback wrapper generated for the MutationObserver API.
lib/generated/idl/MutationObserver.js safe This is standard jsdom-generated WebIDL binding code for MutationObserver with no malicious patterns, external calls, or dynamic code execution.
lib/generated/idl/MutationObserverInit.js safe This is generated WebIDL type-conversion boilerplate for MutationObserverInit with no malicious patterns, network access, file system operations, or dynamic code execution.
lib/generated/idl/MutationRecord.js safe No malicious patterns detected
lib/generated/idl/NamedNodeMap.js safe No malicious patterns detected; this is standard generated WebIDL wrapper code for jsdom's NamedNodeMap interface.
lib/generated/idl/Navigator.js safe This is a standard jsdom WebIDL wrapper for the Navigator interface with no malicious patterns, network calls, dynamic code execution, or install-time behavior.
lib/generated/idl/Node.js safe This is a standard jsdom-generated WebIDL wrapper for the Node interface; all requires, method definitions, and prototypes are conventional, with no exfiltration, obfuscation, dynamic execution, shell/process spawning, or install-time hooks.
lib/generated/idl/NodeFilter.js safe This is a standard Web IDL converter for NodeFilter with no malicious patterns, network calls, file access, or dynamic code execution.
lib/generated/idl/NodeIterator.js safe This is a standard jsdom WebIDL-generated interface wrapper for NodeIterator with no malicious patterns, external calls, or suspicious behavior.
lib/generated/idl/NodeList.js safe This is a generated WebIDL binding for the DOM NodeList interface (likely from jsdom) with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious network/file system access.
lib/generated/idl/OnBeforeUnloadEventHandlerNonNull.js safe No malicious patterns detected
lib/generated/idl/OnErrorEventHandlerNonNull.js safe No malicious patterns detected; the code is a standard WebIDL callback wrapper generated by jsdom for handling event handlers.
lib/generated/idl/PageTransitionEvent.js safe This is a standard jsdom-generated WebIDL wrapper for PageTransitionEvent with no malicious patterns detected.
lib/generated/idl/PageTransitionEventInit.js safe No malicious patterns detected; the file is a standard WebIDL-generated converter for PageTransitionEventInit with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/Performance.js safe No malicious patterns detected; this is standard WebIDL-generated boilerplate for the Performance interface in jsdom.
lib/generated/idl/Plugin.js safe This is standard jsdom/WebIDL-generated wrapper code for the Plugin interface with no malicious patterns, network requests, code execution, or file system access beyond a relative require.
lib/generated/idl/PluginArray.js safe No malicious patterns detected; the code is standard jsdom WebIDL-generated bindings for PluginArray with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/PointerEvent.js safe No malicious patterns detected
lib/generated/idl/PointerEventInit.js safe This is an auto-generated WebIDL dictionary converter for PointerEventInit that only performs standard type conversions and object property validation with no malicious patterns.
lib/generated/idl/PopStateEvent.js safe This is a standard jsdom-generated WebIDL wrapper for PopStateEvent with no malicious patterns detected.
lib/generated/idl/PopStateEventInit.js safe This is a standard WebIDL-generated converter for PopStateEventInit that only performs type conversion and validation with no malicious patterns.
lib/generated/idl/ProcessingInstruction.js safe This is a standard WebIDL-generated wrapper for the ProcessingInstruction DOM interface from jsdom; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, network activity, filesystem manipulation, or process spawning were found.
lib/generated/idl/ProgressEvent.js safe No malicious patterns detected; the file is standard jsdom-generated boilerplate implementing the ProgressEvent Web API interface.
lib/generated/idl/ProgressEventInit.js safe No malicious patterns detected
lib/generated/idl/PromiseRejectionEvent.js safe This is a standard jsdom-generated WebIDL wrapper for PromiseRejectionEvent with no malicious patterns, network calls, process spawning, or dynamic code execution.
lib/generated/idl/PromiseRejectionEventInit.js safe No malicious patterns detected; the code is a standard WebIDL converter for PromiseRejectionEventInit.
lib/generated/idl/QuotaExceededError.js safe No malicious patterns detected; this is standard jsdom WebIDL-generated boilerplate for the QuotaExceededError interface.
lib/generated/idl/QuotaExceededErrorOptions.js safe No malicious patterns detected; the file is a standard WebIDL dictionary converter for QuotaExceededErrorOptions with only type conversion logic.
lib/generated/idl/RadioNodeList.js safe No malicious patterns detected
lib/generated/idl/Range.js safe This is a standard jsdom-generated WebIDL wrapper for the DOM Range interface; no malicious patterns, network calls, credential harvesting, obfuscation, or process execution were detected.
lib/generated/idl/SVGAnimatedPreserveAspectRatio.js safe Code is a standard jsdom WebIDL-generated interface implementation for SVGAnimatedPreserveAspectRatio with no malicious patterns detected.
lib/generated/idl/SVGAnimatedRect.js safe This is a standard jsdom-generated WebIDL wrapper for SVGAnimatedRect with no malicious patterns, network access, dynamic code execution, or file system manipulation.
lib/generated/idl/SVGAnimatedString.js safe No malicious patterns detected
lib/generated/idl/SVGBoundingBoxOptions.js safe No malicious patterns detected; the code is a standard WebIDL-generated converter for SVGBoundingBoxOptions with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/SVGDefsElement.js safe No malicious patterns detected; this is standard WebIDL wrapper/interface code for jsdom's SVGDefsElement with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/SVGDescElement.js safe No malicious patterns detected in the generated WebIDL glue code for SVGDescElement.js.
lib/generated/idl/SVGElement.js safe No malicious patterns detected; this is a standard jsdom-generated DOM interface wrapper for SVGElement with only expected event handler and property definitions.
lib/generated/idl/SVGGElement.js safe No malicious patterns detected
lib/generated/idl/SVGGraphicsElement.js safe This is a standard jsdom-generated WebIDL wrapper for the SVGGraphicsElement interface with no malicious patterns, network activity, file system access, or dynamic code execution.
lib/generated/idl/SVGMetadataElement.js safe No malicious patterns detected; the file is a standard jsdom WebIDL wrapper for SVGMetadataElement with no network, filesystem, process, or code-execution activity.
lib/generated/idl/SVGNumber.js safe No malicious patterns detected; this is standard jsdom WebIDL-generated interface code with no I/O, network, process, or dynamic execution behavior.
lib/generated/idl/SVGPreserveAspectRatio.js safe No malicious patterns detected
lib/generated/idl/SVGRect.js safe No malicious patterns detected; the code is a standard WebIDL-generated SVG DOM interface implementation for jsdom.
lib/generated/idl/SVGSVGElement.js safe No malicious patterns detected; this is a standard WebIDL-generated interface wrapper for SVGSVGElement with no obfuscation, network, filesystem, or process manipulation.
lib/generated/idl/SVGStringList.js safe No malicious patterns detected; this is a standard generated WebIDL wrapper for the SVGStringList interface with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/SVGSwitchElement.js safe No malicious patterns detected
lib/generated/idl/SVGSymbolElement.js safe This is a standard jsdom WebIDL wrapper file for the SVGSymbolElement interface; it contains no malicious patterns, network access, credential harvesting, or dynamic code execution.
lib/generated/idl/SVGTitleElement.js safe No malicious patterns detected
lib/generated/idl/Screen.js safe No malicious patterns detected; this is standard jsdom-generated WebIDL binding code for the Screen interface.
lib/generated/idl/ScrollBehavior.js safe No malicious patterns detected
lib/generated/idl/ScrollIntoViewOptions.js safe No malicious patterns detected
lib/generated/idl/ScrollLogicalPosition.js safe No malicious patterns detected
lib/generated/idl/ScrollOptions.js safe This is a standard WebIDL converter for ScrollOptions with no malicious patterns, network activity, filesystem access, or code execution.
lib/generated/idl/ScrollRestoration.js safe No malicious patterns detected
lib/generated/idl/Selection.js safe No malicious patterns detected; the file is a standard jsdom autogenerated WebIDL wrapper for the Selection interface with no network, filesystem, process, or obfuscated code.
lib/generated/idl/SelectionMode.js safe No malicious patterns detected; the code is a simple WebIDL enumeration converter with no external I/O, dynamic execution, or system access.
lib/generated/idl/ShadowRoot.js safe The code is a standard auto-generated WebIDL wrapper for the ShadowRoot interface in jsdom, with no malicious patterns, network calls, file system access, process spawning, or dynamic code execution.
lib/generated/idl/ShadowRootInit.js safe No malicious patterns detected; the code is a standard WebIDL converter for ShadowRootInit with no network, file, process, or dynamic execution behavior.
lib/generated/idl/ShadowRootMode.js safe No malicious patterns detected; the code is a simple enumeration validator with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/StaticRange.js safe No malicious patterns detected
lib/generated/idl/StaticRangeInit.js safe No malicious patterns detected
lib/generated/idl/Storage.js safe No malicious patterns detected; the file contains standard WebIDL-generated bindings for the Storage interface with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/StorageEvent.js safe No malicious patterns detected
lib/generated/idl/StorageEventInit.js safe This is a standard WebIDL-generated converter for StorageEventInit that only performs type conversions and does not contain any malicious patterns.
lib/generated/idl/StyleSheet.js safe This is a standard generated WebIDL wrapper for the StyleSheet interface, containing no malicious patterns, obfuscation, network activity, or suspicious behavior.
lib/generated/idl/StyleSheetList.js safe No malicious patterns detected; this is standard jsdom webidl-generated wrapper code for StyleSheetList with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/SubmitEvent.js safe This is auto-generated WebIDL binding code for the SubmitEvent interface with no malicious patterns; it performs standard type conversions, wrapper creation, and prototype installation using jsdom internal modules.
lib/generated/idl/SubmitEventInit.js safe No malicious patterns detected; this is a standard WebIDL dictionary conversion module for a SubmitEventInit with no network, filesystem, process, or dynamic execution activity.
lib/generated/idl/SupportedType.js safe No malicious patterns detected
lib/generated/idl/Text.js safe This is a standard jsdom-generated WebIDL wrapper for the DOM Text interface, containing no malicious patterns, network access, credential harvesting, or dynamic code execution.
lib/generated/idl/TextDecodeOptions.js safe This is a standard WebIDL-generated type conversion helper for TextDecodeOptions with no malicious patterns, network calls, or file system access.
lib/generated/idl/TextDecoder.js safe No malicious patterns detected; this is standard generated WebIDL wrapper code for jsdom's TextDecoder implementation.
lib/generated/idl/TextDecoderOptions.js safe This is standard WebIDL dictionary conversion code generated by the jsdom/webidl2js project; it contains no network, filesystem, process, or dynamic execution patterns and is benign.
lib/generated/idl/TextEncoder.js safe No malicious patterns detected; the file is a standard WebIDL-generated TextEncoder wrapper with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
lib/generated/idl/TextEncoderEncodeIntoResult.js safe No malicious patterns detected; the file is a standard webidl-conversions helper for validating TextEncoderEncodeIntoResult dictionaries.
lib/generated/idl/TextTrackKind.js safe No malicious patterns detected
lib/generated/idl/TouchEvent.js safe No malicious patterns detected; the code is a standard WebIDL-generated interface implementation for TouchEvent with no network, filesystem, process, or obfuscated behavior.
lib/generated/idl/TouchEventInit.js safe No malicious patterns detected; the file is a standard WebIDL conversion module for TouchEventInit with no exfiltration, dynamic execution, or network activity.
lib/generated/idl/TransitionEvent.js safe This is a standard generated WebIDL wrapper for the TransitionEvent interface with no malicious patterns, network activity, command execution, or filesystem manipulation.
lib/generated/idl/TransitionEventInit.js safe No malicious patterns detected; this is standard WebIDL type conversion code for TransitionEventInit.
lib/generated/idl/TreeWalker.js safe No malicious patterns detected; the file is standard generated WebIDL boilerplate for the TreeWalker interface with no network, filesystem, process, eval, or credential-access behavior.
lib/generated/idl/UIEvent.js safe This is a standard jsdom-generated WebIDL wrapper for the UIEvent interface with no malicious patterns detected.
lib/generated/idl/UIEventInit.js safe No malicious patterns detected
lib/generated/idl/ValidityState.js safe No malicious patterns detected
lib/generated/idl/VisibilityState.js safe No malicious patterns detected
lib/generated/idl/VoidFunction.js safe No malicious patterns detected
lib/generated/idl/WebSocket.js safe No malicious patterns detected
lib/generated/idl/WheelEvent.js safe This is standard jsdom WebIDL-generated code for the WheelEvent interface, with no malicious patterns such as exfiltration, credential harvesting, dynamic execution, or process spawning.
lib/generated/idl/WheelEventInit.js safe This is a standard WebIDL conversion utility for WheelEventInit with no malicious patterns, network calls, file access, or dynamic code execution.
lib/generated/idl/XMLDocument.js safe No malicious patterns detected; the code is a standard WebIDL wrapper for jsdom's XMLDocument with no network, filesystem, process, or dynamic execution behavior.
lib/generated/idl/XMLHttpRequest.js safe This is a standard WebIDL-generated binding file for the XMLHttpRequest interface from the jsdom library, containing only type conversions, argument validation, and property accessors with no malicious patterns.
lib/generated/idl/XMLHttpRequestEventTarget.js safe No malicious patterns detected; the file is a standard WebIDL-generated interface wrapper for XMLHttpRequestEventTarget used by jsdom.
lib/generated/idl/XMLHttpRequestResponseType.js safe The code is a benign WebIDL enum converter with no malicious patterns.
lib/generated/idl/XMLHttpRequestUpload.js safe No malicious patterns detected; this is a standard WebIDL binding file for the XMLHttpRequestUpload interface from the jsdom project.
lib/generated/idl/XMLSerializer.js safe No malicious patterns detected; the code is a standard WebIDL-generated wrapper for XMLSerializer with no network, filesystem, process, or dynamic code execution behavior.
lib/generated/idl/utils.js safe No malicious patterns detected; the only dynamic evaluation is a fixed literal needed to retrieve the AsyncIterator prototype, and there is no network, filesystem, credential, process, or exfiltration behavior.
lib/jsdom/browser/Window.js safe This is a legitimate part of jsdom's Window implementation that creates DOM windows, handles events, timers, storage, and messaging; no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or backdoors were detected.
lib/jsdom/browser/not-implemented.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/browser/parser/html.js safe No malicious patterns detected; the file is a legitimate jsdom/parse5 HTML parser adapter with no network, filesystem, process, or dynamic code execution concerns.
lib/jsdom/browser/parser/index.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/browser/parser/xml.js safe No malicious patterns detected
lib/jsdom/browser/resources/async-resource-queue.js safe No malicious patterns detected; the code is a benign async resource queue implementation from jsdom with no network, filesystem, process execution, or credential access.
lib/jsdom/browser/resources/decompress-interceptor.js safe No malicious patterns detected; the code is a legitimate HTTP response decompression interceptor adapted from undici with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
lib/jsdom/browser/resources/jsdom-dispatcher.js safe This is a legitimate jsdom network dispatcher implementation with no malicious patterns; all imports and filesystem/network operations are expected for the library's documented resource-loading purpose.
lib/jsdom/browser/resources/per-document-resource-loader.js safe The analyzed file is a standard jsdom resource loader that fetches subresources via the configured dispatcher with no evidence of exfiltration, environment harvesting, obfuscation, process spawning, or other malicious patterns.
lib/jsdom/browser/resources/request-interceptor.js safe No malicious patterns detected; the code is a legitimate JSDOM request interceptor for synthetic responses and cancellation handling.
lib/jsdom/browser/resources/request-manager.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/browser/resources/resource-queue.js safe No malicious patterns detected; the code implements a resource download queue with standard promise and linked-list logic.
lib/jsdom/browser/resources/stream-handler.js safe No malicious patterns detected; the file is a legitimate helper for streaming file/data URL responses through undici's handler API.
lib/jsdom/level3/xpath.js safe No malicious patterns detected
lib/jsdom/living/aborting/AbortController-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/aborting/AbortSignal-impl.js safe No malicious patterns detected in the AbortSignal implementation code.
lib/jsdom/living/attributes.js safe The code is a standard part of the jsdom library implementing DOM attribute manipulation; no malicious patterns, network activity, dynamic code execution, or process spawning were detected.
lib/jsdom/living/attributes/Attr-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/attributes/NamedNodeMap-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/constraint-validation/DefaultConstraintValidation-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/constraint-validation/ValidityState-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/crypto/Crypto-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSS-impl.js safe No malicious patterns detected; the code implements CSS.supports and CSS.escape logic for jsdom without exfiltration, dynamic execution, or filesystem/process access.
lib/jsdom/living/css/CSSConditionRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSContainerRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSCounterStyleRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSFontFaceRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSGroupingRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSImportRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSKeyframeRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSKeyframesRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSLayerBlockRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSLayerStatementRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSMediaRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSNamespaceRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSNestedDeclarations-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSPageRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSRuleList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSScopeRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSStyleDeclaration-impl.js safe No malicious patterns detected
lib/jsdom/living/css/CSSStyleProperties-impl.js safe No malicious patterns detected
lib/jsdom/living/css/CSSStyleRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/CSSStyleSheet-impl.js safe No malicious patterns detected; the code is a legitimate jsdom CSSStyleSheet implementation with no network, filesystem, process, obfuscation, or credential-related activity.
lib/jsdom/living/css/CSSSupportsRule-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/ElementCSSInlineStyle-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/MediaList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/StyleSheet-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/StyleSheetList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/helpers/computed-style.js safe The code is a legitimate implementation of CSS computed style calculation for jsdom, with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
lib/jsdom/living/css/helpers/css-parser.js safe No malicious patterns detected; the code is a legitimate CSS parser helper for jsdom that only uses static requires, csstree parsing, and DOM exception/rule creation without any network, filesystem, process, or dynamic code execution.
lib/jsdom/living/css/helpers/css-values.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/helpers/font-sizes.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/helpers/generic-property-descriptor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/helpers/line-widths.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/helpers/patched-csstree.js safe No malicious patterns detected
lib/jsdom/living/css/helpers/shorthand-properties.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/helpers/stylesheets.js safe No malicious patterns detected; the code is a legitimate part of jsdom's CSS stylesheet fetching and parsing logic.
lib/jsdom/living/css/helpers/system-colors.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/background.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundAttachment.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundClip.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundColor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundImage.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundOrigin.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundPosition.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundPositionX.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundPositionY.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundRepeat.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/backgroundSize.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/border.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderBottom.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderBottomColor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderBottomStyle.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderBottomWidth.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderColor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderLeft.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderLeftColor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderLeftStyle.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderLeftWidth.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderRight.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderRightColor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderRightStyle.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderRightWidth.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderSpacing.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderStyle.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderTop.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderTopColor.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderTopStyle.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderTopWidth.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/borderWidth.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/bottom.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/clip.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/display.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/flex.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/flexBasis.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/flexGrow.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/flexShrink.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/font.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/fontFamily.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/fontSize.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/fontStyle.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/fontVariant.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/fontWeight.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/height.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/left.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/lineHeight.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/margin.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/marginBottom.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/marginLeft.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/marginRight.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/marginTop.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/opacity.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/padding.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/paddingBottom.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/paddingLeft.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/paddingRight.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/paddingTop.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/right.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/top.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/css/properties/width.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/custom-elements/CustomElementRegistry-impl.js safe This is a legitimate jsdom implementation of the CustomElementRegistry API with no malicious patterns detected.
lib/jsdom/living/custom-elements/ElementInternals-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/deviceorientation/DeviceMotionEventAcceleration-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/deviceorientation/DeviceMotionEventRotationRate-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/documents.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/domparsing/DOMParser-impl.js safe The DOMParser implementation safely parses HTML and XML with scripting disabled and contains no malicious patterns.
lib/jsdom/living/domparsing/InnerHTML-impl.js safe No malicious patterns detected; the code implements standard DOM innerHTML getter/setter functionality for jsdom.
lib/jsdom/living/domparsing/XMLSerializer-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/domparsing/parse5-adapter-serialization.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/domparsing/serialization.js safe No malicious patterns detected; this file contains standard DOM serialization logic using expected dependencies (parse5, w3c-xmlserializer) without obfuscation, network, file system, process, or credential access.
lib/jsdom/living/encoding/TextDecoder-impl.js safe No malicious patterns detected; the file is a straightforward TextDecoder wrapper with no network, filesystem, process, or obfuscated behavior.
lib/jsdom/living/encoding/TextEncoder-impl.js safe No malicious patterns detected in the TextEncoder implementation file.
lib/jsdom/living/events/BeforeUnloadEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/BlobEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/CloseEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/CompositionEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/CustomEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/DeviceMotionEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/DeviceOrientationEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/ErrorEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/Event-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/EventModifierMixin-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/EventTarget-impl.js safe No malicious patterns detected; this is a standard jsdom DOM event target implementation with no data exfiltration, credential harvesting, obfuscation, or process execution.
lib/jsdom/living/events/FocusEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/HashChangeEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/InputEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/KeyboardEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/MessageEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/MouseEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/PageTransitionEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/PointerEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/PopStateEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/ProgressEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/PromiseRejectionEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/StorageEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/SubmitEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/TouchEvent-impl.js safe No malicious patterns detected
lib/jsdom/living/events/TransitionEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/UIEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/events/WheelEvent-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/fetch/Headers-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/fetch/header-list.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/fetch/header-types.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/fetch/header-utils.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/file-api/Blob-impl.js safe No malicious patterns detected
lib/jsdom/living/file-api/File-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/file-api/FileList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/file-api/FileReader-impl.js safe No malicious patterns detected; the code is a standard FileReader implementation from jsdom with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
lib/jsdom/living/geometry/DOMRect-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/geometry/DOMRectReadOnly-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/binary-data.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/by-id-cache.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/create-element.js safe This is legitimate jsdom DOM element creation code implementing the WHATWG DOM spec with no malicious patterns detected.
lib/jsdom/living/helpers/custom-elements.js safe This is a legitimate jsdom internal module implementing the HTML custom elements specification; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
lib/jsdom/living/helpers/dates-and-times.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/details.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/dom-tree.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/encoding.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/events.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/focusing.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/form-controls.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/html-collections.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/html-constructor.js safe This file implements the HTML custom element constructor logic for jsdom and contains no malicious patterns such as data exfiltration, dynamic code execution, credential harvesting, or process spawning.
lib/jsdom/living/helpers/is-window.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/iterable-weak-list.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/iterable-weak-set.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/json.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/mutation-observers.js safe No malicious patterns detected
lib/jsdom/living/helpers/namespaces.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/number-and-date-inputs.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/ordered-set.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/page-transition-event.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/runtime-script-errors.js safe No malicious patterns detected
lib/jsdom/living/helpers/shadow-dom.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/strings.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/svg/basic-types.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/svg/render.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/text.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/traversal.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/validate-names.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/helpers/weak-value-map.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/hr-time/Performance-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/interfaces.js safe No malicious patterns detected; this is a standard jsdom interface registry file that only maps DOM interface names to local require() calls and installs them on a window object.
lib/jsdom/living/mutation-observer/MutationObserver-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/mutation-observer/MutationRecord-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/MimeType-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/MimeTypeArray-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/Navigator-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/NavigatorConcurrentHardware-impl.js safe No malicious patterns detected; the code only reads CPU count via os.cpus() to report hardware concurrency.
lib/jsdom/living/navigator/NavigatorCookies-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/NavigatorID-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/NavigatorLanguage-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/NavigatorOnLine-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/NavigatorPlugins-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/Plugin-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/navigator/PluginArray-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/node-document-position.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/node-type.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/node.js safe No malicious patterns detected; the code implements standard DOM node cloning and namespace lookup logic for jsdom.
lib/jsdom/living/nodes/CDATASection-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/CharacterData-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/ChildNode-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/Comment-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/DOMImplementation-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/DOMStringMap-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/DOMTokenList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/Document-impl.js safe No malicious patterns detected; this is legitimate jsdom Document implementation code with standard DOM APIs, cookie handling via tough-cookie, and no data exfiltration, code execution, or filesystem/process manipulation.
lib/jsdom/living/nodes/DocumentFragment-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/DocumentOrShadowRoot-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/DocumentType-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/Element-impl.js safe No malicious patterns detected
lib/jsdom/living/nodes/ElementContentEditable-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/GlobalEventHandlers-impl.js safe No malicious patterns detected; the file is a standard jsdom event-handler implementation with no network, filesystem, process, or obfuscation concerns.
lib/jsdom/living/nodes/HTMLAnchorElement-impl.js safe No malicious patterns detected in this standard jsdom HTMLAnchorElement implementation.
lib/jsdom/living/nodes/HTMLAreaElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLAudioElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLBRElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLBaseElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLBodyElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLButtonElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLCanvasElement-impl.js safe No malicious patterns detected; the code is a legitimate jsdom implementation for HTMLCanvasElement with no data exfiltration, dynamic code execution, or other security concerns.
lib/jsdom/living/nodes/HTMLCollection-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDListElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDataElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDataListElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDetailsElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDialogElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDirectoryElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLDivElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLElement-impl.js safe This is a legitimate jsdom HTMLElement implementation file with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
lib/jsdom/living/nodes/HTMLEmbedElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLFieldSetElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLFontElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLFormControlsCollection-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLFormElement-impl.js safe No malicious patterns detected
lib/jsdom/living/nodes/HTMLFrameSetElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLHRElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLHeadElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLHeadingElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLHtmlElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLHyperlinkElementUtils-impl.js safe No malicious patterns detected; the code is a legitimate implementation of HTML hyperlink URL utilities from the jsdom library.
lib/jsdom/living/nodes/HTMLIFrameElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLImageElement-impl.js safe No malicious patterns detected
lib/jsdom/living/nodes/HTMLInputElement-impl.js safe No malicious patterns detected; the code is a legitimate jsdom implementation of the HTMLInputElement DOM interface.
lib/jsdom/living/nodes/HTMLLIElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLLabelElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLLegendElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLLinkElement-impl.js safe No malicious patterns detected; the code is a standard jsdom HTMLLinkElement implementation that fetches stylesheets based on element attributes without any exfiltration, obfuscation, or process execution.
lib/jsdom/living/nodes/HTMLMapElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLMarqueeElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLMediaElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLMenuElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLMetaElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLMeterElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLModElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLOListElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLObjectElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLOptGroupElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLOptionElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLOptionsCollection-impl.js safe No malicious patterns detected; the code is a standard implementation of the HTMLOptionsCollection interface for jsdom.
lib/jsdom/living/nodes/HTMLOrSVGElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLOutputElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLParagraphElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLParamElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLPictureElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLPreElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLProgressElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLQuoteElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLSelectElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLSlotElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLSourceElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLSpanElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLStyleElement-impl.js safe No malicious patterns detected
lib/jsdom/living/nodes/HTMLTableCaptionElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTableCellElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTableColElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTableElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTableRowElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTableSectionElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTemplateElement-impl.js safe No malicious patterns detected; the file implements standard HTMLTemplateElement DOM behavior for jsdom.
lib/jsdom/living/nodes/HTMLTextAreaElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTimeElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTitleElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLTrackElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLUListElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLUnknownElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/HTMLVideoElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/LinkStyle-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/Node-impl.js safe This is a legitimate jsdom DOM Node implementation file with no malicious patterns; all requires are internal, no network/file/process access, no eval or dynamic code execution.
lib/jsdom/living/nodes/NodeList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/NonDocumentTypeChildNode-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/NonElementParentNode-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/ParentNode-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/ProcessingInstruction-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/RadioNodeList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGDefsElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGDescElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGElement-impl.js safe No malicious patterns detected in the SVGElement-impl.js file; it contains standard DOM element implementation logic without exfiltration, credential harvesting, obfuscation, or dynamic code execution.
lib/jsdom/living/nodes/SVGGElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGGraphicsElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGMetadataElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGSVGElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGSwitchElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGSymbolElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGTests-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/SVGTitleElement-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/ShadowRoot-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/Slotable-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/Text-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/nodes/WindowEventHandlers-impl.js safe No malicious patterns detected; the file simply defines event accessors for window event handlers.
lib/jsdom/living/nodes/XMLDocument-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/range/AbstractRange-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/range/Range-impl.js safe No malicious patterns detected; the code is a standard implementation of the DOM Range API used by jsdom, with no network, filesystem, process spawning, credential harvesting, or obfuscated behavior.
lib/jsdom/living/range/StaticRange-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/range/boundary-point.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/selection/Selection-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGAnimatedPreserveAspectRatio-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGAnimatedRect-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGAnimatedString-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGListBase.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGNumber-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGPreserveAspectRatio-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGRect-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/svg/SVGStringList-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/traversal/NodeIterator-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/traversal/TreeWalker-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/traversal/helpers.js safe No malicious patterns detected; the code implements standard DOM traversal filtering logic with proper error handling and no external data access, dynamic execution, or suspicious behavior.
lib/jsdom/living/webidl/DOMException-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/webidl/QuotaExceededError-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/websockets/WebSocket-impl.js safe This is a legitimate jsdom WebSocket implementation that wraps undici's WebSocket, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning detected.
lib/jsdom/living/webstorage/Storage-impl.js safe This is a standard implementation of the Web Storage API (localStorage/sessionStorage) in jsdom with no malicious patterns detected.
lib/jsdom/living/window-properties.js safe No malicious patterns detected; the code implements standard DOM named property tracking for jsdom without any data exfiltration, credential harvesting, obfuscation, or process execution.
lib/jsdom/living/window/BarProp-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/window/External-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/window/History-impl.js safe No malicious patterns detected; the code is a standard implementation of the HTML5 History API for jsdom with no suspicious behavior.
lib/jsdom/living/window/Location-impl.js safe No malicious patterns detected
lib/jsdom/living/window/Screen-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/window/SessionHistory.js safe No malicious patterns detected; the file implements standard WHATWG session history logic using only internal jsdom modules and no suspicious network, filesystem, or code-execution behavior.
lib/jsdom/living/xhr/FormData-impl.js safe No malicious patterns detected; the code is a standard jsdom FormData implementation with no exfiltration, obfuscation, or suspicious behavior.
lib/jsdom/living/xhr/XMLHttpRequest-impl.js safe This is legitimate jsdom XMLHttpRequest implementation code with no malicious patterns detected; the worker thread usage, network requests, and cookie handling are all standard library functionality.
lib/jsdom/living/xhr/XMLHttpRequestEventTarget-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/xhr/XMLHttpRequestUpload-impl.js safe Cleared by Jev triage; no further analysis needed
lib/jsdom/living/xhr/multipart-form-data.js safe No malicious patterns detected
lib/jsdom/living/xhr/xhr-sync-worker.js safe The code is a legitimate JSDOM internal worker for synchronous XHR handling, with no malicious patterns detected.
lib/jsdom/living/xhr/xhr-utils.js safe The code implements standard CORS/XHR fetch handling for jsdom with no malicious patterns, exfiltration, obfuscation, or suspicious behavior detected.
lib/jsdom/virtual-console.js safe No malicious patterns detected; the code implements a simple virtual console for jsdom with no network, filesystem, process, or dynamic code execution activity.

Frequently asked questions

Is jsdom safe to use?

No confirmed malware was found in jsdom@30.1.1, but the review flagged 10 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does jsdom contain malware?

No malware was identified in jsdom@30.1.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was jsdom checked?

Togoder Security downloaded the published npm package and had an AI model read its 653 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan jsdom together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in jsdom@30.1.1, cost nothing.

Related security reports