# mkdirp@0.5.6 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:35:18.000Z
- Files reviewed: 2
- Findings: no findings
- Report: https://security.togoder.click/npm/mkdirp@0.5.6
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package mkdirp@0.5.6 on Oct 4, 2026. An AI review of 2 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `bin/cmd.js` (safe): No malicious patterns detected; the script is a standard CLI wrapper for the mkdirp library with no network, credential, or process-spawning activity.
- `index.js` (safe): No malicious patterns detected

## Version ranges

None of the 2 scanned versions of mkdirp are flagged high or critical. The latest scanned version, 3.0.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 3.0.1 (`3.0.1`): not scanned
- 0.5.6 – 1.0.4 (`>=0.5.6 <=1.0.4`): clean

## Scanned versions

- [1.0.4](https://security.togoder.click/npm/mkdirp@1.0.4): safe, 2026-10-04T16:55:52.000Z
- [0.5.6](https://security.togoder.click/npm/mkdirp@0.5.6): safe, 2026-10-04T16:35:18.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
