# json5@1.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:17:41.000Z
- Files reviewed: 9
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/json5@1.0.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package json5@1.0.2 on Oct 6, 2026. An AI review of 9 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Module system modification

Finding ID: `NPS-4CF863F164FA`

File: `lib/register.js:1`

Registers a custom require.extensions handler for .json5 files, modifying Node.js module loading behavior at import time. This is a common legitimate pattern for JSON5 parsers, but it changes global require behavior for any project using this package.

### [low] Top-level code execution

Finding ID: `NPS-DC3B7478BD80`

File: `lib/register.js:1`

Code executes at import time (require.extensions assignment), altering the runtime environment of the host application. While typical for this library's purpose, it demonstrates import-time side effects.

### [low] File system read

Finding ID: `NPS-1D444D3ECC13`

File: `lib/register.js:1`

Reads arbitrary .json5 files from disk via fs.readFileSync when such files are required. This is the expected behavior of a JSON5 parser module and stays within the scope requested by the consumer.

## Files reviewed

- `lib/register.js` (medium): The code is a standard JSON5 require extension hook that modifies module loading and reads files as expected for this library, with no signs of exfiltration, credential harvesting, obfuscation, or malicious network/process activity.
- `dist/index.js` (safe): The code is a legitimate implementation of the JSON5 parsing and stringifying library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or dynamic code execution.
- `lib/cli.js` (safe): No malicious patterns detected; the code is a standard JSON5 CLI parser with no network, credential, or process execution behavior.
- `lib/index.js` (safe): This is a standard compiled CommonJS module that re-exports parse and stringify functions, with no suspicious or malicious patterns detected.
- `lib/parse.js` (safe): No malicious patterns detected; this is a legitimate JSON5 parser implementation.
- `lib/require.js` (safe): No malicious patterns detected
- `lib/stringify.js` (safe): This is a legitimate JSON5 stringify implementation with no malicious patterns detected; it only performs serialization and string manipulation with no network, filesystem, process, or dynamic execution activities.
- `lib/unicode.js` (safe): No malicious patterns detected; the file contains only Unicode property escape regular expressions for identifier and whitespace matching, with no I/O, network, process execution, or obfuscated behavior.
- `lib/util.js` (safe): No malicious patterns detected; the file contains only standard utility functions for character classification using Unicode regex tests.

## Version ranges

None of the 2 scanned versions of json5 are flagged high or critical. The latest scanned version, 2.2.3, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.0.2 – 2.2.3 (`>=1.0.2 <=2.2.3`): medium (global-scope-modification +2 more)

## Scanned versions

- [2.2.3](https://security.togoder.click/npm/json5@2.2.3): medium, 2026-10-06T14:10:42.000Z
- [1.0.2](https://security.togoder.click/npm/json5@1.0.2): medium, 2026-10-06T14:17:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
