# mipd@0.0.7 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:35:17.000Z
- Files reviewed: 18
- Findings: no findings
- Report: https://security.togoder.click/npm/mipd
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package mipd@0.0.7 on Oct 4, 2026. An AI review of 18 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/cjs/index.js` (safe): No malicious patterns detected
- `dist/cjs/register.js` (safe): No malicious patterns detected
- `dist/cjs/store.js` (safe): No malicious patterns detected; the code implements a simple provider store with subscription and lifecycle management.
- `dist/cjs/types.js` (safe): No malicious patterns detected
- `dist/cjs/utils.js` (safe): No malicious patterns detected
- `dist/cjs/window.js` (safe): No malicious patterns detected
- `dist/esm/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/register.js` (safe): No malicious patterns detected
- `dist/esm/store.js` (safe): No malicious patterns detected; the file only implements an in-memory provider store with event listeners and imports a local utility module.
- `dist/esm/types.js` (safe): No malicious patterns detected
- `dist/esm/utils.js` (safe): No malicious patterns detected; the code only implements standard EIP-6963 provider announcement and discovery using browser window events.
- `dist/esm/window.js` (safe): No malicious patterns detected
- `src/index.ts` (safe): No malicious patterns detected
- `src/register.ts` (safe): No malicious patterns detected; the file only contains TypeScript type definitions and interface declarations for EIP-1193 provider registration.
- `src/store.ts` (safe): No malicious patterns detected; the code is a legitimate EIP-6963 provider store implementation that only requests provider announcements via the standard browser event mechanism.
- `src/types.ts` (safe): No malicious patterns detected; the file only defines TypeScript interfaces for EIP-6963 provider events with no runtime code or suspicious behavior.
- `src/utils.ts` (safe): No malicious patterns detected; the code only implements standard EIP-6963 provider announcement and request utilities without any exfiltration, dynamic execution, or system access.
- `src/window.ts` (safe): This file only contains type-only imports and ambient TypeScript type declarations for EIP-6963 events with no runtime code, network calls, filesystem access, or executable logic.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
