# jsonparse@1.3.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:16.000Z
- Files reviewed: 3
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/jsonparse
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package jsonparse@1.3.1 on Oct 6, 2026. An AI review of 3 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] credential handling

Finding ID: `NPS-96C261EFC554`

File: `examples/twitterfeed.js:5`

The code requires './credentials' and uses cred.username and cred.password to authenticate against Twitter's streaming API. While not inherently malicious, this demonstrates handling of plaintext credentials that could be harvested if the credentials file is compromised or if this pattern is replicated in a malicious package.

### [low] external network request

Finding ID: `NPS-E157557D1DBF`

File: `examples/twitterfeed.js:6`

The code creates an HTTP client to stream.twitter.com and sends an Authorization header containing Base64-encoded credentials. This is a legitimate Twitter API call in an example file, but it demonstrates outbound network behavior with credentials attached.

### [low] deprecated API usage

Finding ID: `NPS-05F8D7435438`

File: `jsonparse.js:55`

Uses deprecated 'new Buffer()' constructor (e.g., lines 55, 57, 257, 262, 265) which is deprecated in modern Node.js and can lead to uninitialized memory exposure or security warnings.

## Files reviewed

- `examples/twitterfeed.js` (medium): This appears to be a benign example file demonstrating Twitter streaming API usage with a custom JSON parser; no malicious patterns such as exfiltration, obfuscation, or backdoors were detected.
- `bench.js` (safe): No malicious patterns detected; the file is a simple local JSON parsing benchmark with no network, credential, or system access.
- `jsonparse.js` (safe): This is a legitimate streaming JSON parser with no malicious patterns; only minor deprecated API usage was found.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
