Summary
Togoder Security scanned the npm package next@16.3.8 on Oct 6, 2026. An AI review of 3305 source files produced 6 high, 245 medium, 685 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 936
Remote binary download without integrity verification
NPS-140248425475
The code downloads an executable binary (mkcert) from GitHub releases and writes it to disk without verifying a checksum or signature. If the download is compromised via MITM or a compromised release, arbitrary code could be executed.
Suspicious process execution
NPS-64407DC0225B
The code uses execSync to run the downloaded binary with shell interpolation of dynamically constructed paths and hostnames. This could allow command injection if host or certDir contain malicious values.
Node.js Inspector Exposure
NPS-C0307DEC67A1
The middleware endpoint /__nextjs_attach-nodejs-inspector opens the Node.js inspector on the process debug port (process.debugPort) if not already listening, then fetches and returns the DevTools frontend URL from the inspector's HTTP endpoint. This grants anyone who can reach this route full debugging access to the Node.js process, including the ability to execute arbitrary code in the runtime via the inspector protocol. While this is intended for Next.js development mode, exposing it in a production or non-loopback context is a serious security risk.
Remote Code Execution Surface via Debugger
NPS-C2E62E9493B8
By exposing the Node.js inspector endpoint, an attacker with network access to this route could connect to the inspector WebSocket, evaluate arbitrary JavaScript, read environment variables, files, and credentials, and spawn processes. This effectively provides a backdoor-like capability if the endpoint is reachable outside trusted development environments.
Local debugger/DevTools middleware exposure
NPS-E847F970F741
Middleware getAttachNodejsDebuggerMiddleware and devToolsConfigMiddleware expose Node.js debugger attach functionality and devtools configuration over the dev server. This is a powerful capability that, if the dev server is reachable by untrusted parties, could allow attaching a Node debugger or otherwise inspecting/interfering with the process.
Path traversal / arbitrary file read
NPS-2858B1421EE5
The asset name is taken directly from the 'blob:' input and resolved against options.distDir without validating that the final path stays inside distDir. A crafted blob URL such as 'blob:../../../../etc/passwd' (when options.assets is not provided) would resolve outside the intended distribution directory, allowing arbitrary readable files to be served via the Response stream.
Dynamic code execution
NPS-EA1E608CBEBA
The requireFromString function compiles and executes arbitrary JavaScript code provided as a string using module._compile. This is a dynamic code execution capability that could be abused if the input is attacker-controlled.
Dynamic code execution via require hook
NPS-B95BD7F20964
The code compiles TypeScript config using SWC and then dynamically loads the resulting CommonJS code via requireFromString, which executes the transpiled module in the current process. While this is intentional behavior for loading Next.js config, it represents dynamic code execution where arbitrary code from next.config.ts is run at build time.
Dynamic require of manifest file
NPS-7E0B6A9A45A5
The readEntryJSFiles function constructs a file path from pagePath and requires it at runtime. While this is intended to load Next.js RSC manifests, the pattern of requiring a file whose path is derived from route/manifest data could be exploited if an attacker can influence pagePath to load arbitrary JavaScript files, leading to code execution. The save/restore of global.__RSC_MANIFEST is also a fragile global mutation pattern.
Environment variable input parsing
NPS-1F042C2DCC6B
The code reads process.env.NEXT_PRIVATE_PAGE_PATHS and process.env.NEXT_PRIVATE_APP_PATHS and parses them with JSON.parse. These environment variables can override route path discovery. While this appears to be a legitimate testing hook in Next.js, it represents an environment-controlled code path that can influence build output. If an attacker can set these environment variables, they can inject arbitrary paths into the build configuration.
Dynamic module loading with external/environment-controlled paths
NPS-649BA217809B
The code resolves and requires modules based on environment variables such as __INTERNAL_CUSTOM_TURBOPACK_BINDINGS, NEXT_TEST_NATIVE_DIR, NEXT_TEST_WASM_DIR, and NEXT_TEST_NATIVE_IGNORE_LOCAL_INSTALL. If an attacker can control these env vars, they could load arbitrary native binaries or JS modules into the process.
Native binary download fallback
NPS-B015E9E68C04
loadBindings/tryLoadNativeWithFallback download native SWC binaries at runtime via download-swc when local bindings are missing. This introduces a network-dependent, runtime-fetched executable code path which, if the download source or integrity is compromised, could execute untrusted native code.
Runtime execution of native .node binaries
NPS-07642AF15C7B
The module loads and executes platform-specific native Node addons (@next/swc-* / next-swc.*.node). Native binaries can contain arbitrary code; trust depends entirely on the upstream package integrity from the registry.
Dynamic worker thread creation from external input
NPS-044DEF1263C8
The code spawns Node.js Worker threads using a filename provided via the creation.options.filename parameter. This filename is passed directly to new Worker(...) without validation. While this is a legitimate pattern for Turbopack's loader worker pool (executing loader files), the filename could originate from build configuration or external input, allowing arbitrary JavaScript files to be executed in a worker thread context if an attacker can control the filename. This constitutes dynamic module loading/execution.
Dynamic import with placeholder
NPS-94BCE2D43004
The code uses import('MODULE') with a placeholder 'MODULE' that is later replaced during build. This dynamic import could load arbitrary external modules depending on the build configuration, potentially fetching malicious code from untrusted sources if the placeholder is not properly controlled.
Global prototype patching / network interception
NPS-AC9E8E26261E
The code permanently monkey-patches net.Socket.prototype.connect to intercept all outgoing TCP connections and record host/port into an external array. While it restores the original method when the returned cleanup function is invoked, until then it silently observes all socket connections made anywhere in the process. This is a legitimate access-trace mechanism for Turborepo, but the same pattern is commonly used to intercept and harvest connection targets (potentially including internal service addresses, databases, or credential-bearing endpoints).
Data collection at runtime
NPS-2166B5ACCC74
Every TCP connect call is inspected and the destination host and port are pushed into the caller-supplied 'addresses' array. The destination of that array is controlled by the caller; if used maliciously, this could accumulate internal network topology information. In this package it appears intended for tracing/telemetry of accessed network resources.
Dynamic module loading based on external configuration
NPS-D7D918118B4B
The loadPlugin function resolves and requires PostCSS plugin modules using require.resolve and require() with plugin names provided from external PostCSS configuration files found in the project directory. While this is the intended behavior of PostCSS plugin loading, it means that a malicious or compromised PostCSS configuration file can cause arbitrary modules installed in the project to be loaded and executed at build time. This is a supply-chain/config-trust concern rather than a direct malicious pattern in this file.
Improper output encoding
NPS-F0A2CB05D9EC
resolveRobots and resolveSitemap build output (robots.txt, sitemap XML, manifest JSON) by directly interpolating user/route-supplied values (userAgent, allow, disallow, crawlDelay, host, sitemap URLs, item.url, alternates languages/hrefs, image locs, and all video fields such as title, description, content_loc, player_loc, restriction, platform, uploader info, etc.) without XML/HTML escaping or newline sanitization. If route metadata is attacker-influenced, this can lead to injection into generated robots.txt (e.g. injecting additional 'Disallow'/'Sitemap' directives via newlines) and malformed or injected XML in sitemap.xml (e.g. breaking out of element content or attributes such as the uploader info attribute or restriction relationship attribute). While this is not a remote code execution or data exfiltration flaw, it is a genuine output-encoding/security issue in a build-time metadata generator.
Dynamic module import with computed path
NPS-B98A657918EB
The generated code includes a dynamic import statement for an incremental cache handler: import incrementalCacheHandler from ${stringifiedCacheHandlerPath}. The path is derived from the cacheHandler loader option. If an attacker can control this option, they could cause the build to import an arbitrary module, potentially executing malicious code.
Dynamic code execution via generated string
NPS-5E0CA5010645
The loader returns a JavaScript source string that is compiled/executed by webpack. The string is built using dynamic values such as page, absolutePagePath, cacheHandler, middlewareConfig, and rootDir derived from loader options and the build context. While this is typical for webpack loaders, if these values are attacker-controlled (e.g., via a malicious config or compromised dependency), it could lead to arbitrary code execution in the build process.
Dynamic module loading with computed path
NPS-6127AD860964
The code performs require(fontLoaderPath).default where fontLoaderPath is obtained from loader options via this.getOptions(). If the webpack configuration or any upstream source can influence fontLoaderPath, this allows arbitrary module loading and potential code execution during the build process. While this is a legitimate Next.js feature, it represents a dynamic require that should be validated/restricted.
Build-time code execution
NPS-9FF00E02A6BC
This is a webpack loader that executes at build time and dynamically loads/executes a font loader module specified by fontLoaderPath. Build-time loaders are a known supply-chain risk vector as they run with developer privileges. The dynamic require is the primary concern, though it appears to be an intentional part of Next.js's font system.
Dynamic module loading with computed specifiers
NPS-9FDB7BB34D92
The loader reads a 'modules' array from webpack options (potentially attacker-controlled if the build config is compromised or if a dependency injects options) and generates require() calls with dynamically constructed paths. Module specifiers are passed through webpack's resolver against rootContext and then embedded into generated code via JSON.stringify. While JSON.stringify mitigates direct code injection, a malicious config or compromised build chain could force loading of arbitrary modules, including sensitive files if a path resolutions allows it. This is expected behavior for a Next.js internal instrumentation loader, but the dynamic require generation is a notable pattern worth flagging in third-party contexts.
Unvalidated request body JSON parsing
NPS-372C642EEA69
The HTTP handler reads the request body into a string and passes it through JSON.parse(body) before handing it to the MCP transport. There is no length limit on the body, no Content-Type validation, and no streaming limit, so a client can send an arbitrarily large payload to cause memory exhaustion (DoS). The parsed JSON is also accepted without checking the Content-Type or method restrictions expected by the MCP spec.
HTTP server bound to loopback without authentication
NPS-1E8FA9BD5A97
The MCP HTTP server listens on 127.0.0.1 (loopback only), which is good, but it exposes an unauthenticated tool (query_spans) that returns trace data. Any local process or a DNS-rebinding attack from a browser page can reach 127.0.0.1 and invoke the MCP endpoint. No Origin/Host header validation or authentication is performed, allowing cross-site requests to interact with the local trace server.
Data exfiltration / file upload to external server
NPS-7F2F7A10C2F7
The code reads local CPU profile (.cpuprofile) and Turbopack trace files and uploads their contents to an external endpoint (nextjs.org/api/upload-trace, overridable via __NEXT_UPLOAD_TRACE_URL_OVERRIDE). While this appears to be legitimate telemetry for the Next.js team, it constitutes uploading potentially sensitive local build data to a remote server.
Process spawning and dynamic dependency installation
NPS-E1473ABDEB9D
The code dynamically installs missing dependencies via installDependencies and then spawns the Playwright CLI binary using cross-spawn with shell: false. While this is part of the legitimate Next.js experimental test workflow, the dynamic installation and execution of package binaries could be abused if an attacker controls package resolution or the project environment.
Spawning processes or shell commands
NPS-23306D2E8EAF
The code uses child_process.spawn to execute a command derived from getNpxCommand(baseDir).split(' '). If getNpxCommand returns a string influenced by untrusted input (e.g., project directory path or environment), it could allow command injection or execution of arbitrary binaries. The spawn call also passes options.revision directly as an argument, which, while not shell-interpreted, could be manipulated if revision is attacker-controlled.
dangerouslySetInnerHTML usage
NPS-616CB4986FA9
The component uses dangerouslySetInnerHTML to inject document.documentElement.innerHTML directly into the DOM. While it caches the page's own HTML on mount, this pattern can be exploited if the cached HTML contains attacker-controlled content (e.g., injected via XSS or a compromised dependency), effectively re-rendering arbitrary scripts/markup without sanitization.
Global fetch override
NPS-9419F3356D1F
The module installs a global window.fetch override during lock scopes. While intended for a testing API and gated by environment checks, monkey-patching fetch could interfere with other scripts or be abused if the lock state is manipulated. It blocks user-initiated fetches until lock release, which is a behavior change outside normal app code.
Cookie manipulation
NPS-73819C03677D
The code reads and writes the NEXT_INSTANT_TEST_COOKIE via both document.cookie and cookieStore, including a defensive clear that modifies cookies outside the component's immediate scope. This could affect cookie state for the whole origin and potentially leak lock state or resurrect stale cookies if race conditions are exploited.
Suspicious network request
NPS-3EE231CEEC6F
The code creates a WebSocket connection using a URL derived from options.assetPrefix and options.path. While this is expected behavior for a Next.js hot module replacement (HMR) client, it could be exploited if the assetPrefix is controlled by an attacker, leading to connection to a malicious server.
Dynamic URL construction
NPS-8D3654B1ED37
The WebSocket URL is constructed using getSocketUrl(options.assetPrefix) and options.path. If these values are not properly sanitized, an attacker could potentially redirect the WebSocket connection to an arbitrary server.
Dynamic HTML injection
NPS-07F24DFDD949
The function reactElementToDOM uses dangerouslySetInnerHTML to assign raw HTML to el.innerHTML. If untrusted input reaches this path, it could lead to DOM-based XSS. This is a known React/Next.js head manager pattern, but it is still a dangerous capability if the data source is compromised.
Use of innerHTML
NPS-4B19CCAB978A
Direct assignment to innerHTML can execute inline scripts and event handlers when combined with attacker-controlled props. This is a common vector for client-side code injection.
Third-party registry verification needed
NPS-CE3801CE01BE
File uses '@swc/helpers', 'react', 'react-dom' and Next.js internal shared modules. Confirm the package name, publisher, and integrity hash match the official Next.js distribution; typosquatted republishes of this file would be highly dangerous due to arbitrary script injection capability.
dangerouslySetInnerHTML usage
NPS-FB5058EE0A6C
The component supports a 'dangerouslySetInnerHTML' prop that directly assigns HTML content to script element innerHTML without sanitization, enabling arbitrary inline script execution if untrusted input reaches this prop.
Dynamic script injection
NPS-1AA8077C572F
The loadScript function dynamically creates <script> elements and sets their src from the 'src' prop, then appends them to document.body. While this is the intended behavior of Next.js's Script component, it allows arbitrary remote script loading if a malicious prop value is passed, which could enable supply-chain or XSS attacks in consuming applications.
Dynamic code execution via self.__next_s
NPS-25B36155EF89
In the appDir path, the component emits inline scripts invoking '(self.__next_s=self.__next_s||[]).push(...)' with JSON-encoded props. This pattern is internal to Next.js but executes dynamic payloads at runtime and should be treated as elevated risk surface if the module is not the official Next.js package.
Global runtime patching
NPS-038C9C80E848
The module patches core Node.js globals including globalThis.Request, globalThis.Response, globalThis.Headers, net.Socket.prototype.connect, https.Agent.prototype.addRequest, and node:http ClientRequest/get/request. This modifies core HTTP behavior process-wide at import time via the applyPatch mechanism, which is a powerful interception mechanism that could be used for man-in-the-middle modification of all outgoing requests.
Dynamic module loading with environment variable
NPS-A4586B4E2731
The function uses require(process.env.NEXT_FONT_GOOGLE_MOCKED_RESPONSES) to load a module based on an environment variable. While this is intended for testing (mocked responses), if an attacker can control this environment variable, they could load arbitrary code. This is a potential security risk in environments where environment variables are not fully trusted or can be influenced by external input.
Filesystem read based on user-controlled path
NPS-AE2C2DFBA76B
When the NEXT_FONT_GOOGLE_MOCKED_RESPONSES environment variable is set, the function reads arbitrary files from disk via fs.readFileSync(url) when url starts with '/'. If an attacker can influence the 'url' value (e.g., through a compromised font manifest or build configuration) and the environment variable is set, this could allow reading sensitive files. However, this path is a documented mocking/testing feature and requires environmental precondition, so severity is moderate.
Dynamic module loading
NPS-AC71EFA81CA2
The file dynamically loads './bundle' and calls the function coreLibPluginPass(). While this pattern is common in Babel's build output, the loaded module could contain obfuscated or malicious code. The actual security risk cannot be assessed without inspecting the 'bundle' module it requires.
Dynamic module loading
NPS-9E61358ABB29
The file uses require('./bundle') with a relative path and invokes .core() on the imported module. While the path is static and relative, the actual behavior depends entirely on the contents of './bundle', which is not provided for analysis. This pattern is common in Babel but could hide malicious code if the bundle is compromised.
Dynamic code execution (eval)
NPS-93E39316FFB2
The loadQueries function uses eval('require')(eval('require').resolve(name, {paths:['.', ctx.path]})) to dynamically resolve and load modules from user-controlled config names. While guarded by checkExtend() and dangerousExtend checks, this is still dynamic module loading based on config input and can lead to arbitrary code execution if a malicious package name passes the prefix check (e.g., a malicious 'browserslist-config-*' package installed in node_modules).
process spawning
NPS-E0AD7E70610F
The module wraps child_process.spawn and spawnSync to execute external commands. While this is the intended purpose of the cross-spawn library, it is a capability that could be misused if the module is compromised or if inputs are attacker-controlled.
HTTP header injection risk
NPS-F5E94C24F7E7
The _createHttpHeader function builds raw HTTP header strings from response headers without sanitizing CRLF characters. If an upstream server returns a header value containing \r\n, this could enable HTTP response splitting/header injection in the websocket upgrade path.
Potential Server-Side Request Forgery (SSRF)
NPS-34AD04B6286C
The proxy implementation forwards requests to arbitrary targets provided via options (target/forward/URL). If target URLs are derived from untrusted input, this can be abused for SSRF against internal services. This is inherent to proxy libraries but requires callers to validate targets.
Redirect handling strips credentials on cross-host only
NPS-4E3CF1EF19E0
In followRedirects logic, authorization and cookie headers are stripped only when the redirect host differs from the original request's URL object host, but the comparison uses new URL(location, forwardTarget) and compares against 'forwardTarget' host rather than the actual current hop. Under certain redirect chains this comparison may not correctly detect cross-host hops, potentially leaking Authorization/Cookie headers to a different origin.
Dynamic code execution
NPS-5FE199429AA9
The code uses eval("require")(file) to dynamically load modules. While this is a known pattern in jest-worker for resolving module paths at runtime, eval-based module loading can be exploited if the file variable is attacker-controlled. In this context, file is received from the parent process via IPC, which is normally trusted, but it represents a dynamic code execution path that could be abused if the IPC channel is compromised.
IPC message handling / dynamic invocation
NPS-E7CAA92EA5CD
The child process listens for messages from the parent and executes functions from dynamically required modules based on message content (execMethod). Method names and arguments are controlled by the parent process. If a malicious or compromised parent process sends crafted messages, arbitrary exported functions from the loaded module could be invoked with arbitrary arguments.
Dynamic code execution
NPS-0B976F2D2D32
The file uses eval('require')(file) to dynamically load modules specified in messages from the parent process. While this is legitimate jest-worker functionality, the use of eval to obtain require bypasses normal module resolution and could be exploited if the parent process is compromised or if the file path is attacker-controlled.
Arbitrary function execution
NPS-F034F7EAF8AD
execFunction applies a function (from the dynamically required module) with user-supplied arguments. The method and args come from parent process messages. If the parent process is malicious or compromised, it could invoke arbitrary exported functions with arbitrary arguments.
Dynamic code execution
NPS-FD6FFEA0CDA4
The loader uses eval() to dynamically import ES modules based on a computed URL from loader.path. While this is standard webpack loader-runner behavior for ESM loaders, eval with computed input is a code execution risk if loader.path can be influenced by untrusted input.
Dynamic module loading
NPS-803DCE97A301
Uses require(loader.path) to load arbitrary modules from computed paths. This is core functionality for a loader runner, but allows loading any module specified by the loader configuration.
Dynamic code execution
NPS-C23E95915FBE
The evalModuleCode function uses Node's Module._compile to evaluate and execute arbitrary JavaScript module code (provided as the 'code' argument) at runtime. While this is an expected part of mini-css-extract-plugin's child compiler behavior, it represents a dynamic code execution primitive that could be abused if the extracted CSS content or module code is attacker-controlled.
module loading hijacking
NPS-8BEA123798FF
The code monkey-patches Module.prototype._compile, intercepting the compilation of every CommonJS module loaded after this package is imported. While the modification is gated on 'use client'/'use server' directives and delegates to the original compile, this is an invasive runtime behavior that hooks into Node's core module system and could affect unexpected files.
dynamic code parsing and directive-based branching
NPS-AE7B31C67EC6
Uses acorn-loose to parse arbitrary file contents at require time and makes security-relevant decisions based on string directives in the source. This creates a mechanism where the behavior of any required module can be altered based on its content, which expands the attack surface if the package is ever compromised or if attacker-controlled files are loaded.
module loading hijacking
NPS-8BEA123798FF
The code monkey-patches Module.prototype._compile, intercepting the compilation of every CommonJS module loaded after this package is imported. While the modification is gated on 'use client'/'use server' directives and delegates to the original compile, this is an invasive runtime behavior that hooks into Node's core module system and could affect unexpected files.
dynamic code parsing and directive-based branching
NPS-AE7B31C67EC6
Uses acorn-loose to parse arbitrary file contents at require time and makes security-relevant decisions based on string directives in the source. This creates a mechanism where the behavior of any required module can be altered based on its content, which expands the attack surface if the package is ever compromised or if attacker-controlled files are loaded.
Dynamic code execution
NPS-C1A4D784974A
Uses eval("require").resolve(...) to dynamically load optional Sass implementations. While this is a known pattern in sass-loader, dynamic require resolution can be abused by malicious packages if module resolution is influenced by attacker-controlled paths or environment.
Unsafe dynamic module loading
NPS-E612BF01462D
The loader accepts a user-provided 'implementation' option and calls require(s) on it if it is a string. This allows loading arbitrary modules based on build configuration, which could be exploited if untrusted configuration is used.
Dynamic code execution
NPS-3C836CB4C77B
The code uses new Function(""+e) to convert a non-function argument into a function, which can execute arbitrary code if the input is controlled by an attacker.
Dynamic code execution
NPS-535773125CD1
The code uses eval() and execScript() to execute arbitrary JavaScript code within iframe contexts. This is inherent to the vm-browserify package's purpose of providing a browser-based VM implementation, but it represents a significant security concern if untrusted code is ever passed to these functions.
Dynamic module loading from external input
NPS-83AF5C23A606
The function resolves and dynamically imports adapterPath from a file URL via pathToFileURL(require.resolve(adapterPath)).href, then invokes adapterMod.onBuildComplete(...). This allows arbitrary code from an adapter module to execute with full build-time privileges. While this is an intentional Next.js adapter mechanism, the adapter path is an external input and the invoked callback receives sensitive build outputs, file paths, environment config, middleware matchers, and prerender tokens.
Sensitive data exposure to third-party adapter
NPS-66953A9A573A
The onBuildComplete callback is passed prerenderManifest.preview.previewModeId as config.bypassToken on prerender outputs (lines ~684 and ~832), and numerous absolute filesystem paths, project directory, repo root, distDir, and full routing/middleware matcher details. A malicious adapter could exfiltrate secrets or use the preview bypass token to access preview-authenticated routes.
Execution of user-provided code
NPS-3FE8E88F8473
The function executes config.compiler.runAfterProductionCompile (a user-provided function from next.config.js) during the production build. This is by design for Next.js, but in a third-party package context it represents arbitrary code execution at build time from configuration, which could be abused if an attacker can influence the configuration.
Dynamic module loading / require hook
NPS-17EC4BB40AEC
The code overrides Node.js require.extensions for multiple file extensions (.js, .ts, .cts, .mts, .cjs, .mjs) and dynamically transforms and executes code using swc transformSync. This is a powerful hook that can intercept and modify module loading behavior, potentially allowing arbitrary code execution or code injection if swcOptions are attacker-controlled or if the hook is used to load untrusted modules.
Dynamic code execution via _compile
NPS-F8888C959312
The require hook uses mod._compile to execute transformed code. This is a low-level Node.js API that compiles and runs code. Combined with the fallback to readFileSync and transformSync, it can execute arbitrary JavaScript from files on disk. While this is the intended function of a require hook, it represents a risk if the package is compromised or if the hook is misused.
Dynamic code execution / module loading
NPS-14FBDA24F906
The transpileConfig function reads a Next.js config file from disk, transpiles it with SWC, and then executes the resulting code via requireFromString. If an attacker can control or modify nextConfigPath (e.g., via a malicious project configuration or path traversal), this could lead to arbitrary code execution. Additionally, the code dynamically imports the config path using import(pathToFileURL(nextConfigPath).href) when the Node.js native TypeScript loader is enabled, which also executes the file. This is expected behavior for loading user config, but the path is derived from input and not validated to be within a trusted scope.
Dynamic import with computed path
NPS-27F1F22E49A8
The use of import(pathToFileURL(nextConfigPath).href) dynamically imports a file based on the nextConfigPath parameter. If this path is influenced by external input, it could load malicious modules. However, in the context of Next.js, this is intended for loading the user's own configuration.
Predictable Cryptographic Keys
NPS-920A63D3A8EF
The preview signing and encryption keys are generated using crypto.randomBytes, which is cryptographically secure. However, the keys are stored in a plaintext JSON file (.previewinfo) in the cache directory, which could be accessible to other users or processes on the system, potentially leading to key compromise.
Dynamic module loading with computed path
NPS-40085624A8B4
The readEntryJSFiles function constructs a file path from user-influenced inputs (pagePath, appRoute) and calls require() on it. While this is intended to load Next.js RSC manifest files from the dist directory, the dynamic require with a path derived from external data could potentially load unintended modules if pagePath or appRoute contain path traversal sequences. The code does not sanitize or validate these inputs before constructing the path.
Dynamic worker thread creation with computed filename
NPS-0B266DD8B1FD
The code creates a Node.js Worker thread using a filename derived from the creation.options.filename value, which is passed from an external bindings callback. If an attacker can influence this filename (e.g., through a crafted project configuration or module resolution), it could lead to arbitrary code execution in a worker thread. The workerData also includes bindingPath and cwd, potentially exposing environment context to the worker.
Dynamic import with placeholder
NPS-833349D71E4E
The code uses a dynamic import('MODULE') where MODULE appears to be a build-time placeholder that will be replaced with the actual module path. If not properly controlled, this could allow loading arbitrary modules from untrusted sources. This is a common pattern in bundlers/frameworks (like Next.js edge runtime) but could be exploited if the placeholder is user-controllable.
Proxy with dynamic property access
NPS-4BA89598AA9D
The Proxy get trap dynamically accesses mod[name] and returns a function that calls it. If name is attacker-controlled, this could allow invoking arbitrary exports from the imported module. This is inherent to the design but could be a security concern if the imported module exposes dangerous functions.
Environment variable access tracking
NPS-021ED7585A75
The code wraps process.env in a Proxy and records every accessed environment variable key into the provided envVars set. While this appears to be for build-time instrumentation (turborepo-access-trace), it globally replaces process.env for the entire process. Any consumer of this function can capture all environment variable names accessed by subsequent code, which could aid reconnaissance for credential harvesting if the tracked set is exfiltrated or misused. No exfiltration or credential file reads are present in this file itself.
Global prototype modification / monkey-patching
NPS-DD283D04DE08
The code permanently overrides net.Socket.prototype.connect, a core Node.js networking primitive. While it only records the destination address/port and then calls the original implementation, this technique can be abused in a supply-chain context to intercept or redirect arbitrary network connections, and it affects all code running in the process. It is a legitimate pattern used by Turborepo for build-time network access tracing, but it is a high-impact behavior that warrants review.
Use of require with dynamic path
NPS-F2FFA54981D0
createLazyPostCssPlugin wraps require(pluginPath) and require(pluginPath)(options). The pluginPath is resolved at runtime from external configuration, enabling execution of arbitrary npm packages specified in the PostCSS config. Although this is a legitimate feature of the build system, it represents a code execution vector tied to build-time configuration.
Dynamic module loading with computed input
NPS-D23531AA3147
The loadPlugin function calls require.resolve(pluginName, { paths: [dir] }) and then require(pluginPath) or require(pluginPath)(options) where pluginName and pluginPath are derived from user-controlled PostCSS configuration. While this is expected behavior for a PostCSS plugin loader, it means arbitrary modules can be loaded and executed based on config file contents. This is a potential supply-chain risk if a malicious postcss.config.js is present in a project.
Potential SSRF via URL resolution
NPS-55FE3E7D74B0
The plugin resolves URLs found in CSS declarations (via url() and image-set()). It uses options.resolver and options.context to resolve requests, which can lead to network requests if not properly sandboxed. An attacker controlling CSS input could potentially cause the loader to fetch arbitrary URLs, leading to server-side request forgery (SSRF) or information disclosure. However, this is standard behavior for CSS URL handling and not inherently malicious, but it is a security-sensitive operation.
String interpolation into generated code
NPS-FA3096F30A65
The createMetadataExportsCode function interpolates metadata file paths and module import source strings directly into generated JavaScript code using template literals. This is a code generation pattern, and if any interpolated value contained malicious content, it could result in code injection into the generated output. In practice the values are derived from controlled file system enumeration and stringify output, but it represents an injection surface worth noting.
XML Injection / Improper Output Encoding
NPS-AEB737245A53
The resolveSitemap function builds XML output by directly interpolating untrusted input values (item.url, language keys/values, image URLs, video fields such as title, thumbnail_loc, description, content_loc, player_loc, restriction relationship/content, uploader info/content, etc.) without XML-escaping them. If an attacker can control any of these metadata fields (e.g. via route metadata derived from request data), they could inject arbitrary XML elements/attributes into the sitemap, potentially leading to XSS when the sitemap is served/parsed, or to content spoofing and structure corruption of the generated sitemap. Similarly, resolveRobots interpolates rule values directly into robots.txt without sanitization, which could allow header/line injection if values contain newlines.
Dynamic require with computed path
NPS-97509A17E1B6
The loader performs require(fontLoaderPath) where fontLoaderPath is obtained from this.getOptions(). While this is part of Next.js's internal font loading mechanism, dynamically requiring a module based on loader options can be exploited if an attacker can control the loader options. If a malicious webpack configuration or dependency injection occurs, this could allow arbitrary module loading and code execution at build time.
Dynamic module resolution and generation
NPS-4CA8E0ED19E0
The loader dynamically resolves module specifiers using this.getResolve() and rootContext, then generates require() calls with the resolved paths. While this is a legitimate webpack loader pattern, it allows arbitrary module inclusion based on the 'modules' option, which could be exploited if the option is attacker-controlled to load malicious modules.
build-time plugin hook execution
NPS-AD090A258B3B
The plugin uses compiler.hooks.compilation.tap, hooks.renderModuleContent.tap, hooks.render.tap, and hooks.chunkHash.tap to inject code into every rendered module during compilation. Hooks that rewrite module content are a legitimate webpack pattern but represent a powerful mutation point: any consumer of this package grants it the ability to inject arbitrary code into the output bundle. Reviewers should ensure the package is pinned and trusted.
dynamic code execution via eval()
NPS-8D983FA7B4F4
The plugin intentionally emits eval(...) calls into the generated bundle to support webpack's eval-source-map devtool. While this is standard behavior for the devtool and not malicious per se, it creates a code-execution sink: any untrusted content interpolated into content + footer is executed in the browser context. The content originates from webpack's own module sources, and footer is JSON-stringified, so injection is bounded, but the pattern still constitutes dynamic code execution and should be flagged when auditing a third-party package.
dangerouslySetInnerHTML usage
NPS-C67346563039
The component uses React's dangerouslySetInnerHTML to inject previously captured document.documentElement.innerHTML. This bypasses React's XSS protections and could enable HTML/script injection if the captured markup is ever influenced by attacker-controlled content or if the cached snapshot is tampered with in the browser. While intended for error-boundary graceful degradation, it is a notable unsafe rendering pattern.
Unvalidated attribute propagation
NPS-F091332A301B
setAttributesFromProps(el, props) forwards props directly as DOM attributes without visible validation in this file. Combined with the head element injection, untrusted props could set arbitrary attributes (e.g., onerror, nonce, href) enabling script execution or CSP bypass via nonce handling in isEqualNode.
DOM-based XSS via dangerouslySetInnerHTML
NPS-3DCB51CB9712
reactElementToDOM() directly assigns props.dangerouslySetInnerHTML.__html to element.innerHTML. If any component props are influenced by untrusted input (e.g., URL parameters, user content), this can insert arbitrary HTML/scripts into <head> elements such as meta, link, style, or script tags, leading to DOM-based XSS. This is standard React behavior but worth noting for a head manager operating on user-influenced data.
Dynamic script/style element injection into document head
NPS-EDF8534A95DC
updateElements() creates and appends arbitrary 'meta', 'base', 'link', 'style', and 'script' elements to document.head from input components. If callers pass attacker-controlled props (href, src, innerHTML, charset, etc.), this could be abused to load external resources, exfiltrate data via link preloads, or inject scripts.
dynamic module loading
NPS-F854A932780C
The function __turbopack_load_page_chunks__ dynamically loads chunks via __turbopack_load__ using data provided at runtime (chunksData). If an attacker can control the chunksData input (e.g., via server-side rendering or injection), this could lead to loading arbitrary modules. While typical for bundlers, it represents a dynamic code loading surface.
Dynamic script creation and injection into DOM
NPS-225495BE760E
The code creates <script> elements from caller-supplied src/children/dangerouslySetInnerHTML values and appends them to document.body. This is the intended behavior of next/script, but it is a code-execution primitive. If a consumer of this package passes untrusted values, it can load and execute arbitrary remote scripts or inline code.
Dynamic script injection via innerHTML
NPS-4C783C8942B3
The loadScript function assigns el.innerHTML = dangerouslySetInnerHTML.__html directly to a dynamically created script element. If the dangerouslySetInnerHTML prop originates from untrusted input, this enables arbitrary JavaScript execution (XSS). While Next.js documents this prop as dangerous, it is still a code-execution sink that warrants review.
Runtime string interpolation into an inline script tag
NPS-FDC812A2AC3B
For appDir beforeInteractive strategy, the component emits an inline <script> whose content is built with template literals embedding JSON.stringify'd props. htmlEscapeJsonString is applied for escaping, which mitigates XSS, but the pattern of constructing executable script content from runtime props is a high-risk sink that should be treated carefully.
Trusted Types policy bypass
NPS-7ED31E928262
The Trusted Types policy 'nextjs' is created with identity functions for createHTML, createScript, and createScriptURL, effectively disabling the browser's Trusted Types XSS mitigation. Any string passed through this policy will be treated as trusted, which can reintroduce XSS vulnerabilities if untrusted input reaches these sinks.
Security-sensitive exported function
NPS-B61AB5DF867E
__unsafeCreateTrustedScriptURL is exported and explicitly documented as security-sensitive. It promotes arbitrary strings to TrustedScriptURL, and if callers pass attacker-controlled URLs, it can lead to script loading and execution. The fallback to raw strings when Trusted Types are unavailable means the function does not actually enforce any safety.
Dynamic imports with computed paths
NPS-56527C28AE6D
The code uses dynamic import() with paths computed from runtime variables (dir, cacheHandler, and handler values from cacheHandlers). This allows loading of arbitrary modules based on user-controlled configuration. While this is typical Next.js cache handler configuration, it constitutes dynamic module loading with external input and could be exploited if the configuration source is untrusted.
File system manipulation
NPS-B890EDE3A586
The code extracts tar archives to directories outside the package scope (cache directory and node_modules). This is necessary for the package's functionality but could overwrite files if the tar contains malicious paths (zip slip). The tar library used is from next/dist/compiled/tar, presumably safe, but still a risk.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/build/collect-build-traces.js | medium | This appears to be a legitimate Next.js build tracing module with no malicious patterns; the identified concerns are typical of build tooling that manipulates files and reads environment variables but pose only low risk in this context. |
| dist/build/next-config-ts/require-hook.js | medium | This module provides TypeScript require hook support with dynamic code compilation; it is not inherently malicious but introduces dynamic code execution and global module loading modifications that could be risky in untrusted contexts. |
| dist/build/next-config-ts/transpile-config.js | medium | The file is part of Next.js build tooling and intentionally transpiles and executes the project's own next.config.ts; no exfiltration, credential harvesting, obfuscation, or malicious process spawning was detected, though dynamic code execution is inherent to its function. |
| dist/build/route-bundle-stats.js | medium | This is a legitimate Next.js internal bundle-stats module, but it uses dynamic require() of filesystem paths derived from route data and mutates globals, which are patterns that warrant caution though no malicious behavior is evident. |
| dist/build/route-discovery.js | medium | This appears to be legitimate Next.js route discovery code with no clear malicious patterns, though it contains environment-variable-driven build overrides (NEXT_PRIVATE_PAGE_PATHS/NEXT_PRIVATE_APP_PATHS) that warrant monitoring as potential build-injection vectors. |
| dist/build/swc/index.js | medium | This is legitimate Next.js SWC binding loader code, but it exhibits several risky patterns — environment-variable-controlled dynamic requires/imports and runtime download of native binaries — that could be abused if those inputs are attacker-controlled. |
| dist/build/swc/loaderWorkerPool.js | medium | No clear malicious intent, but the file dynamically spawns worker threads using filenames supplied via bindings and mutates global scheduler state, warranting caution if inputs are not validated upstream. |
| dist/build/templates/edge-wrapper.js | medium | The code is a build template for Edge Runtime module wrapping with dynamic import and global state modification, but no direct malicious patterns are evident; the use of placeholders and global pollution presents minor risks if the build process is compromised. |
| dist/build/turborepo-access-trace/env.js | medium | The file implements an environment-variable access-tracking Proxy for Turborepo and contains no exfiltration, code execution, network, or process-spawning logic; the only notable concern is its global mutation of process.env and credential-harvesting potential if the tracked Set were misused by other code. |
| dist/build/turborepo-access-trace/helpers.js | medium | This is Turborepo's legitimate build access tracing helper that proxies environment variables, TCP connections, and filesystem paths for dependency tracking; no malicious patterns detected. |
| dist/build/turborepo-access-trace/tcp.js | medium | The file monkey-patches net.Socket.prototype.connect to record TCP connection destinations into an external array, which is a network-interception pattern that is benign in Turborepo's tracing context but carries inherent risk of connection-target harvesting if misused. |
| dist/build/webpack-build/index.js | medium | This file is Next.js's legitimate webpack build orchestrator; it contains no exfiltration, credential harvesting, obfuscation, or backdoor logic, but it does spawn worker processes with inherited environment variables and dynamically loads a sibling module, which are expected build-tool patterns rather than malicious behavior. |
| dist/build/webpack/alias/react-dom-server.js | medium | The code is a legitimate Next.js shim that conditionally loads React DOM server builds and intentionally disables legacy APIs; no malicious patterns were detected, though environment-dependent module loading is noted as a low-risk observation. |
| dist/build/webpack/config/blocks/css/plugins.js | medium | This is legitimate Next.js PostCSS plugin loading code; it dynamically resolves and requires plugins from user configuration, which is expected but represents a config-driven code execution surface rather than an inherent malicious pattern. |
| dist/build/webpack/loaders/metadata/resolve-route-data.js | medium | No malicious patterns (exfiltration, credential harvesting, eval, process spawning, network access, or install-time execution) were detected; the only security concern is missing XML/HTML/text escaping when interpolating metadata into generated robots.txt and sitemap.xml output, which can permit content injection. |
| dist/build/webpack/loaders/next-edge-function-loader.js | medium | This is a legitimate Next.js webpack loader, but it generates and evaluates code using dynamic build-time inputs (page paths, cache handler paths, base64 config), which could pose a risk if those inputs are compromised. |
| dist/build/webpack/loaders/next-font-loader/index.js | medium | Legitimate Next.js font loader with a dynamic require of a configurable font loader path, which poses a moderate supply-chain risk if the path can be externally controlled. |
| dist/build/webpack/loaders/next-instrumentation-client-loader.js | medium | This appears to be a legitimate Next.js instrumentation loader that dynamically resolves and requires user-configured modules; no exfiltration, credential harvesting, obfuscation, or process spawning is present, but the dynamic require generation based on build options warrants a warning-level note. |
| dist/build/webpack/loaders/next-middleware-loader.js | medium | This is a Next.js webpack middleware loader that decodes base64 configuration and resolves module paths; no clear malicious patterns like exfiltration, credential harvesting, or shell execution are present, but it relies on attacker-controllable build options and dynamic module resolution which warrant low-severity caution. |
| dist/cli/internal/turbo-trace-server.js | medium | The file is a local Turbopack trace/MCP server: it starts a loopback HTTP endpoint and a native trace server handle, with no data exfiltration, credential harvesting, obfuscation, mining, shells, or install-time execution detected, but it has unauthenticated local HTTP exposure and unbounded JSON body parsing that could enable local DoS or DNS-rebinding-style abuse. |
| dist/cli/internal/upload-trace.js | medium | Code intentionally uploads local build trace/profile files to an external Next.js endpoint; appears to be legitimate telemetry but does send user files off-machine. |
| dist/cli/next-dev.js | medium | This appears to be a legitimate Next.js dev server CLI file with expected telemetry, process forking, and trace upload behaviors; no malicious patterns such as credential theft, obfuscation, backdoors, or unauthorized external exfiltration were identified, though telemetry and trace upload to a configurable URL warrant awareness. |
| dist/cli/next-info.js | medium | This file is a legitimate Next.js diagnostic utility that collects system and package information, performs network requests to the npm registry, and spawns version-check commands; no clear malicious patterns such as credential harvesting, exfiltration, or backdoors were found. |
| dist/cli/next-start.js | medium | The code appears to be a legitimate Next.js CLI start script with no malicious patterns, but includes dynamic import of inspector and environment variable manipulation, which are low-risk security considerations. |
| dist/cli/next-test.js | medium | No clear malicious intent detected; findings relate to legitimate but potentially risky operations (dependency installation, process spawning, config file generation) that are standard for the Next.js test CLI. |
Show 1975 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/cli/next-upgrade.js | medium | The file spawns an external process to run '@next/codemod@canary upgrade', which is expected functionality, but the command construction from getNpxCommand and user-supplied options.revision introduces a potential command injection risk if those inputs are not properly validated. |
| dist/client/components/app-router.js | medium | This is a legitimate Next.js App Router client component with expected framework behaviors (history API patching, dynamic conditional requires, dev-mode globals); no data exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns were found, though some patterns warrant low-severity attention. |
| dist/client/components/errors/graceful-degrade-boundary.js | medium | The component relies on dangerouslySetInnerHTML with cached document HTML and reflects DOM attributes, which introduces a moderate XSS/tampering risk despite no direct exfiltration, credential harvesting, or code execution patterns. |
| dist/client/components/layout-router.js | medium | The code is part of Next.js's client-side router and contains no obvious malicious patterns; the findings are low-risk architectural concerns typical of framework internals. |
| dist/client/components/segment-cache/navigation-testing-lock.js | medium | Code implements a testing-only navigation lock with global fetch override and cookie manipulation; no direct exfiltration or malicious payloads, but the global side effects and race conditions merit a warning. |
| dist/client/dev/hot-reloader/app/web-socket.js | medium | This is legitimate Next.js Hot Module Replacement (HMR) client code with standard development-time WebSocket communication, dynamic imports for Turbopack, and no malicious patterns detected; minor warnings are due to dev-only patterns that are normal for HMR infrastructure. |
| dist/client/dev/hot-reloader/pages/hot-reloader-pages.js | medium | This is a legitimate Next.js development hot-reloader client file with standard HMR functionality; the WebSocket communication and dynamic module replacement patterns are expected development tooling behaviors, though they represent inherent development-time attack surface. |
| dist/client/dev/hot-reloader/pages/websocket.js | medium | The code appears to be a legitimate Next.js HMR client, but it constructs WebSocket URLs from configurable options and automatically reloads the page, which could be exploited under certain conditions. |
| dist/client/head-manager.js | medium | The code is part of a legitimate Next.js head manager but contains dangerous DOM injection capabilities (innerHTML, dangerouslySetInnerHTML) and direct head manipulation that could be exploited if untrusted input is passed to it. |
| dist/client/normalize-locale-path.js | medium | The code appears to be a legitimate Next.js internal helper for locale path normalization, with no clear malicious intent, though it uses conditional dynamic require and environment variable checks that warrant low-severity caution. |
| dist/client/request/search-params.browser.js | medium | This appears to be standard transpiled Next.js code that conditionally loads development or production search-params modules based on NODE_ENV, with no evidence of data exfiltration, credential harvesting, obfuscation, or process spawning, though the environment-based dynamic require warrants low-level attention. |
| dist/client/script.js | medium | This appears to be Next.js's legitimate client-side Script loader, but it contains dynamic script injection and dangerouslySetInnerHTML patterns inherent to its design, so verify provenance and treat as elevated-risk supply-chain surface. |
| dist/compiled/@babel/runtime/regenerator/index.js | medium | This is a standard Babel regenerator runtime compatibility shim; it only uses Function() for a deliberate global assignment fallback and shows no signs of exfiltration, credential theft, backdoors, or other malicious behavior. |
| dist/compiled/@edge-runtime/primitives/index.js | medium | The code appears to be a legitimate Edge Runtime primitive loader for WeakRef, but dynamically loads a companion module at import time which cannot be fully verified from this snippet alone. |
| dist/compiled/@edge-runtime/primitives/timers.js.text.js | medium | The module re-exports modified global setTimeout/setInterval via Proxies that coerce the returned Timeout to a primitive, which is suspicious monkey-patching but no clear exfiltration, credential harvesting, or code execution was found. |
| dist/compiled/@mswjs/interceptors/ClientRequest/index.js | medium | This is the genuine @mswjs/interceptors ClientRequest interceptor package; it performs extensive runtime monkey-patching of Node.js HTTP/net/TLS globals for legitimate request interception, with no evidence of data exfiltration, credential harvesting, backdoors, or malicious code execution. |
| dist/compiled/@next/font/dist/google/fetch-css-from-google-fonts.js | medium | The code dynamically loads a module from a path specified by an environment variable, which could allow arbitrary code execution if that variable is attacker-controlled. |
| dist/compiled/@next/font/dist/google/fetch-font-file.js | medium | The code is a legitimate Next.js font fetching utility with a documented mocking feature; no clear malicious patterns, but the env-var-triggered arbitrary file read warrants caution. |
| dist/compiled/@next/font/local/loader.js | medium | The file only performs a static relative require of an internal module; no malicious indicators such as exfiltration, credential harvesting, obfuscation, or process execution were found, though the out-of-directory module load is noted as a minor concern. |
| dist/compiled/@next/react-refresh-utils/dist/loader.js | medium | The loader injects React refresh runtime code into source files, which is expected behavior for a development tool; no malicious patterns were detected. |
| dist/compiled/babel/core-lib-config.js | medium | Wrapper file with no directly observable malicious patterns, but it defers all behavior to a bundled module that cannot be reviewed from this file alone. |
| dist/compiled/babel/core-lib-plugin-pass.js | medium | The file is a simple module re-export that dynamically loads a bundle, which requires further inspection of that bundle to determine safety. |
| dist/compiled/babel/core.js | medium | The file itself is a simple re-export, but its security depends on the unanalyzed './bundle' module, which could contain malicious code. |
| dist/compiled/babel/plugin-syntax-dynamic-import.js | medium | The file is a thin one-line re-export shim with no direct malicious patterns, but it defers all behavior to an unprovided bundle, giving low-confidence risk pending review of that dependency. |
| dist/compiled/babel/types.js | medium | This is a trivial re-export shim that delegates to './bundle' with no direct malicious indicators, but its behavior depends entirely on the unreviewed bundle file. |
| dist/compiled/browserslist/index.js | medium | This is a webpack-bundled copy of the legitimate 'browserslist' library; no exfiltration, backdoors, or malicious payloads were found, but it does contain dynamic eval/require patterns and reads environment variables and config files as part of its normal operation. |
| dist/compiled/cross-spawn/index.js | medium | This is the legitimate cross-spawn npm package (bundled with ncc) that provides cross-platform child process spawning; it contains standard process spawning, environment variable, and filesystem access expected of such a utility, but no malicious exfiltration, obfuscation, or backdoor patterns were detected. |
| dist/compiled/httpxy/index.js | medium | This is a legitimate httpxy/http-proxy-style library with no malicious code, but it exhibits typical proxy-library risks (SSRF, header injection, credential forwarding on redirects) that require careful caller-side validation. |
| dist/compiled/image-detector/detector.js | medium | This is a benign image-dimension detection library with no network, credential, obfuscation, or process-spawning behavior; the only notable concerns are caller-controlled fs access in the TIFF handler and parser robustness against malformed input. |
| dist/compiled/jest-worker/processChild.js | medium | This appears to be a legitimate jest-worker child process implementation that uses eval-based require and IPC message-driven dynamic function execution; no clear malicious intent (no exfiltration, credential harvesting, network calls, or backdoors), but the dynamic code execution patterns warrant a warning. |
| dist/compiled/jest-worker/threadChild.js | medium | This appears to be legitimate jest-worker threadChild code (webpack bundled), but it uses eval('require') for dynamic module loading and executes functions based on parent process messages, which are inherent risks in worker architectures. |
| dist/compiled/loader-runner/LoaderRunner.js | medium | This is the standard webpack loader-runner compiled bundle; it uses eval for dynamic ESM imports and require for loading arbitrary loaders, which are expected behaviors but carry inherent dynamic code execution risk if inputs are untrusted. |
| dist/compiled/mini-css-extract-plugin/loader.js | medium | This appears to be the legitimate mini-css-extract-plugin loader bundle; it contains dynamic module compilation (expected for its function), a stray debug console.log, and computed require paths, but no clear exfiltration, credential harvesting, backdoor, or process-spawning behavior was detected. |
| dist/compiled/react-experimental/cjs/react.development.js | medium | This appears to be the legitimate React development build with expected dev-mode behaviors; no clear exfiltration, credential harvesting, obfuscated payloads, or backdoors were identified, though a few dynamic loading patterns and global error reporting paths are noted as low-risk observations. |
| dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-node-register.js | medium | This is the official Meta React Server DOM Webpack Node register hook; it contains no exfiltration, credential harvesting, obfuscation, or shell execution, but its monkey-patching of Module.prototype._compile and directive-based runtime branching are invasive patterns worth noting as medium-risk behavior rather than outright malicious code. |
| dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-node-register.js | medium | This is the official Meta React Server DOM Webpack Node register hook; it contains no exfiltration, credential harvesting, obfuscation, or shell execution, but its monkey-patching of Module.prototype._compile and directive-based runtime branching are invasive patterns worth noting as medium-risk behavior rather than outright malicious code. |
| dist/compiled/regenerator-runtime/runtime.js | medium | This is the legitimate Facebook regenerator-runtime polyfill; it contains no malicious patterns, though its use of the Function constructor as a strict-mode escape hatch and its global assignment are minor security-relevant observations. |
| dist/compiled/sass-loader/cjs.js | medium | The file appears to be the legitimate sass-loader compiled output, but it uses dynamic require/eval patterns and environment variables that could pose limited risk if untrusted configuration or module resolution is involved. |
| dist/compiled/setimmediate/setImmediate.js | medium | The file is a standard setImmediate polyfill but contains a dynamic code execution pattern (new Function) that could be exploited if user-controlled input is passed. |
| dist/compiled/timers-browserify/main.js | medium | This appears to be a standard browserify timer polyfill with no obvious malicious patterns, but uses Function constructor and dynamic require which warrant low-severity review. |
| dist/compiled/vm-browserify/index.js | medium | This is a legitimate vm-browserify shim that implements a browser-based VM with eval-based code execution; no malicious exfiltration, credential harvesting, or backdoor patterns were found, but its inherent use of dynamic code execution warrants caution. |
| dist/compiled/webpack/lazy-compilation-node.js | medium | This is legitimate webpack lazy-compilation runtime code making a dynamic HTTP request for HMR; no malicious patterns, credential theft, shell execution, or obfuscation were found. |
| dist/esm/build/adapter/build-complete.js | medium | This file is legitimate Next.js build orchestration code, but it dynamically imports an external adapter module and hands it extensive build artifacts, paths, and preview tokens; the risk is inherent to the adapter mechanism rather than malicious code. |
| dist/esm/build/after-production-compile.js | medium | This Next.js build utility executes user-configured code after production builds and emits telemetry; it contains no evident malicious patterns but does perform dynamic code execution driven by configuration. |
| dist/esm/build/load-jsconfig.js | medium | No malicious patterns detected; the code is a legitimate Next.js build utility that loads TypeScript/JavaScript configuration files, with dynamic require patterns that are expected for this functionality. |
| dist/esm/build/next-config-ts/require-hook.js | medium | The code is a legitimate require hook for transpiling TypeScript and ESM files using swc, but it modifies global Node.js module loading behavior and executes dynamically transformed code, which could be exploited if the package or its configuration is compromised. |
| dist/esm/build/next-config-ts/transpile-config.js | medium | The code performs dynamic code execution and module loading based on a config file path, which is a potential security risk if the path is attacker-controlled, but no clear malicious patterns like data exfiltration or backdoors were found. |
| dist/esm/build/preview-key-utils.js | medium | The code generates and stores cryptographic keys in plaintext files without apparent malicious intent, but the storage mechanism poses a moderate security risk. |
| dist/esm/build/route-bundle-stats.js | medium | The code appears to be a legitimate build-time utility for collecting route bundle statistics in a Next.js project, with minor security concerns around dynamic require of constructed paths and global variable manipulation. |
| dist/esm/build/route-discovery.js | medium | This appears to be legitimate Next.js internal route-discovery code, but uses environment-variable-controlled path overrides and hardcoded dynamic require.resolve calls that warrant minor scrutiny. |
| dist/esm/build/swc/loaderWorkerPool.js | medium | No direct exfiltration, credential theft, obfuscation, or shell execution, but dynamic worker creation from external input and global worker pool management introduce potential risk if inputs are not trusted. |
| dist/esm/build/templates/edge-wrapper.js | medium | The code is a standard edge runtime wrapper that dynamically imports a module and exposes its exports through a thenable Proxy; while it uses dynamic import and top-level side effects, no malicious patterns like data exfiltration or backdoors are present. |
| dist/esm/build/turborepo-access-trace/env.js | medium | The file implements an environment variable access-tracking Proxy for build instrumentation; it contains no exfiltration, credential file access, dynamic execution, or network activity, but it globally intercepts process.env which is a moderate information-gathering concern if misused. |
| dist/esm/build/turborepo-access-trace/tcp.js | medium | This is a legitimate-looking TCP connect tracer used by Turborepo to detect network access during builds; it monkey-patches net.Socket.prototype.connect to log destinations but does not exfiltrate data, harvest credentials, execute dynamic code, or spawn processes. |
| dist/esm/build/webpack/config/blocks/css/index.js | medium | This is a legitimate Next.js webpack CSS configuration module; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected, though dynamic module resolution and environment variable usage are present as expected build-time behaviors. |
| dist/esm/build/webpack/config/blocks/css/plugins.js | medium | This file is a legitimate Next.js PostCSS plugin loader with dynamic require() calls driven by user configuration, which is expected but carries inherent supply-chain risks typical of build tooling. |
| dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-url-parser.js | medium | The code appears to be a legitimate PostCSS plugin for parsing URLs in CSS, but it includes dynamic module resolution and URL fetching capabilities that could be security-sensitive if misused, though no direct malicious patterns were found. |
| dist/esm/build/webpack/loaders/metadata/discover.js | medium | The code is a legitimate Next.js build-time metadata discovery module; it uses dynamic imports and string interpolation of file paths into generated code, which are typical for a webpack loader but represent low-to-medium injection surface if upstream inputs are untrusted. |
| dist/esm/build/webpack/loaders/metadata/resolve-route-data.js | medium | No malicious behavior (exfiltration, code execution, backdoors, credential harvesting, process spawning, or install-time hooks) was found; the code is a straightforward metadata-to-text/XML serializer, though it lacks output encoding that could enable XML/robots.txt injection if inputs are attacker-controlled. |
| dist/esm/build/webpack/loaders/next-font-loader/index.js | medium | This is a legitimate Next.js internal webpack loader for font processing; the dynamic require and path resolution are part of its normal operation, but could be abused if an attacker controls loader options or the resource query. |
| dist/esm/build/webpack/loaders/next-instrumentation-client-loader.js | medium | This is a legitimate Next.js webpack loader for client instrumentation; no malicious patterns like data exfiltration, credential harvesting, or code execution were found, but dynamic module resolution warrants caution if options are untrusted. |
| dist/esm/build/webpack/plugins/eval-source-map-dev-tool-plugin.js | medium | This is a forked webpack EvalSourceMapDevToolPlugin that legitimately uses eval/createScript and base64 source-map data URIs as part of the eval-source-map devtool; no exfiltration, credential harvesting, process spawning, or backdoor behavior is present. |
| dist/esm/build/worker.js | medium | This appears to be a legitimate Next.js worker build file with benign top-level imports and environment variable usage; no malicious patterns such as exfiltration, obfuscation, process spawning, or backdoor installation were detected. |
| dist/esm/client/app-dir/link.js | medium | This is legitimate Next.js Link component code with only minor patterns (dynamic require, location.replace with local-URL guard) that are not indicative of malicious activity. |
| dist/esm/client/app-globals.js | medium | This is legitimate Next.js client bootstrap code with environment-gated dynamic requires and import-time side effects, but no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious patterns. |
| dist/esm/client/components/app-router.js | medium | This is a legitimate Next.js App Router client component that patches browser history APIs, installs global event handlers, and dynamically requires internal modules, but contains no clear data exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns. |
| dist/esm/client/components/errors/graceful-degrade-boundary.js | medium | The code is a legitimate-looking React error boundary for graceful degradation, but it uses dangerouslySetInnerHTML and captures/reapplies full document HTML attributes, which are unsafe rendering patterns worth flagging. |
| dist/esm/client/components/links.js | medium | This is a legitimate Next.js client-side link prefetching module with no malicious patterns; minor warnings are due to dynamic require() calls and browser API usage that are expected for this functionality. |
| dist/esm/client/detect-domain-locale.js | medium | The file contains a benign Next.js feature-flag pattern using environment variable gating and a hardcoded relative dynamic require; no malicious behavior detected, but dynamic require and env-based execution warrant low-severity notice. |
| dist/esm/client/dev/hot-reloader/app/web-socket.js | medium | The file contains standard Hot Module Replacement (HMR) WebSocket client logic for Next.js development; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning were detected. |
| dist/esm/client/head-manager.js | medium | The file is part of Next.js head manager and contains no clear malicious intent, but it performs DOM operations (innerHTML, script/style/meta/link injection into document.head) that could enable XSS if untrusted data reaches component props. |
| dist/esm/client/next-turbopack.js | medium | The code appears to be a legitimate Next.js Turbopack client entry point with dynamic chunk loading, but no clear malicious patterns such as exfiltration, credential harvesting, or backdoors were detected. |
| dist/esm/client/react-client-callbacks/error-boundary-callbacks.js | medium | This appears to be a legitimate Next.js internal error-boundary callback module; no clear malicious behavior (no exfiltration, credential harvesting, obfuscation, or process spawning) was detected, though it uses dynamic dev-only require and error reporting hooks that merit routine scrutiny. |
| dist/esm/client/request/params.browser.js | medium | The code uses environment-based conditional require to load one of two static modules, which is a benign pattern but carries minor risk due to dynamic loading and ESM/CJS mixing. |
| dist/esm/client/request/search-params.browser.js | medium | Code conditionally loads modules based on NODE_ENV; this is a typical pattern but relies on environment variable control, posing a low risk if the environment is compromised. |
| dist/esm/client/script.js | medium | This is the legitimate Next.js next/script client runtime; it contains expected dynamic script-injection primitives (innerHTML, DOM script appending, inline script emission) that are code-execution sinks but are consistent with the component's documented purpose and contain no exfiltration, credential harvesting, obfuscation, or process-spawning malicious patterns. |
| dist/esm/client/trusted-types.js | medium | This Next.js Trusted Types helper intentionally implements a no-op Trusted Types policy and exports a documented unsafe string-to-TrustedScriptURL promotion function, weakening XSS protections rather than containing classic malicious code. |
| dist/esm/client/webpack.js | medium | The code monkey-patches webpack internals to append a deployment ID query string to chunk filenames; while it modifies module/asset loading behavior and exposes a global public-path setter without validation, no exfiltration, credential harvesting, or obfuscated payloads were found. |
| dist/esm/export/helpers/create-incremental-cache.js | medium | This appears to be legitimate Next.js incremental cache setup code, but it uses dynamic imports with computed paths from configuration which could load arbitrary modules if the configuration is attacker-controlled. |
| dist/esm/lib/download-swc.js | medium | The code downloads and extracts SWC binaries from a registry, which is expected for Next.js, but it involves network requests and file system operations outside the package scope, posing moderate risk if the registry or tar contents are compromised. |
| dist/esm/lib/find-config.js | medium | The code dynamically discovers and executes local configuration files, which is a legitimate pattern but introduces a code execution surface if the search path or key is attacker-controlled; no data exfiltration, credential harvesting, obfuscation, or network exfiltration was detected. |
| dist/esm/lib/helpers/get-npx-command.js | medium | The file contains a benign use of execSync to probe yarn dlx availability, with no malicious patterns detected, though child process execution warrants low-severity caution. |
| dist/esm/lib/helpers/get-online.js | medium | The code performs expected network and proxy checks with minor process spawning, but no malicious patterns are evident. |
| dist/esm/lib/helpers/get-pkg-manager.js | medium | The code is a standard package manager detection utility with minor process execution that is not overtly malicious, but execSync calls make it a low-severity concern. |
| dist/esm/lib/helpers/get-registry.js | medium | The code executes the detected package manager's config command to read the registry URL, which is a legitimate but potentially risky pattern if the package manager name is attacker-controlled; no clear malicious intent, but medium risk due to shell execution. |
| dist/esm/lib/helpers/git.js | medium | Purpose-built git branch/commit helper that uses execSync with hardcoded arguments; no exfiltration, backdoor, or obfuscation found, but the generic args shell interpolation is a latent injection risk if reused. |
| dist/esm/lib/helpers/install.js | medium | The code is a legitimate package manager installation helper that spawns npm, pnpm, or yarn with user-provided dependencies; no clear malicious patterns were detected, but it does execute processes with input that should be validated to prevent command injection. |
| dist/esm/lib/memory/startup.js | medium | This Next.js memory debugging module is not malicious but enables heap snapshot generation via SIGUSR2 and near memory limits, which could expose sensitive in-memory data to disk if the module is enabled in production. |
| dist/esm/lib/mkcert.js | medium | The code downloads and executes a remote binary without integrity checks and uses shell commands with dynamic input, posing security risks. |
| dist/esm/lib/patch-incorrect-lockfile.js | medium | The code is a legitimate Next.js lockfile patcher but performs unverified network fetches driven by registry configuration and rewrites package-lock.json with fetched tarball/integrity data, creating a supply-chain tampering risk if the registry or network is compromised. |
| dist/esm/lib/recursive-copy.js | medium | The code performs recursive file copying with potential path traversal and symlink following risks, but no clear malicious patterns were detected. |
| dist/esm/lib/turbopack-warning.js | medium | The file appears to be legitimate Next.js Turbopack warning/validation code with no exfiltration, obfuscation, shell execution, or credential harvesting; only minor low-severity dynamic loading and process.exit behaviors are present. |
| dist/esm/lib/verify-partytown-setup.js | medium | The code performs legitimate Next.js build-time operations for Partytown integration, including dynamic module loading and file system cleanup, but carries low-to-medium risk due to dynamic require and recursive deletion. |
| dist/esm/lib/verify-typescript-setup.js | medium | This is legitimate Next.js TypeScript verification code with expected dynamic require, auto-install, and file-writing behaviors; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors detected. |
| dist/esm/next-devtools/server/attach-nodejs-debugger-middleware.js | medium | The middleware intentionally exposes the Node.js inspector debugger endpoint, which if reachable outside a trusted local development environment can lead to remote code execution and credential/data theft. |
| dist/esm/next-devtools/server/devtools-config-middleware.js | medium | Dev-server middleware exposes an unauthenticated local POST endpoint that buffers unbounded input and writes user-controlled JSON to a cache file, presenting DoS and potential prototype-pollution concerns but no clear exfiltration, credential theft, or code-execution payloads. |
| dist/esm/next-devtools/server/launch-editor.js | medium | The code is part of Next.js devtools for launching editors and contains legitimate process spawning and environment variable usage, but lacks robust input sanitization in some paths, posing a moderate security risk if misused. |
| dist/esm/next-devtools/server/restart-dev-server-middleware.js | medium | The code implements Next.js dev-server restart and status endpoints; it contains no data exfiltration, credential harvesting, obfuscation, or backdoor patterns, but exposes unauthenticated process termination and cache-invalidation capabilities that could cause denial of service if the dev server were exposed. |
| dist/esm/next-devtools/userspace/app/forward-logs.js | medium | Code appears to be legitimate Next.js devtools log forwarding, but it intercepts console/error output and transmits serialized runtime data over a WebSocket, which could leak sensitive information if enabled outside trusted development contexts. |
| dist/esm/next-devtools/userspace/pages/pages-dev-overlay-setup.js | medium | This appears to be legitimate Next.js devtools code that installs a pages dev overlay and global error handlers; no clear malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or backdoors were detected. |
| dist/esm/server/api-utils/get-cookie-parser.js | medium | No malicious patterns detected; the code performs standard cookie parsing with a benign runtime require of an internal Next.js module. |
| dist/esm/server/api-utils/node/api-resolver.js | medium | The file contains legitimate Next.js API resolver logic with some inherent risks around header forwarding and network requests, but no clear malicious patterns or backdoors. |
| dist/esm/server/api-utils/node/try-get-preview-data.js | medium | The code is part of Next.js's legitimate preview mode handling, but it contains weak validation (dev-mode fallback), dynamic requires of internal modules, and JSON parsing of decrypted cookie data without strict type checks, which could be exploited in misconfigured deployments. |
| dist/esm/server/app-render/action-handler.js | medium | This is legitimate Next.js internal Server Actions handling code that performs intentional internal worker forwarding, with no malicious exfiltration, credential harvesting, obfuscated payloads, or backdoors, but it does include outbound fetch requests driven by request-derived origin/host metadata that warrant defensive scrutiny against SSRF and header/cookie leakage. |
| dist/esm/server/app-render/app-render-render-utils.js | medium | The code is part of Next.js's rendering utilities and does not contain malicious patterns, but it calls an explicitly dangerous internal function for flushing immediates, which warrants caution. |
| dist/esm/server/app-render/app-render-scheduling.js | medium | The code is a Next.js internal workaround that monkey-patches Node.js timer internals to guarantee atomic timer groups; it contains no exfiltration, credential harvesting, dynamic code execution, network, or process-spawning behavior, though its reliance on private timer fields is a fragile practice worth noting. |
| dist/esm/server/app-render/debug-channel-server.js | medium | This file contains no malicious patterns; it is a legitimate debug channel switcher for Next.js that conditionally loads Node or Web implementations based on an environment variable, with production safeguards. |
| dist/esm/server/app-render/encryption-utils-server.js | medium | The code is a legitimate Next.js encryption utility that manages encryption keys for server actions; no malicious patterns were detected, but it does handle sensitive encryption keys and environment variables. |
| dist/esm/server/app-render/entry-base.js | medium | No clear malicious behavior was identified; the file contains standard Next.js internal re-exports and environment-conditional requires that are low-risk but warrant review. |
| dist/esm/server/app-render/instant-test-bootstrap.js | medium | The file contains no data exfiltration, credential harvesting, obfuscation, miner, or process-spawning behavior; it generates a cookie-gated same-origin RSC prefetch inline script, which is a minor concern due to inline script generation and automatic fetch but consistent with its documented purpose. |
| dist/esm/server/dev/dev-validation-worker-pool.js | medium | Legitimate Next.js dev-server validation worker code with expected dynamic module loading, worker spawning, and env propagation; no malicious patterns, exfiltration, or credential harvesting detected. |
| dist/esm/server/dev/get-source-map-from-file.js | medium | This is legitimate Next.js internals for reading source maps, but it resolves user/file-controlled sourceMappingURL paths without sanitization, allowing potential out-of-scope file reads. |
| dist/esm/server/dev/hot-reloader-shared-utils.js | medium | The code is a benign Next.js hot-reloader utility that checks version information via a fixed public npm registry endpoint; no malicious patterns were detected. |
| dist/esm/server/dev/hot-reloader-webpack.js | medium | This is legitimate Next.js dev-server hot-reloader code with no evident malware, but it includes powerful dev-only features (inspector fetch, CORS reflection, debugger attach middleware, unauthenticated WebSocket HMR) that could be dangerous if the dev server is exposed beyond localhost. |
| dist/esm/server/dev/middleware-webpack.js | medium | This is a Next.js webpack dev-tools middleware file; no overt malicious code (exfiltration, credential theft, obfuscation, backdoors, miners) is present, but it exposes unauthenticated dev-server endpoints that can launch editors with user-controlled paths, which could enable process spawning or path traversal if reachable. |
| dist/esm/server/dev/on-demand-entry-handler.js | medium | This is legitimate Next.js development server code with no overt malicious patterns, though it handles unauthenticated HMR WebSocket messages and includes MCP handler dispatch that warrants caution in untrusted dev environments. |
| dist/esm/server/dev/use-cache-probe-pool.js | medium | Code is a legitimate Next.js dev-only 'use cache' hang-detection probe pool; no exfiltration, credential harvesting, obfuscation, or shell execution detected, though it spawns workers with inherited env and computes worker paths dynamically. |
| dist/esm/server/lib/app-info-log.js | medium | Code appears to be legitimate Next.js startup logging with minor file-write side effects (agent rules generation) and env file path enumeration, no clear malicious behavior detected. |
| dist/esm/server/lib/cpu-profile.js | medium | The code is a legitimate CPU profiling utility for Next.js, but it reads environment variables to determine file write paths without sanitization or containment, presenting a low-to-medium arbitrary file write risk if those environment variables are attacker-controlled. |
| dist/esm/server/lib/module-loader/node-module-loader.js | medium | This appears to be a legitimate Next.js runtime module loader, but it performs dynamic module loading with require()/__non_webpack_require__() and conditionally branches on environment variables, which warrants monitoring if the loaded module id can be influenced externally. |
| dist/esm/server/lib/module-loader/route-module-loader.js | medium | No overtly malicious behavior, but the loader dynamically imports a caller-controlled module id through an injectable loader, a potential arbitrary module loading/execution risk that warrants review of the underlying NodeModuleLoader and callers. |
| dist/esm/server/lib/render-server.js | medium | The code is part of Next.js internals and contains a potential dynamic import from an environment variable in test mode, but no overtly malicious patterns were found. |
| dist/esm/server/lib/router-utils/resolve-routes.js | medium | This is a standard Next.js internal router utility file; it contains no malicious patterns such as exfiltration, credential theft, obfuscation, or backdoor behavior, though it includes minor trust-boundary considerations around proxy headers and test-gated file reads. |
| dist/esm/server/lib/router-utils/setup-dev-bundler.js | medium | This appears to be legitimate Next.js development bundler code with no evidence of malicious intent; findings are limited to normal framework behaviors like dynamic requires, env var reads, and telemetry. |
| dist/esm/server/lib/start-server.js | medium | This appears to be legitimate Next.js server startup code with a minor medium-risk shell command interpolation concern in getProcessIdUsingPort and several low-risk patterns typical of a development server. |
| dist/esm/server/load-components.js | medium | The file is part of Next.js internal server-side code that loads manifests and page modules dynamically; while it uses eval-like manifest evaluation and computed path module loading, these are expected patterns for this framework and no clear malicious intent (exfiltration, backdoors, credential harvesting) is present. |
| dist/esm/server/load-manifest.external.js | medium | The code executes manifest files as JavaScript via vm.runInNewContext, which is a potential sandbox escape vector if manifest contents are attacker-controlled, but no immediate malicious patterns are present. |
| dist/esm/server/mcp/get-or-create-mcp-server.js | medium | The file itself contains no overt malicious patterns such as exfiltration, shell execution, or obfuscation, but it exposes a privileged MCP server with filesystem path forwarding and dev-server control tools that could pose security risks if exposed or if the underlying tool implementations lack input validation. |
| dist/esm/server/mcp/mcp-telemetry-tracker.js | medium | Code is a benign telemetry counter, but it contains a runtime require() for an internal telemetry events module that warrants inspection of the referenced file. |
| dist/esm/server/mcp/tools/get-project-metadata.js | medium | No clear malicious patterns found, but the file records telemetry on each tool invocation and returns the local project path, which should be reviewed in context of the telemetry tracker implementation. |
| dist/esm/server/mcp/tools/get-routes.js | medium | The code is a legitimate MCP tool for scanning Next.js route files; no malicious exfiltration, credential harvesting, obfuscation, or command execution patterns were detected, though it does perform intentional filesystem scanning and internal telemetry tracking. |
| dist/esm/server/node-environment-baseline.js | medium | The code performs top-level global object modifications and lazy module loading via require(), which are not overtly malicious but represent potential attack surfaces for supply chain compromise. |
| dist/esm/server/node-environment-extensions/console-file.js | medium | The code patches console methods to mirror output to a file logger during development; while not overtly malicious, it introduces a data persistence mechanism that could leak sensitive console output if the log file is not properly secured. |
| dist/esm/server/node-environment-extensions/fast-set-immediate.external.js | medium | Legitimate Next.js internal module that globally monkey-patches Node.js timer/nextTick primitives at import time, which is invasive but not malicious; no exfiltration, credential theft, dynamic code execution, or shell commands were found. |
| dist/esm/server/node-environment-extensions/node-crypto.js | medium | The code is a legitimate Next.js instrumentation patch that wraps node:crypto functions to track dynamic IO during prerendering; no malicious exfiltration, backdoor, or process-spawning patterns were found, though the import-time monkey-patching is a notable behavioral concern. |
| dist/esm/server/node-environment-extensions/process-error-handlers.js | medium | No data exfiltration, credential harvesting, obfuscation, or backdoor patterns detected, but the code intentionally overrides Node.js process-level error handling by removing all uncaughtException and unhandledRejection listeners, which is a potentially risky global side effect. |
| dist/esm/server/node-environment-extensions/unhandled-rejection.external.js | medium | The code is not overtly malicious (no exfiltration, exec, or credential harvesting), but it aggressively monkey-patches Node.js process error-handling methods at import time to selectively suppress unhandled rejections, which is an invasive and potentially fragile practice that warrants scrutiny. |
| dist/esm/server/node-environment-extensions/web-crypto.js | medium | The file is framework instrumentation that transparently wraps crypto.getRandomValues and crypto.randomUUID for prerender IO tracking; it contains no exfiltration, credential harvesting, obfuscation, or process spawning, but does monkey-patch global Web Crypto APIs which warrants caution. |
| dist/esm/server/node-polyfill-crypto.js | medium | No malicious behavior detected, but the code mutates globalThis.crypto at import time and exposes a settable, configurable global property that could be overwritten by other code, weakening cryptographic trust boundaries on affected Node.js versions. |
| dist/esm/server/post-process.js | medium | The code is a legitimate Next.js server utility for HTML post-processing with CSS optimization; it uses standard patterns with no clear malicious intent, though dynamic require and env var usage are noted as minor concerns. |
| dist/esm/server/render-result.js | medium | This is legitimate Next.js internal code for handling render results with no malicious patterns; the dynamic require and environment variable access are standard framework patterns. |
| dist/esm/server/require-hook.js | medium | This file is a legitimate Next.js require-hook that patches Node module resolution, but its monkey-patching of require and _resolveFilename represents a powerful, high-risk pattern that could be repurposed or abused if the package or its dependencies were compromised. |
| dist/esm/server/require.js | medium | The code appears to be standard Next.js server-side page loading logic with dynamic requires and file system access, but no clear malicious patterns like data exfiltration or credential harvesting were found. |
| dist/esm/server/route-matcher-providers/helpers/manifest-loaders/node-manifest-loader.js | medium | This Next.js manifest loader dynamically requires files based on a constructed path; while it appears to be a legitimate internal helper, the lack of path validation on the 'name' input poses a potential arbitrary module loading risk if inputs are not strictly controlled upstream. |
| dist/esm/server/route-modules/app-page/module.render.js | medium | The file is a benign Next.js internal lazy-render helper; no data exfiltration, credential harvesting, obfuscation, network access, process spawning, or install-time execution was found, though it does use runtime require for an internal compiled module. |
| dist/esm/server/route-modules/route-module.js | medium | This file is a legitimate Next.js internal module handling route preparation, manifest loading, and cache setup; no exfiltration, credential theft, backdoors, or obfuscation patterns were found, though it does contain dynamic module loading and eval-based manifest loading that are controlled by configuration. |
| dist/esm/server/web/adapter.js | medium | This is a legitimate Next.js middleware adapter file with no evident malicious intent; the only notable concerns are a dynamic require gated by an environment variable and header/rewrite propagation behavior that could theoretically leak information if misconfigured. |
| dist/esm/server/web/get-edge-preview-props.js | medium | This file is a benign Next.js edge-runtime helper that reads preview mode environment variables; no exfiltration, obfuscation, process spawning, or other malicious patterns are present in the provided code. |
| dist/esm/server/web/sandbox/context.js | medium | The code is part of Next.js edge runtime sandboxing and uses dynamic code execution, environment variable exposure, and file system access, but these are inherent to its sandboxing purpose and not overtly malicious. |
| dist/esm/server/web/sandbox/fetch-inline-assets.js | medium | The code lacks proper path validation when resolving file paths from user-controlled 'blob:' URLs, potentially allowing path traversal and unauthorized file reads. |
| dist/esm/server/web/sandbox/sandbox.js | medium | The code contains several low-to-medium risk patterns related to sandbox context manipulation and dynamic evaluation, but no clear malicious intent or data exfiltration was detected. |
| dist/esm/shared/lib/bloom-filter.js | medium | The file implements a standard Bloom filter with no exfiltration, credential harvesting, obfuscation, or command execution; only minor concerns around conditional dynamic require, environment variable usage, and unvalidated import data. |
| dist/esm/shared/lib/image-blur-svg.js | medium | No exfiltration, credential harvesting, obfuscation, network, or process-spawning code is present, but the function builds an SVG string via unescaped string interpolation of caller-controlled values (notably blurDataURL), creating a potential injection vector. |
| dist/esm/shared/lib/router/utils/middleware-route-matcher.js | medium | No malicious exfiltration, credential harvesting, or backdoor patterns detected, but the code compiles and executes externally-supplied regex patterns dynamically, which could pose a ReDoS or input-validation risk depending on how matchers are sourced. |
| dist/esm/shared/lib/router/utils/path-match.js | medium | The file is a legitimate Next.js path-matching utility with no clear malicious behavior, but it has minor security considerations around dynamic regex construction and object spreading that could be abused by untrusted input. |
| dist/esm/shared/lib/size-limit.js | medium | No clearly malicious behavior identified; only a minor concern about dynamic require() usage in an ESM module. |
| dist/experimental/testmode/fetch.js | medium | The file is part of Next.js experimental test-mode fetch interception and does not exhibit overt malicious behavior, but it globally monkey-patches fetch and forwards full request details (including credentials and headers) to a local proxy, which could be abused if the proxy endpoint is compromised or misconfigured. |
| dist/experimental/testmode/playwright/next-fixture.js | medium | No overt malicious code such as exfiltration, credential harvesting, obfuscation, or process spawning was found; however, the module's wildcard route interception and configurable fetch loopback behavior are test-mode capabilities that should be vetted before inclusion in non-test environments. |
| dist/experimental/testmode/playwright/next-worker-fixture.js | medium | The file implements a scoped local proxy server for Next.js testmode with no clear malicious behavior, though the runtime-registered proxy handlers represent a minor attack surface. |
| dist/experimental/testmode/playwright/page-route.js | medium | Test-mode Playwright route handler that proxies cross-origin fetch requests and manipulates headers; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution were detected, but the proxying behavior warrants caution. |
| dist/experimental/testmode/proxy/server.js | medium | The file implements a test-mode HTTP proxy server that binds to all network interfaces and forwards fetch requests without apparent target restrictions, creating network exposure and potential SSRF/DoS concerns, though no overtly malicious (exfiltration, credential theft, RCE) patterns are present. |
| dist/export/helpers/create-incremental-cache.js | medium | The code contains dynamic imports with user-influenced paths and global state modification, which pose moderate security risks if inputs are not properly validated. |
| dist/lib/download-swc.js | medium | No overt malicious patterns (no exfiltration, credential harvesting, or shell execution) were found, but the script downloads and extracts remote tarballs without integrity verification, posing a supply-chain risk. |
| dist/lib/find-config.js | medium | This is a legitimate configuration file loader from Next.js that dynamically imports config files found via directory traversal, which carries inherent code-execution risk if malicious config files are planted in parent directories, but contains no overtly malicious patterns. |
| dist/lib/helpers/get-cache-directory.js | medium | The code appears to be a legitimate cache directory resolver, but it uses environment variables and file system checks that could be exploited if the module is used in a malicious context, though no overt malicious patterns are present. |
| dist/lib/helpers/get-npx-command.js | medium | The file contains child_process.execSync usage and returns shell command strings for package manager invocation, which are low-to-medium risk patterns in isolation but could become dangerous if combined with untrusted input downstream. |
| dist/lib/helpers/get-online.js | medium | The code appears to be a legitimate helper for checking online status and proxy configuration, with only minor concerns around shell command execution and environment variable access. |
| dist/lib/helpers/get-pkg-manager.js | medium | No malicious patterns detected; the code performs standard package manager detection using environment variables, lockfile checks, and version commands, with only minor shell execution concerns. |
| dist/lib/helpers/get-registry.js | medium | The code executes a shell command to retrieve the npm registry, using a package manager name derived from project files, which could theoretically enable command injection if that name is attacker-controlled; otherwise it appears to be a legitimate Next.js helper. |
| dist/lib/helpers/install.js | medium | The code is a legitimate helper for spawning package manager install commands, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors, though it does spawn processes based on caller-provided dependency names. |
| dist/lib/inline-static-env.js | medium | This appears to be a legitimate Next.js build-time utility that inlines static environment variables into client and server bundles; no exfiltration, credential harvesting, dynamic code execution, or backdoor patterns were found, though the broad file rewriting and env inlining behavior should be understood by consumers. |
| dist/lib/memory/startup.js | medium | Legitimate memory debugging code for Next.js that modifies V8 flags, registers a SIGUSR2 handler, and generates heap snapshots, with no malicious patterns detected but minor security considerations around heap snapshot data exposure. |
| dist/lib/mkcert.js | medium | Legitimate mkcert wrapper, but contains shell-exec of a downloaded binary with unverified integrity and unsanitized host interpolation. |
| dist/lib/patch-incorrect-lockfile.js | medium | The file performs legitimate-looking lockfile patching for @next/swc packages, but includes outbound network fetches, external lockfile mutation, and dynamic registry resolution that warrant caution despite no overtly malicious payloads. |
| dist/lib/require-instrumentation-client.js | medium | The file is a benign Next.js internal loader that requires an aliased instrumentation module at import time; no exfiltration, credential harvesting, obfuscation, process spawning, or network activity is present, though the resolved module's behavior cannot be audited from this file alone. |
| dist/lib/turbopack-warning.js | medium | No malicious patterns (exfiltration, credential theft, obfuscation, shells, mining) found; only benign Next.js Turbopack configuration validation with a forced process.exit(1) and environment-variable-gated behavior typical of the framework. |
| dist/lib/typescript/runTypeScriptCli.js | medium | The code spawns the TypeScript CLI via cross-spawn with array arguments and shell disabled, performs signal-based process group termination for cleanup, and reads package metadata; no data exfiltration, credential harvesting, obfuscation, or backdoor patterns were found, but the process spawning and forced termination capabilities warrant a warning-level classification. |
| dist/lib/typescript/writeAppTypeDeclarations.js | medium | The code appears to be a legitimate Next.js utility for writing TypeScript declaration files, with no malicious patterns such as data exfiltration, credential harvesting, or code execution; minor warnings relate to expected file system writes and path construction. |
| dist/lib/verify-partytown-setup.js | medium | The code appears to be a legitimate Next.js utility for verifying and setting up Partytown, with no clear malicious patterns, though it uses dynamic require and file system operations that carry low inherent risk. |
| dist/lib/verify-typescript-setup.js | medium | This is legitimate Next.js TypeScript setup/verification code with no malicious patterns; the flagged items (dynamic require of the TypeScript API, auto-installation of TS dependencies, and writing tsconfig/next-env files) are expected framework behaviors rather than security defects. |
| dist/lib/worker.js | medium | This appears to be a legitimate Next.js build worker wrapper around jest-worker with no overt data exfiltration, credential theft, obfuscation, or backdoor code, but it inherits and propagates the full parent environment into child processes and spawns/kills child processes, which are expected build-tool behaviors rather than malicious patterns. |
| dist/next-devtools/server/attach-nodejs-debugger-middleware.js | medium | This appears to be a legitimate Next.js development helper that exposes the Node.js inspector via a dev-server middleware, but it creates a debugger exposure risk if the dev server is reachable by untrusted parties. |
| dist/next-devtools/server/launch-editor.js | medium | This is legitimate Next.js devtools code for launching editors, but it spawns external processes and consumes EDITOR/VISUAL/REACT_EDITOR environment variables, creating command-execution surface that is a normal but notable risk; no malicious exfiltration or backdoor patterns were found. |
| dist/next-devtools/server/middleware-response.js | medium | No malicious patterns detected; however, the code may expose sensitive error details via util.inspect in HTTP 500 responses. |
| dist/next-devtools/server/restart-dev-server-middleware.js | medium | This is a legitimate Next.js dev-server restart/status middleware with no signs of exfiltration, credential harvesting, obfuscation, or backdoor code; the only concerns are dev-only process termination and cache invalidation triggered by local HTTP requests. |
| dist/next-devtools/userspace/app/errors/intercept-console-error.js | medium | Legitimate Next.js devtools code that intercepts and forwards console errors, but the global console patching and error forwarding behavior warrants medium-severity attention in third-party contexts. |
| dist/next-devtools/userspace/app/forward-logs.js | medium | This is Next.js devtools instrumentation that intercepts console output/errors and forwards them over WebSocket, which is intended functionality but creates a data channel that could exfiltrate sensitive logged information if the socket endpoint or activation env variable is misused. |
| dist/server/api-utils/node/api-resolver.js | medium | This appears to be legitimate Next.js API route resolver code with expected framework behaviors; the main concerns are the SSRF-prone fetch using the Host header and dynamic require calls, but no clear malicious patterns were found. |
| dist/server/app-render/app-render-scheduling.js | medium | No malicious patterns (no exfiltration, credential harvesting, eval, shells, or network activity) were found; the only concerns are benign but invasive monkey-patching of Node.js timer internals for scheduling determinism. |
| dist/server/app-render/entry-base.js | medium | This appears to be a legitimate Next.js server-render entry module, but contains several low-severity patterns (environment-gated dynamic require, globalThis mutation, import-time side effects) that warrant attention rather than indicating active malice. |
| dist/server/app-render/module-loading/instrument-module-getter.js | medium | Code is a legitimate Next.js internal module-getter instrumentation wrapper; it only reads Next.js-specific environment flags and lazily requires a static relative module, with no exfiltration, credential access, or command execution observed. |
| dist/server/config-utils.js | medium | This Next.js config utility installs a global require hook aliasing webpack modules to bundled Next.js copies; while the paths are explicit and appear benign, the pattern of globally mutating module resolution and using dynamic require.resolve warrants a warning for supply-chain review. |
| dist/server/dev/hot-reloader-shared-utils.js | medium | No malicious patterns detected; the only outbound network call is a hardcoded, non-exfiltrating version staleness check against the public npm registry. |
| dist/server/dev/hot-reloader-turbopack.js | medium | This is a legitimate Next.js Turbopack dev hot-reloader file; it contains dev-time network access to the local inspector, dynamic invocation of global HMR hooks, and environment variable usage, but no clear data exfiltration, credential harvesting, obfuscation, or backdoor patterns were found. |
| dist/server/dev/hot-reloader-webpack.js | medium | This is legitimate Next.js dev-server hot-reloader code; the only notable concern is an origin-reflection CORS policy on dev hot-reloader endpoints that could expose source/source-maps to arbitrary origins in a development environment. |
| dist/server/dev/middleware-webpack.js | medium | This is a Next.js devtools middleware file with no obvious credential harvesting, exfiltration, obfuscation, or eval/child_process abuse, but it exposes user input to filesystem path resolution, source map reading, and editor process launching, creating a non-trivial attack surface if the dev server is reachable by untrusted parties. |
| dist/server/dev/use-cache-probe-pool.js | medium | This appears to be legitimate Next.js dev-server internals (use-cache hang probe worker pool) with no exfiltration, credential harvesting, obfuscation, backdoors, or shell execution; only routine child-process spawning and env propagation warrant low-severity notes. |
| dist/server/lib/cpu-profile.js | medium | The code appears to be a legitimate CPU profiling utility for Next.js, but it writes files based on environment variables and executes at import time, posing a low-to-medium risk if environment variables are attacker-controlled. |
| dist/server/lib/experimental/create-env-definitions.js | medium | The code is a legitimate Next.js utility for generating TypeScript definitions from environment variables, with only minor concerns about file writing and env variable key processing, but no malicious patterns detected. |
| dist/server/lib/generate-agent-files.js | medium | No malicious patterns detected (no exfiltration, credential harvesting, code execution, or network activity), but the module silently creates and rewrites AGENTS.md/CLAUDE.md in the project directory at dev time and injects AI-agent instruction content. |
| dist/server/lib/module-loader/node-module-loader.js | medium | This is a Next.js internal node module loader with dynamic require based on an id parameter; it contains no exfiltration, credential harvesting, obfuscation, or process spawning, but the dynamic require pattern warrants a low-to-medium warning. |
| dist/server/lib/render-server.js | medium | The code is part of Next.js's server rendering infrastructure and contains legitimate dynamic import and environment-based behavior, but the lack of validation on environment-controlled import paths and server field propagation introduces medium-risk attack surfaces. |
| dist/server/lib/router-server.js | medium | This is a legitimate Next.js router-server module from the Next.js package; it contains no clear data exfiltration, credential harvesting, obfuscated payloads, or reverse shells, but uses dynamic requires, global fetch patching, and internal header filtering that warrant routine supply-chain verification since the analyzed file appears to be legitimate Next.js core code. |
| dist/server/lib/router-utils/instrumentation-globals.external.js | medium | The code appears to be a legitimate Next.js instrumentation loading utility, but it dynamically loads and executes a module from a computed path, which could be risky if the path or file is attacker-controlled. |
| dist/server/lib/router-utils/proxy-request.js | medium | No clear malicious code (exfiltration, credential theft, shells, or mining) was found, but the code implements a generic request-forwarding proxy with limited target validation, which carries SSRF/open-proxy and header-forwarding risks if exposed to untrusted input. |
| dist/server/lib/start-server.js | medium | This is a legitimate Next.js start-server module with no data exfiltration or credential harvesting, but it uses child_process.exec with interpolated port values for port lookup, which is a minor command-injection pattern worth noting. |
| dist/server/load-components.js | medium | This appears to be legitimate Next.js server-side code for loading page components and manifests, but contains dynamic code execution (evalManifest) and dynamic module loading (requirePage) patterns that warrant caution if page paths or manifest paths are attacker-controllable. |
| dist/server/load-manifest.external.js | medium | This appears to be legitimate Next.js manifest-loading code, but the evalManifest function executes file contents via vm.runInNewContext and paths are file-system derived, which are risky if callers pass untrusted paths; no exfiltration, backdoors, or mining patterns were found. |
| dist/server/node-environment-baseline.js | medium | The file is a Next.js runtime shim that modifies globalThis at import time and lazily loads a bundled WebSocket implementation, which is not overtly malicious but introduces supply-chain and runtime trust concerns. |
| dist/server/node-environment-extensions/console-file.js | medium | The code patches global console methods for development-time file logging; no data exfiltration, credential harvesting, obfuscation, or malicious network/process activity detected, but global console modification is a minor security hygiene concern. |
| dist/server/node-environment-extensions/fast-set-immediate.external.js | medium | This is a legitimate Next.js internal timer-shimming module, but it globally monkey-patches setImmediate/clearImmediate/process.nextTick at import time, which is a risky pattern worth flagging despite no evidence of exfiltration, credential theft, or backdoors. |
| dist/server/node-environment-extensions/process-error-handlers.js | medium | This is Next.js internal code that intentionally overrides Node.js error handling to prevent crashes, which is a legitimate framework behavior but carries security implications by suppressing uncaught exceptions and unhandled rejections. |
| dist/server/node-environment-extensions/unhandled-rejection.external.js | medium | No malicious exfiltration, credential theft, obfuscation, or backdoor patterns were found; the primary risks are aggressive global process monkey-patching and selective suppression of unhandled rejection events, which are legitimate but intrusive Error-handling side effects. |
| dist/server/node-environment.js | medium | The file itself contains no direct malicious patterns, but its import-time execution of multiple opaque environment-modifying modules warrants review of the required submodules for potential hidden malicious behavior. |
| dist/server/node-polyfill-crypto.js | medium | The file is a legitimate crypto polyfill but mutates the global crypto object at import time with a mutable setter, creating a medium-risk attack surface for crypto-provider substitution by other code in the process; no direct malicious behavior is present. |
| dist/server/post-process.js | medium | The code is a legitimate Next.js post-processing utility that conditionally loads the 'critters' package for CSS optimization; no malicious patterns were detected. |
| dist/server/render-result.js | medium | The file is part of Next.js's rendering internals and contains no malicious patterns; the only notable items are standard framework-specific dynamic require calls with hardcoded module names and environment variable checks for runtime detection. |
| dist/server/require-hook.js | medium | The file monkey-patches Node.js module resolution to alias Next.js internal modules; no direct malicious behavior (exfiltration, shells, crypto) was found, but the module-loading interception warrants caution. |
| dist/server/require.js | medium | The code performs dynamic module loading and file reads based on computed paths derived from manifests and user input, which could be exploited for path traversal or arbitrary code execution if inputs are not properly sanitized. |
| dist/server/route-matcher-providers/helpers/manifest-loaders/node-manifest-loader.js | medium | This appears to be legitimate Next.js internal manifest-loading code with a dynamic require pattern that could be risky if inputs are not validated, but no overt malicious behavior is present. |
| dist/server/route-modules/route-module.js | medium | This appears to be legitimate Next.js framework code with standard dynamic imports and manifest loading, though it uses runtime-computed module paths and environment variables that warrant awareness rather than indicating outright malice. |
| dist/server/web/adapter.js | medium | The file contains conditional dynamic require of an experimental internal module based on an environment variable, which poses a moderate risk if that variable is attacker-controlled, but no clear malicious patterns like data exfiltration, credential harvesting, or backdoors were found. |
| dist/server/web/sandbox/context.js | medium | The code is part of Next.js Edge Runtime sandboxing and includes legitimate dynamic code execution and environment variable access, but these patterns pose security risks if the sandbox is bypassed or if input paths are attacker-controlled. |
| dist/server/web/sandbox/fetch-inline-assets.js | medium | The function reads and streams local files based on an unvalidated blob name that can traverse outside the intended distDir, creating a path traversal / arbitrary file read risk. |
| dist/server/web/sandbox/sandbox.js | medium | The file is a legitimate Next.js edge sandbox runner; it contains no data exfiltration, credential harvesting, obfuscation, or backdoor patterns, though it does perform dynamic evaluation and global context injection that are inherent to its sandboxing role. |
| dist/shared/lib/router/utils/escape-path-delimiters.js | medium | The code is not malicious but contains a broken regular expression that could cause runtime errors and weaken path escaping. |
| dist/shared/lib/router/utils/path-match.js | medium | Path-matching utility with no network, filesystem, process, or exfiltration behavior; only a minor concern that caller-supplied regex modifications could enable ReDoS if fed untrusted input. |
| dist/telemetry/anonymous-meta.js | medium | This is a Next.js telemetry metadata collector that fingerprints the host environment (OS, CPU, memory, Docker/WSL/CI status) but does not exfiltrate data, harvest credentials, execute shell commands, or contain obfuscated/backdoor code. |
| dist/telemetry/detached-flush.js | medium | The file implements Next.js's detached telemetry flush mechanism, which reads and deletes project-local event files and forwards telemetry data; no credential harvesting, obfuscation, shell spawning, or other clearly malicious patterns were detected, though it does execute filesystem operations and telemetry transmission at import time. |
| dist/telemetry/events/swc-load-failure.js | medium | No malicious patterns detected; the file contains expected Next.js telemetry reporting logic with minor dynamic require and data collection concerns. |
| dist/telemetry/events/swc-plugins.js | medium | This appears to be legitimate Next.js telemetry code for detecting SWC plugins in package.json dependencies, with minor concerns around dynamic require and filesystem traversal that are consistent with its intended purpose rather than malicious intent. |
| dist/telemetry/events/version.js | medium | No malicious patterns such as exfiltration, credential harvesting, obfuscated code execution, backdoors, or process spawning were detected; the file is a benign telemetry event builder with limited privacy implications due to collected configuration and environment metadata. |
| dist/telemetry/post-telemetry-payload.js | medium | The code is a legitimate Next.js telemetry sender that exfiltrates data to an external endpoint, which is expected behavior but poses a medium risk due to unvalidated payload transmission. |
| dist/telemetry/project-id.js | medium | Code is not clearly malicious but executes a shell command to read git remote URL and accesses environment variables for telemetry project identification, which warrants caution. |
| dist/telemetry/storage.js | medium | This is Next.js's official telemetry implementation that intentionally collects and transmits anonymous usage data; it is not malicious but represents a privacy/data-exfiltration concern that should be controlled via NEXT_TELEMETRY_DISABLED. |
| dist/trace/report/index.js | medium | The file itself appears to be a benign reporting aggregator, but the included 'to-telemetry' reporter raises data exfiltration concerns that require inspection of its implementation. |
| dist/trace/shared.js | medium | The code appears to be a legitimate tracing utility with no clear malicious intent, but it does access environment variables and pollutes the global namespace, which are minor security concerns. |
| dist/trace/trace-uploader.js | medium | This is Next.js's trace uploader: it collects build trace data and project metadata and POSTs it to an argv-supplied URL, which is intended telemetry behavior but technically constitutes outbound data transmission of project/git metadata to a caller-controlled endpoint, warranting a warning rather than a clean safe rating. |
| dist/trace/upload-trace.js | medium | This module spawns a detached child process to upload trace and telemetry data (including project paths and persistent identifiers) to a caller-supplied remote URL, which is a privacy/data-exfiltration concern despite appearing to be legitimate Next.js telemetry code. |
| root-params.js | medium | No malicious patterns detected; the module is a harmless compiler placeholder that throws an error on import. |
| app.js | safe | Cleared by Jev triage; no further analysis needed |
| babel.js | safe | Cleared by Jev triage; no further analysis needed |
| cache.js | safe | This is a legitimate Next.js cache module that conditionally exports server/client caching utilities using standard require() calls, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or shell execution. |
| client.js | safe | Cleared by Jev triage; no further analysis needed |
| compat/router.js | safe | Cleared by Jev triage; no further analysis needed |
| constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/api/app-dynamic.js | safe | The file is a simple re-export module that only forwards exports from a shared internal library, with no suspicious or malicious code patterns. |
| dist/api/app.js | safe | No malicious patterns detected; this is a simple re-export module pointing to a local _app file with no external network, process, filesystem, or dynamic code execution behavior. |
| dist/api/constants.js | safe | This file is a simple re-export of constants from a shared library with no malicious patterns detected. |
| dist/api/document.js | safe | No malicious patterns detected; the file only re-exports a local _document module. |
| dist/api/dynamic.js | safe | No malicious patterns detected |
| dist/api/error.js | safe | This file only contains standard re-export statements with no malicious patterns detected |
| dist/api/error.react-server.js | safe | No malicious patterns detected |
| dist/api/form.js | safe | No malicious patterns detected |
| dist/api/head.js | safe | No malicious patterns detected |
| dist/api/headers.js | safe | No malicious patterns detected |
| dist/api/image.js | safe | This file only re-exports an image library from a shared internal module with no suspicious code patterns. |
| dist/api/link.js | safe | No malicious patterns detected |
| dist/api/navigation.js | safe | No malicious patterns detected; the file is a simple re-export from a local client component. |
| dist/api/navigation.react-server.js | safe | No malicious patterns detected |
| dist/api/og.js | safe | No malicious patterns detected |
| dist/api/router.js | safe | This is a simple re-export module that only re-exports from a relative client router module, with no malicious patterns detected. |
| dist/api/script.js | safe | No malicious patterns detected |
| dist/api/server.js | safe | No malicious patterns detected; the file only re-exports from an internal module. |
| dist/build/adapter/build-complete.js | safe | This is a legitimate Next.js build adapter module that processes build outputs, traces file dependencies, and invokes adapter callbacks; no malicious patterns, data exfiltration, credential harvesting, or backdoor code detected. |
| dist/build/adapter/setup-node-env.external.js | safe | No malicious patterns detected; the file only conditionally imports standard Next.js internal server environment modules. |
| dist/build/after-production-compile.js | safe | No malicious patterns detected |
| dist/build/analysis/extract-const-value.js | safe | No malicious patterns detected |
| dist/build/analysis/get-page-static-info.js | safe | No malicious patterns detected; this is a legitimate Next.js static page analysis module that reads local page files, parses ASTs, and parses route segment configurations. |
| dist/build/analysis/parse-module.js | safe | No malicious patterns detected |
| dist/build/analyze/index.js | safe | This is legitimate Next.js bundle analyzer source code with no malicious patterns; it only performs local file operations, starts a localhost server, and records telemetry events. |
| dist/build/babel/loader/get-config.js | safe | This is legitimate Next.js Babel loader configuration code with no malicious patterns detected. |
| dist/build/babel/loader/index.js | safe | This is a legitimate Next.js Babel loader that transforms source code using webpack's loader API and contains no malicious patterns. |
| dist/build/babel/loader/transform.js | safe | No malicious patterns detected; the file is a legitimate Babel transformation loader adapted from @babel/core. |
| dist/build/babel/loader/util.js | safe | No malicious patterns detected |
| dist/build/babel/plugins/commonjs.js | safe | The code is a standard Babel plugin wrapper for CommonJS transformation, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/build/babel/plugins/jsx-pragma.js | safe | No malicious patterns detected; this is a standard Babel JSX pragma plugin for Next.js with no external network, filesystem, or process manipulation. |
| dist/build/babel/plugins/next-font-unsupported.js | safe | No malicious patterns detected; the code is a standard Babel plugin that throws an error when next/font imports are used, with no data exfiltration, credential harvesting, obfuscation, network activity, or process execution. |
| dist/build/babel/plugins/next-page-config.js | safe | No malicious patterns detected; the file is a Next.js Babel plugin that validates page config exports at build time and contains no network, filesystem, process, or code execution behavior. |
| dist/build/babel/plugins/next-page-disallow-re-export-all-exports.js | safe | This is a standard Next.js Babel plugin that only validates and rejects invalid export * from syntax in page components, with no malicious patterns such as network access, process spawning, credential harvesting, or dynamic code execution. |
| dist/build/babel/plugins/next-ssg-transform.js | safe | No malicious patterns detected; the code is a legitimate Next.js Babel plugin for transforming SSG/SSR exports. |
| dist/build/babel/plugins/optimize-hook-destructuring.js | safe | No malicious patterns detected |
| dist/build/babel/plugins/react-loadable-plugin.js | safe | This is a legitimate Babel plugin for Next.js dynamic imports with no malicious patterns detected. |
| dist/build/babel/preset.js | safe | This is a legitimate Next.js Babel preset configuration file with no malicious patterns detected; all require() calls use static strings, no eval/exec, no network requests, no credential harvesting, and no install-time hooks. |
| dist/build/browser-variant-modules.js | safe | No malicious patterns detected; the file is a generated static list of module paths with no dynamic code execution, network access, or filesystem manipulation. |
| dist/build/build-context.js | safe | No malicious patterns detected; the file contains benign internal state management utilities for Next.js build process. |
| dist/build/compiler.js | safe | No malicious patterns detected |
| dist/build/create-compiler-aliases.js | safe | This is a legitimate Next.js build configuration file that only defines webpack alias mappings and module path resolutions, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, network requests, or process spawning. |
| dist/build/define-env.js | safe | No malicious patterns detected |
| dist/build/duration-to-string.js | safe | No malicious patterns detected; the code only contains pure utility functions for formatting time durations. |
| dist/build/entries.js | safe | No malicious patterns detected; the code is a legitimate Next.js build utility for creating webpack entrypoints. |
| dist/build/file-classifier.js | safe | No malicious patterns detected; the file only contains pure functions for extracting and combining route slot metadata. |
| dist/build/generate-build-id.js | safe | No malicious patterns detected; the code is a benign utility function for generating a build ID with fallback logic and input validation. |
| dist/build/generate-routes-manifest.js | safe | No malicious patterns detected; the code is a legitimate Next.js routes manifest generator with no network, filesystem, process, or obfuscated behavior. |
| dist/build/get-babel-config-file.js | safe | No malicious patterns detected; the code only searches for Babel configuration files in a given directory using path.join and fs.existsSync. |
| dist/build/get-babel-loader-config.js | safe | No malicious patterns detected; the code is a standard Babel loader configuration utility for Next.js with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/build/get-static-info-including-layouts.js | safe | No malicious patterns detected; the code performs local file system checks and static config inheritance for Next.js pages and layouts. |
| dist/build/get-supported-browsers.js | safe | No malicious patterns detected; the file is a standard Next.js utility that resolves supported browsers via browserslist with no network, filesystem, process, or dynamic execution risks. |
| dist/build/handle-entrypoints.js | safe | No malicious patterns detected; the file contains standard Next.js internal entrypoint handling logic with no exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| dist/build/handle-externals.js | safe | No malicious patterns detected; the code is a legitimate Next.js webpack external handling module with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/build/is-writeable.js | safe | This utility simply checks whether a directory is writeable using fs.access with no malicious behavior, external calls, or suspicious patterns. |
| dist/build/jest/__mocks__/empty.js | safe | No malicious patterns detected |
| dist/build/jest/__mocks__/fileMock.js | safe | No malicious patterns detected; the file is a standard Jest mock for static file imports. |
| dist/build/jest/__mocks__/nextFontMock.js | safe | This is a standard Next.js font mock file for Jest testing that uses a Proxy to return mock font objects with no network, filesystem, process, or dynamic code execution activity. |
| dist/build/jest/__mocks__/styleMock.js | safe | No malicious patterns detected |
| dist/build/jest/jest.js | safe | No malicious patterns detected; this is a legitimate Next.js Jest configuration helper that loads environment variables and configuration files without exfiltration, obfuscation, or suspicious system calls. |
| dist/build/jest/object-proxy.js | safe | The file implements a benign Proxy-based mock object for CSS module imports in Jest tests, with no network, filesystem, process, or credential access patterns. |
| dist/build/load-entrypoint.js | safe | No malicious patterns detected; the code is a legitimate Next.js build artifact that reads local template files and expands them using a SWC binding. |
| dist/build/load-jsconfig.js | safe | No malicious patterns detected |
| dist/build/lockfile.js | safe | No malicious patterns detected |
| dist/build/manifests/formatter/format-manifest.js | safe | No malicious patterns detected; the file only performs standard JSON serialization of a manifest object. |
| dist/build/next-dir-paths.js | safe | No malicious patterns detected |
| dist/build/normalize-catchall-routes.js | safe | No malicious patterns detected |
| dist/build/output/format.js | safe | No malicious patterns detected; the code only formats cache-control time values using simple arithmetic and string interpolation. |
| dist/build/output/index.js | safe | No malicious patterns detected; the code is a standard Next.js build monitoring module with no network, filesystem, or process manipulation. |
| dist/build/output/log.js | safe | No malicious patterns detected |
| dist/build/output/store.js | safe | No malicious patterns detected; the file is a standard Next.js dev-build store module with no exfiltration, obfuscation, credential harvesting, or command execution. |
| dist/build/page-extensions-type.js | safe | No malicious patterns detected |
| dist/build/polyfills/fetch/index.js | safe | No malicious patterns detected |
| dist/build/polyfills/fetch/whatwg-fetch.js | safe | This file is a simple polyfill re-exporting fetch API globals from self, with no suspicious or malicious patterns detected. |
| dist/build/polyfills/object-assign.js | safe | No malicious patterns detected |
| dist/build/polyfills/object.assign/auto.js | safe | No malicious patterns detected |
| dist/build/polyfills/object.assign/implementation.js | safe | No malicious patterns detected |
| dist/build/polyfills/object.assign/index.js | safe | No malicious patterns detected |
| dist/build/polyfills/object.assign/polyfill.js | safe | No malicious patterns detected |
| dist/build/polyfills/object.assign/shim.js | safe | No malicious patterns detected |
| dist/build/polyfills/polyfill-module.js | safe | No malicious patterns detected; the code only contains standard polyfills for modern JavaScript methods. |
| dist/build/polyfills/process.js | safe | No malicious patterns detected; the file is a benign Next.js process polyfill with no exfiltration, obfuscation, or suspicious network/process activity. |
| dist/build/preview-key-utils.js | safe | The code is a legitimate Next.js utility for generating and caching preview mode cryptographic keys; no malicious patterns such as exfiltration, obfuscation, network requests, or process spawning were detected. |
| dist/build/print-build-errors.js | safe | No malicious patterns detected |
| dist/build/progress.js | safe | The code is a benign progress bar utility with no malicious patterns, network requests, credential harvesting, or dynamic code execution. |
| dist/build/rendering-mode.js | safe | No malicious patterns detected |
| dist/build/segment-config/app/app-segment-config.js | safe | No malicious patterns detected; the file is a standard Zod schema definition for Next.js app segment configuration with no network, filesystem, process, or dynamic execution behavior. |
| dist/build/segment-config/app/app-segments.js | safe | No malicious patterns detected; the code is legitimate Next.js internal logic for collecting app segment configurations. |
| dist/build/segment-config/app/collect-root-param-keys.js | safe | No malicious patterns detected; the code is a standard Next.js internal utility for collecting route parameter keys. |
| dist/build/segment-config/middleware/middleware-config.js | safe | No malicious patterns detected; the code defines Zod validation schemas for Next.js middleware configuration without any exfiltration, code execution, or suspicious behavior. |
| dist/build/segment-config/pages/pages-segment-config.js | safe | No malicious patterns detected; the file only defines a Zod schema and a parse function for Next.js page segment configuration. |
| dist/build/sort-by-page-exts.js | safe | No malicious patterns detected |
| dist/build/spinner.js | safe | No malicious patterns detected; the code is a standard Next.js build artifact implementing a terminal spinner with console log capture. |
| dist/build/static-paths/app.js | safe | This is Next.js framework code for static path generation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution detected. |
| dist/build/static-paths/app/extract-pathname-route-param-segments-from-loader-tree.js | safe | No malicious patterns detected; the code is a legitimate Next.js utility for extracting route parameters from a loader tree. |
| dist/build/static-paths/pages.js | safe | No malicious patterns detected; this is standard Next.js build-time logic for processing getStaticPaths results with input validation and path escaping. |
| dist/build/static-paths/types.js | safe | No malicious patterns detected |
| dist/build/static-paths/utils.js | safe | No malicious patterns detected; the file contains standard Next.js routing utility functions with no network, filesystem, process, or dynamic code execution concerns. |
| dist/build/swc/helpers.js | safe | No malicious patterns detected |
| dist/build/swc/install-bindings.js | safe | No malicious patterns detected |
| dist/build/swc/jest-transformer.js | safe | No malicious patterns detected |
| dist/build/swc/options.js | safe | No malicious patterns detected; the file is a legitimate Next.js SWC options builder that resolves plugin paths from user configuration and constructs compiler options without exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/build/swc/types.js | safe | No malicious patterns detected |
| dist/build/templates/app-page.js | safe | No malicious patterns detected; this is a legitimate Next.js app-page template with build-time template placeholders and no suspicious runtime behavior. |
| dist/build/templates/app-route.js | safe | This is legitimate Next.js framework code for an App Router route handler; no malicious patterns such as exfiltration, credential harvesting, shell execution, or obfuscated payloads were found. |
| dist/build/templates/edge-app-route.js | safe | No malicious patterns detected; this is a legitimate Next.js internal edge route module template with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/build/templates/edge-ssr-app.js | safe | This is a legitimate Next.js Edge SSR runtime template with no malicious patterns detected; dynamic requires use build-time placeholders (VAR_USERLAND, VAR_PAGE) and there is no exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/build/templates/edge-ssr.js | safe | No malicious patterns detected; the file is a legitimate Next.js Edge SSR template with standard module imports, request handling, and rendering logic. |
| dist/build/templates/helpers.js | safe | No malicious patterns detected; the file only contains a benign module hoisting utility with no I/O, network, process, or dynamic execution behavior. |
| dist/build/templates/middleware.js | safe | This is a standard Next.js middleware template generated by the framework; it contains no malicious patterns, external data exfiltration, credential harvesting, obfuscation, or dynamic code execution beyond normal module loading. |
| dist/build/templates/pages-api.js | safe | This is a legitimate Next.js build template for Pages API routes with no malicious patterns detected. |
| dist/build/templates/pages-edge-api.js | safe | No malicious patterns detected; the file is a standard Next.js edge API page template with only placeholder substitutions and internal framework imports. |
| dist/build/templates/pages.js | safe | No malicious patterns detected; this is a standard Next.js build artifact for page route modules with no obfuscation, exfiltration, or dangerous dynamic execution. |
| dist/build/turbopack-analyze/index.js | safe | No malicious patterns detected; the file is a legitimate Next.js Turbopack analysis module using expected imports, native bindings, and project lifecycle operations. |
| dist/build/turbopack-build/impl.js | safe | This is legitimate Next.js Turbopack build orchestration code with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution. |
| dist/build/turbopack-build/index.js | safe | No malicious patterns detected; the code is a legitimate Turbopack build orchestration module using workers and environment variables for build configuration. |
| dist/build/turborepo-access-trace/index.js | safe | The module is a simple re-export of local helper and result modules with no suspicious behavior, network activity, or credential access. |
| dist/build/turborepo-access-trace/result.js | safe | No malicious patterns detected; the file is a straightforward data-container class for tracking environment variables, filesystem paths, and network addresses without any exfiltration, code execution, or filesystem manipulation. |
| dist/build/turborepo-access-trace/types.js | safe | The file contains only TypeScript type definitions and module boilerplate with no executable or malicious code. |
| dist/build/type-check.js | safe | This is a legitimate Next.js build utility for running TypeScript type checking in a worker; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected. |
| dist/build/utils.js | safe | No malicious patterns detected; the file is a legitimate Next.js build utility with expected filesystem, tracing, and static-analysis logic. |
| dist/build/validate-app-paths.js | safe | The code is a Next.js internal route validation module that only manipulates strings and throws descriptive errors, with no network, filesystem, process, or dynamic execution activity. |
| dist/build/warn-about-edge-runtime.js | safe | No malicious patterns detected |
| dist/build/webpack-build/impl.js | safe | No malicious patterns detected; this is legitimate Next.js webpack build orchestration code with no exfiltration, credential harvesting, or dynamic code execution. |
| dist/build/webpack-config-rules/resolve.js | safe | No malicious patterns detected; the file only defines module resolution field preferences for a webpack configuration. |
| dist/build/webpack/alias/react-dom-server-experimental.js | safe | This is a Next.js internal compatibility shim for react-dom/server APIs with conditional requires based on environment variables; no malicious patterns detected. |
| dist/build/webpack/cache-invalidation.js | safe | No malicious patterns detected |
| dist/build/webpack/config/blocks/base.js | safe | No malicious patterns detected; the code is a standard Next.js webpack configuration module with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| dist/build/webpack/config/blocks/css/index.js | safe | No malicious patterns detected; the code is a legitimate Next.js webpack CSS configuration module. |
| dist/build/webpack/config/blocks/css/loaders/client.js | safe | No malicious patterns detected; the code is a standard Next.js webpack CSS loader configuration. |
| dist/build/webpack/config/blocks/css/loaders/file-resolve.js | safe | No malicious patterns detected; the code is a simple URL resolution utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/build/webpack/config/blocks/css/loaders/getCssModuleLocalIdent.js | safe | No malicious patterns detected; this is a legitimate Next.js utility for generating CSS module local class names using safe path, hashing, and string operations. |
| dist/build/webpack/config/blocks/css/loaders/global.js | safe | The file is a standard webpack CSS loader configuration from Next.js with no malicious patterns or security concerns detected. |
| dist/build/webpack/config/blocks/css/loaders/index.js | safe | No malicious patterns detected; the file only re-exports CSS loader modules from sibling files using standard CommonJS export patterns. |
| dist/build/webpack/config/blocks/css/loaders/modules.js | safe | No malicious patterns detected; the file is a standard webpack CSS loader configuration module for Next.js. |
| dist/build/webpack/config/blocks/css/loaders/next-font.js | safe | No malicious patterns detected; this is a legitimate Next.js internal webpack loader configuration module with no data exfiltration, dynamic code execution, process spawning, or suspicious file system access. |
| dist/build/webpack/config/blocks/css/messages.js | safe | No malicious patterns detected |
| dist/build/webpack/config/blocks/images/index.js | safe | No malicious patterns detected; this is a standard Next.js webpack image configuration module with only static loader rules and no network, filesystem, or shell access. |
| dist/build/webpack/config/blocks/images/messages.js | safe | No malicious patterns detected; the file only exports a static error message helper using picocolors for terminal formatting. |
| dist/build/webpack/config/helpers.js | safe | No malicious patterns detected |
| dist/build/webpack/config/index.js | safe | This is a standard Next.js webpack configuration builder with no malicious patterns detected. |
| dist/build/webpack/config/utils.js | safe | The file contains only a simple pipe utility function with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist/build/webpack/loaders/css-loader/src/CssSyntaxError.js | safe | No malicious patterns detected; the file only defines a CSS syntax error class for webpack's css-loader. |
| dist/build/webpack/loaders/css-loader/src/camelcase.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/css-loader/src/index.js | safe | No malicious patterns detected; this is a legitimate css-loader module that normalizes options and processes CSS with PostCSS without any exfiltration, code execution, or suspicious behavior. |
| dist/build/webpack/loaders/css-loader/src/plugins/index.js | safe | This is a standard webpack css-loader plugin index file that only re-exports three PostCSS parser modules with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist/build/webpack/loaders/css-loader/src/plugins/postcss-icss-parser.js | safe | No malicious patterns detected; the code is a legitimate PostCSS plugin for handling ICSS imports/exports in Next.js's bundled CSS loader. |
| dist/build/webpack/loaders/css-loader/src/plugins/postcss-import-parser.js | safe | No malicious patterns detected; the file is a standard PostCSS @import parser from Next.js's bundled css-loader with no exfiltration, code execution, or process spawning behavior. |
| dist/build/webpack/loaders/css-loader/src/plugins/postcss-url-parser.js | safe | No malicious patterns detected; the code is a standard PostCSS URL parser plugin used for CSS URL resolution. |
| dist/build/webpack/loaders/css-loader/src/runtime/api.js | safe | No malicious patterns detected; this is a standard css-loader runtime file that builds CSS strings and source map comments without any exfiltration, code execution, or process spawning. |
| dist/build/webpack/loaders/css-loader/src/runtime/getUrl.js | safe | No malicious patterns detected; the file is a legitimate css-loader runtime utility for normalizing CSS url() values. |
| dist/build/webpack/loaders/css-loader/src/utils.js | safe | This is a legitimate css-loader utility module from Next.js's bundled webpack loader; no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution were detected. |
| dist/build/webpack/loaders/devtool/devtool-style-inject.js | safe | No malicious patterns detected; the code is a legitimate Next.js devtools style injection utility that uses DOM APIs and MutationObserver without any data exfiltration, credential harvesting, dynamic code execution, or network activity. |
| dist/build/webpack/loaders/empty-loader.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/error-loader.js | safe | No malicious patterns detected; the file is a standard webpack error loader for emitting build errors. |
| dist/build/webpack/loaders/get-module-build-info.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/instrumentation-client-stub.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/lightningcss-loader/src/codegen.js | safe | No malicious patterns detected; this is standard webpack CSS loader code generation logic with no external network, filesystem, or process access. |
| dist/build/webpack/loaders/lightningcss-loader/src/index.js | safe | No malicious patterns detected; the file is a standard webpack loader entry point that only re-exports local modules. |
| dist/build/webpack/loaders/lightningcss-loader/src/interface.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/lightningcss-loader/src/loader.js | safe | The lightningcss-loader code is a standard Next.js webpack CSS loader with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized network/file/process operations. |
| dist/build/webpack/loaders/lightningcss-loader/src/minify.js | safe | No malicious patterns detected; the file is a legitimate webpack CSS minification plugin that uses lightningcss and swc bindings for asset optimization. |
| dist/build/webpack/loaders/lightningcss-loader/src/utils.js | safe | No malicious patterns detected; the code performs benign browserslist-to-lightningcss target version conversion with caching. |
| dist/build/webpack/loaders/metadata/discover.js | safe | This is legitimate Next.js metadata discovery code with no malicious patterns; it only performs file enumeration and constructs webpack import paths for static metadata images. |
| dist/build/webpack/loaders/metadata/types.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/modularize-import-loader.js | safe | No malicious patterns detected; this is a standard Next.js webpack loader that generates re-export statements using locally resolved paths. |
| dist/build/webpack/loaders/next-app-loader/create-app-route-code.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal webpack loader helper that resolves app route paths and loads entrypoints without any suspicious behavior. |
| dist/build/webpack/loaders/next-app-loader/index.js | safe | This is a legitimate Next.js internal webpack loader that performs file system operations and path resolution only within the app directory, with no malicious patterns detected. |
| dist/build/webpack/loaders/next-barrel-loader.js | safe | This is a legitimate Next.js Webpack loader for barrel file import optimization; no malicious patterns such as data exfiltration, credential harvesting, code execution, or process spawning were detected. |
| dist/build/webpack/loaders/next-client-pages-loader.js | safe | This is a standard Next.js webpack loader that generates client-side page registration code; no malicious patterns detected. |
| dist/build/webpack/loaders/next-edge-app-route-loader/index.js | safe | This is a legitimate Next.js webpack loader that transforms app route modules for edge runtime; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity were detected. |
| dist/build/webpack/loaders/next-edge-ssr-loader/index.js | safe | This is a standard Next.js webpack loader that generates edge SSR bundles and contains no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution beyond legitimate build-time operations. |
| dist/build/webpack/loaders/next-error-browser-binary-loader.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/next-flight-action-entry-loader.js | safe | No malicious patterns detected; the file is a standard Next.js webpack loader that re-exports server actions. |
| dist/build/webpack/loaders/next-flight-client-entry-loader.js | safe | This is a legitimate Next.js webpack loader that transforms module import statements for client entry points without any malicious patterns, data exfiltration, or code execution. |
| dist/build/webpack/loaders/next-flight-client-module-loader.js | safe | This is a legitimate Next.js webpack loader for React Server Components that transforms source code and manages build metadata without any malicious patterns. |
| dist/build/webpack/loaders/next-flight-css-loader.js | safe | No malicious patterns detected; the file is a standard Next.js Webpack loader that computes a SHA1 checksum for CSS HMR and contains no exfiltration, obfuscation, network, filesystem, or process-spawning behavior. |
| dist/build/webpack/loaders/next-flight-loader/action-client-wrapper.js | safe | No malicious patterns detected; the file is a standard Next.js re-export wrapper with only static requires and no dynamic or suspicious behavior. |
| dist/build/webpack/loaders/next-flight-loader/action-validate.js | safe | No malicious patterns detected; the file only performs a runtime type check on server action exports. |
| dist/build/webpack/loaders/next-flight-loader/cache-wrapper.js | safe | No malicious patterns detected; the file only re-exports the cache binding from an internal Next.js module. |
| dist/build/webpack/loaders/next-flight-loader/index.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack loader for React Server Components with no exfiltration, credential harvesting, obfuscation, or suspicious execution. |
| dist/build/webpack/loaders/next-flight-loader/module-proxy.js | safe | No malicious patterns detected; the file is a simple re-export of createClientModuleProxy from react-server-dom-webpack/server. |
| dist/build/webpack/loaders/next-flight-loader/server-reference.js | safe | No malicious patterns detected; the file is a simple re-export module for a React server reference registration API. |
| dist/build/webpack/loaders/next-flight-loader/track-dynamic-import.js | safe | This file is a simple re-export shim for the Next.js trackDynamicImport utility and contains no malicious patterns. |
| dist/build/webpack/loaders/next-flight-server-reference-proxy-loader.js | safe | This is a legitimate Next.js Webpack loader that generates proxy modules for React Server Components; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/build/webpack/loaders/next-font-loader/postcss-next-font.js | safe | No malicious patterns detected; the file is a legitimate PostCSS plugin for next/font that only manipulates CSS AST nodes and exports font metadata. |
| dist/build/webpack/loaders/next-image-loader/blur.js | safe | No malicious patterns detected; the code is a legitimate Next.js image blur placeholder generator with no data exfiltration, obfuscation, or suspicious behavior. |
| dist/build/webpack/loaders/next-image-loader/index.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack image loader with standard build-time functionality. |
| dist/build/webpack/loaders/next-invalid-import-error-loader.js | safe | This is a legitimate Next.js webpack loader that throws an error with a developer-provided message; no malicious patterns detected. |
| dist/build/webpack/loaders/next-metadata-image-loader.js | safe | This is the legitimate Next.js metadata image webpack loader; no malicious exfiltration, credential harvesting, obfuscation, process spawning, or backdoor patterns are present. |
| dist/build/webpack/loaders/next-metadata-route-loader.js | safe | No malicious patterns detected; this is a legitimate Next.js internal webpack loader that generates metadata route code and reads local resource files for favicon, sitemap, robots, and OpenGraph image handling. |
| dist/build/webpack/loaders/next-middleware-asset-loader.js | safe | No malicious patterns detected; the file is a standard Next.js webpack loader for emitting middleware asset files. |
| dist/build/webpack/loaders/next-middleware-wasm-loader.js | safe | No malicious patterns detected; this is a standard Webpack loader for Next.js middleware WASM files. |
| dist/build/webpack/loaders/next-root-params-loader.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/next-route-loader/index.js | safe | This is a standard Next.js webpack route loader file with no malicious patterns detected. |
| dist/build/webpack/loaders/next-style-loader/index.js | safe | No malicious patterns detected; this is a legitimate webpack loader for Next.js style injection with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoLinkTag.js | safe | No malicious patterns detected; this is a standard Next.js/webpack style loader runtime that injects stylesheets into link tags with no data exfiltration, code execution, or suspicious behavior. |
| dist/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoStyleTag.js | safe | No malicious patterns detected; this is a legitimate Next.js/webpack style loader runtime that dynamically injects CSS into the DOM with no network, filesystem, process, or credential access. |
| dist/build/webpack/loaders/next-style-loader/runtime/isEqualLocals.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/next-swc-loader.js | safe | No malicious patterns detected; the file is a legitimate Next.js SWC webpack loader that performs source transformation without any exfiltration, credential harvesting, obfuscation, or suspicious system interaction. |
| dist/build/webpack/loaders/postcss-loader/src/Error.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/postcss-loader/src/Warning.js | safe | No malicious patterns detected |
| dist/build/webpack/loaders/postcss-loader/src/index.js | safe | This is a legitimate PostCSS webpack loader implementation that processes CSS files without any malicious patterns such as data exfiltration, credential harvesting, obfuscated code, cryptocurrency mining, backdoors, or unauthorized file system/network access. |
| dist/build/webpack/loaders/postcss-loader/src/utils.js | safe | The code only normalizes source map paths using path utilities and does not contain any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/build/webpack/loaders/resolve-url-loader/index.js | safe | No malicious patterns detected; this is a legitimate webpack loader for resolving url() paths with standard source-map and postcss usage. |
| dist/build/webpack/loaders/resolve-url-loader/lib/file-protocol.js | safe | No malicious patterns detected; the file only provides utility functions for prepending and removing the file:// protocol from source map paths. |
| dist/build/webpack/loaders/resolve-url-loader/lib/join-function.js | safe | No malicious patterns detected; the file implements a path-joining utility for webpack's resolve-url-loader with only filesystem existence checks and debug logging. |
| dist/build/webpack/loaders/resolve-url-loader/lib/postcss.js | safe | No malicious patterns detected; this is a legitimate PostCSS plugin for resolving url() references in CSS source maps. |
| dist/build/webpack/loaders/resolve-url-loader/lib/value-processor.js | safe | No malicious patterns detected; the code is a legitimate webpack loader utility for resolving CSS url() references. |
| dist/build/webpack/loaders/utils.js | safe | No malicious patterns detected; the code contains standard webpack utility functions for handling module exports, CSS detection, and base64 encoding/decoding. |
| dist/build/webpack/plugins/build-manifest-plugin-utils.js | safe | No malicious patterns detected; the code is a standard Next.js build-manifest utility with no network, credential, obfuscation, or process-spawning behavior. |
| dist/build/webpack/plugins/build-manifest-plugin.js | safe | No malicious patterns detected; the code is a standard Next.js webpack plugin for generating build manifests. |
| dist/build/webpack/plugins/copy-file-plugin.js | safe | The CopyFilePlugin is a legitimate webpack plugin that reads a file and emits it as an asset during compilation, with no malicious patterns detected. |
| dist/build/webpack/plugins/css-chunking-plugin.js | safe | No malicious patterns detected; the code is a legitimate webpack plugin for CSS chunk optimization with no network, filesystem, or process execution activities. |
| dist/build/webpack/plugins/css-minimizer-plugin.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/deferred-entries-plugin.js | safe | This is a standard Next.js webpack plugin that registers deferred entry points during the build process; no malicious patterns, network calls, credential access, or dynamic code execution were detected. |
| dist/build/webpack/plugins/devtools-ignore-list-plugin.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/eval-source-map-dev-tool-plugin.js | safe | This is a legitimate fork of webpack's EvalSourceMapDevToolPlugin used by Next.js to add ignoreList support for source maps; it contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or suspicious process/network activity. |
| dist/build/webpack/plugins/flight-client-entry-plugin.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack plugin for handling client entry points and server actions. |
| dist/build/webpack/plugins/flight-manifest-plugin.js | safe | This is a legitimate Next.js webpack plugin that generates client reference manifests for React Server Components; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, dynamic execution, or suspicious network/filesystem activity were detected. |
| dist/build/webpack/plugins/force-complete-runtime.js | safe | No malicious patterns detected; the code is a legitimate Next.js webpack plugin that adjusts chunk runtime requirements. |
| dist/build/webpack/plugins/jsconfig-paths-plugin.js | safe | No malicious patterns detected; the file implements a standard webpack resolver plugin for TypeScript/JavaScript path aliases without any suspicious behavior. |
| dist/build/webpack/plugins/memory-with-gc-cache-plugin.js | safe | No malicious patterns detected; the file implements a legitimate webpack memory cache plugin with TTL-based eviction. |
| dist/build/webpack/plugins/middleware-plugin.js | safe | This is a legitimate Next.js webpack plugin for analyzing Edge Runtime middleware code; no malicious patterns such as data exfiltration, credential harvesting, or backdoor installation were detected. |
| dist/build/webpack/plugins/mini-css-extract-plugin.js | safe | No malicious patterns detected; the file is a thin, legitimate wrapper around Next.js's bundled mini-css-extract-plugin that only subclasses it and sets a marker property. |
| dist/build/webpack/plugins/minify-webpack-plugin/src/index.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/next-font-manifest-plugin.js | safe | No malicious patterns detected; the code is a standard Next.js webpack plugin that builds a font manifest during compilation. |
| dist/build/webpack/plugins/next-trace-entrypoints-plugin.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack plugin that performs file tracing and dependency resolution using @vercel/nft. |
| dist/build/webpack/plugins/next-types-plugin/index.js | safe | This is a legitimate Next.js internal webpack plugin that generates TypeScript type definitions for app routes; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or unauthorized system access were detected. |
| dist/build/webpack/plugins/next-types-plugin/shared.js | safe | No malicious patterns detected; the file only defines a simple exported Set for tracking dev page files. |
| dist/build/webpack/plugins/nextjs-require-cache-hot-reloader.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack hot-reload plugin that clears the require cache and sandbox module context for emitted assets. |
| dist/build/webpack/plugins/optional-peer-dependency-resolve-plugin.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/pages-manifest-plugin.js | safe | No malicious patterns detected; the file is a standard Next.js webpack plugin that generates pages-manifest.json without network, credential, process, or obfuscated code activity. |
| dist/build/webpack/plugins/profiling-plugin.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/react-loadable-plugin.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack plugin for generating react-loadable manifests. |
| dist/build/webpack/plugins/rspack-flight-client-entry-plugin.js | safe | No malicious patterns detected; the file is a legitimate Next.js Rspack plugin implementation with only local module imports and standard build tooling logic. |
| dist/build/webpack/plugins/rspack-profiling-plugin.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/slow-module-detection-plugin.js | safe | This is a legitimate Next.js webpack plugin that measures module build times and prints a report to the console; it contains no network, filesystem, process, or dynamic code execution behavior. |
| dist/build/webpack/plugins/subresource-integrity-plugin.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/telemetry-plugin/telemetry-plugin.js | safe | No malicious patterns detected; the file implements a webpack telemetry plugin that only tracks module usage internally without any external data exfiltration, credential access, or dangerous dynamic execution. |
| dist/build/webpack/plugins/telemetry-plugin/update-telemetry-loader-context-from-swc.js | safe | No malicious patterns detected; the code only parses telemetry data and updates in-memory context objects. |
| dist/build/webpack/plugins/telemetry-plugin/use-cache-tracker-utils.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/wellknown-errors-plugin/getModuleTrace.js | safe | No malicious patterns detected; the code is a legitimate webpack error-trace formatting utility from Next.js with no network, filesystem, process, or credential-access activity. |
| dist/build/webpack/plugins/wellknown-errors-plugin/index.js | safe | The code is a webpack plugin that filters warnings and reformats module build errors; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution were detected. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parse-dynamic-code-evaluation-error.js | safe | No malicious patterns detected; this is a benign webpack plugin utility that formats dynamic code evaluation error messages. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseBabel.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseCss.js | safe | No malicious patterns detected; the code only parses CSS error messages and formats them for webpack build output. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseNextAppLoaderError.js | safe | The code is a standard Next.js webpack plugin helper that parses loader errors and contains no malicious patterns. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseNextFontError.js | safe | No malicious patterns detected; the code is a standard Next.js webpack plugin that formats font-related build errors without network, filesystem, or process activity. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseNextInvalidImportError.js | safe | No malicious patterns detected; the code is a standard Next.js webpack error parsing utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseNotFoundError.js | safe | No malicious patterns detected; the file only formats webpack errors for Next.js builds and contains no data exfiltration, obfuscation, dynamic execution, or suspicious network/file/process operations. |
| dist/build/webpack/plugins/wellknown-errors-plugin/parseScss.js | safe | No malicious patterns detected; the file only parses SCSS error messages and formats them for Webpack output. |
| dist/build/webpack/plugins/wellknown-errors-plugin/simpleWebpackError.js | safe | No malicious patterns detected |
| dist/build/webpack/plugins/wellknown-errors-plugin/webpackModuleError.js | safe | No malicious patterns detected |
| dist/build/webpack/stringify-request.js | safe | No malicious patterns detected |
| dist/build/webpack/utils.js | safe | No malicious patterns detected |
| dist/build/worker.js | safe | No malicious patterns detected; this is standard Next.js build worker code with no obfuscation, network calls, credential access, or suspicious lifecycle behavior. |
| dist/build/write-build-id.js | safe | No malicious patterns detected; the code simply writes a build ID file within the distribution directory. |
| dist/bundle-analyzer/_next/static/WF5Ql9w6rALUjSQk9e-fZ/_buildManifest.js | safe | No malicious patterns detected |
| dist/bundle-analyzer/_next/static/WF5Ql9w6rALUjSQk9e-fZ/_clientMiddlewareManifest.js | safe | No malicious patterns detected in the middleware manifest snippet. |
| dist/bundle-analyzer/_next/static/WF5Ql9w6rALUjSQk9e-fZ/_ssgManifest.js | safe | No malicious patterns detected; this is standard Next.js static site generation manifest initialization code. |
| dist/bundle-analyzer/_next/static/chunks/0.8z-24o~zj6q.js | safe | This is a standard Next.js/Turbopack bundle containing React and Next.js framework code with no malicious patterns detected. |
| dist/bundle-analyzer/_next/static/chunks/0nxgmn1p8~ej~.js | safe | This is a legitimate Next.js/Turbopack client-side bundle chunk containing React routing internals with no malicious patterns detected. |
| dist/bundle-analyzer/_next/static/chunks/turbopack-0_jd6_0ca14du.js | safe | This is a legitimate Turbopack runtime chunk loader for Next.js with no malicious patterns detected. |
| dist/cli/internal/query-trace.js | safe | The code is a CLI client that queries a local trace server via JSON-RPC over localhost; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution were detected. |
| dist/cli/internal/static-routes-info.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal CLI for static route bundle analysis with no network, credential, or process execution behavior. |
| dist/cli/next-analyze.js | safe | No malicious patterns detected; the code is a standard Next.js CLI analyze command with expected file system and process signal handling. |
| dist/cli/next-build.js | safe | No malicious patterns detected; this is a legitimate Next.js CLI build entry point that only reads environment variables for debugging/tracing flags and does not exfiltrate data or execute untrusted code. |
| dist/cli/next-export.js | safe | No malicious patterns detected |
| dist/cli/next-post-build.js | safe | No malicious patterns detected; the file is a legitimate Next.js post-build utility that compacts a local Turbopack cache database. |
| dist/cli/next-request-insights.js | safe | No malicious patterns detected; the code only queries a local Next.js dev server for request insights and reads a project lockfile. |
| dist/cli/next-telemetry.js | safe | No malicious patterns detected; this is a legitimate Next.js telemetry preference management CLI. |
| dist/cli/next-typegen.js | safe | This is a legitimate Next.js CLI type generation script that only performs expected build-time tasks (route discovery, TypeScript setup verification, writing .d.ts files) with no malicious patterns, external network calls, credential harvesting, or suspicious process execution. |
| dist/client/add-base-path.js | safe | This is a standard Next.js utility module for prepending a base path to URLs, with no malicious patterns or security concerns detected. |
| dist/client/add-locale.js | safe | No malicious patterns detected; the code is a benign Next.js i18n helper that conditionally adds locale prefixes to paths. |
| dist/client/app-bootstrap.js | safe | The file is a legitimate Next.js client-side bootstrap module with no malicious patterns; dynamic script loading is standard framework behavior scoped to self.__next_s. |
| dist/client/app-call-server.js | safe | No malicious patterns detected; this is a legitimate React/Next.js client-side server action dispatcher. |
| dist/client/app-dir/form.js | safe | No malicious patterns detected; the code is a standard Next.js client-side Form component with expected navigation and validation logic. |
| dist/client/app-dir/link.js | safe | No malicious patterns detected |
| dist/client/app-dir/link.react-server.js | safe | No malicious patterns detected; the file is a standard Next.js Link component with only local module imports and console error logging. |
| dist/client/app-find-source-map-url.js | safe | This is a legitimate Next.js internal client utility for resolving source map URLs; it performs no network exfiltration, process spawning, credential harvesting, or dynamic code execution. |
| dist/client/app-globals.js | safe | This is a standard Next.js internal client globals file with conditional dynamic imports and setup calls that are scoped to the framework's dev/testing features, showing no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/client/app-index.js | safe | No malicious patterns detected; this is standard Next.js App Router client hydration code. |
| dist/client/app-link-gc.js | safe | The code only performs client-side DOM cleanup of Next.js development link elements and contains no malicious patterns. |
| dist/client/app-next-dev.js | safe | This file is a standard Next.js development client bootstrap module with no malicious patterns detected. |
| dist/client/app-next-turbopack.js | safe | This is a standard Next.js Turbopack client bootstrap file; detected patterns are framework-internal dynamic requires and import-time hydration with no malicious indicators. |
| dist/client/app-next.js | safe | No malicious patterns detected; the file appears to be a standard Next.js client bootstrap module with legitimate require calls and no external data flows or dangerous operations. |
| dist/client/app-webpack.js | safe | No malicious patterns detected; the code only modifies webpack chunk filename handling using a deployment ID for legitimate asset URL construction. |
| dist/client/asset-prefix.js | safe | No malicious patterns detected; the code is a benign Next.js utility for computing asset prefix from the current script URL. |
| dist/client/assign-location.js | safe | No malicious patterns detected; the file only contains URL manipulation logic for relative path assignment. |
| dist/client/compat/router.js | safe | This is a standard Next.js router compatibility shim that only uses React context; no malicious patterns detected. |
| dist/client/components/app-router-announcer.js | safe | No malicious patterns detected; code is a legitimate Next.js accessibility component for route announcements. |
| dist/client/components/app-router-headers.js | safe | No malicious patterns detected |
| dist/client/components/app-router-instance.js | safe | This is a legitimate Next.js App Router client component that implements navigation, prefetching, and action queue management without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/client/components/app-router-utils.js | safe | No malicious patterns detected in this Next.js utility module; it only provides URL helpers for prefetching and does not perform any suspicious behavior. |
| dist/client/components/bfcache-state-manager.js | safe | No malicious patterns detected; the code is a standard React hook for managing a back/forward cache with no security concerns. |
| dist/client/components/builtin/app-error.js | safe | No malicious patterns detected; this is the standard Next.js static 500 error page component that only renders HTML/CSS and React markup at build time. |
| dist/client/components/builtin/default-null.js | safe | This is a standard Next.js internal module that exports a simple null-returning component with no malicious patterns. |
| dist/client/components/builtin/default.js | safe | This is a benign Next.js internal module that exports a parallel route default component which simply calls notFound(); no malicious patterns detected. |
| dist/client/components/builtin/empty-stub.js | safe | No malicious patterns detected; the file is a simple empty React/JSX stub that only defines a null-returning component and harmless CommonJS interop boilerplate. |
| dist/client/components/builtin/error-styles.js | safe | No malicious patterns detected; the file only defines static error-page styles, a CSS theme string, and an SVG warning icon. |
| dist/client/components/builtin/forbidden.js | safe | No malicious patterns detected; the file is a benign React component for a 403 Forbidden error page with no network, filesystem, or dynamic code execution behavior. |
| dist/client/components/builtin/global-error.js | safe | No malicious patterns detected |
| dist/client/components/builtin/global-not-found.js | safe | No malicious patterns detected |
| dist/client/components/builtin/layout.js | safe | No malicious patterns detected; the file is a standard React/Next.js default layout component with no network, filesystem, process, or dynamic code execution behavior. |
| dist/client/components/builtin/not-found.js | safe | No malicious patterns detected |
| dist/client/components/builtin/unauthorized.js | safe | No malicious patterns detected |
| dist/client/components/catch-error.js | safe | No malicious patterns detected; this is a standard Next.js React error boundary component with no data exfiltration, credential harvesting, obfuscation, or process/network abuse. |
| dist/client/components/client-boundary-params.browser.js | safe | No malicious patterns detected; the file only re-exports browser-side params/searchParams helpers with no network, filesystem, eval, or process activity. |
| dist/client/components/client-boundary-params.js | safe | No malicious patterns detected; this is a standard Next.js internal module that re-exports param/searchParam helpers with no network, filesystem, process, or dynamic code execution behavior. |
| dist/client/components/client-page.js | safe | This is a standard Next.js client page component that only imports React context and route parameter utilities, with no malicious patterns detected. |
| dist/client/components/client-segment.js | safe | No malicious patterns detected; the file is a legitimate Next.js client component for segment rendering with no external calls, obfuscation, or process execution. |
| dist/client/components/dev-root-http-access-fallback-boundary.js | safe | No malicious patterns detected; the file is a standard Next.js development component with no network, filesystem, process, or dynamic code execution activity. |
| dist/client/components/error-boundary.js | safe | No malicious patterns detected |
| dist/client/components/errors/root-error-boundary.js | safe | No malicious patterns detected; the code is a standard React error boundary that conditionally renders based on bot user-agent detection. |
| dist/client/components/forbidden.js | safe | This is a legitimate Next.js internal module implementing the experimental forbidden() function, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning. |
| dist/client/components/handle-isr-error.js | safe | No malicious patterns detected; the code appears to be a legitimate error handler for Incremental Static Regeneration in Next.js. |
| dist/client/components/hooks-server-context.js | safe | No malicious patterns detected; the file only defines a custom error class and a validator function for Next.js dynamic server usage errors. |
| dist/client/components/http-access-fallback/error-boundary.js | safe | No malicious patterns detected; this is a standard Next.js React error boundary component with no data exfiltration, credential harvesting, obfuscation, network requests, or process spawning. |
| dist/client/components/http-access-fallback/error-fallback.js | safe | No malicious patterns detected; the file is a standard React error fallback component with a static inline style. |
| dist/client/components/http-access-fallback/http-access-fallback.js | safe | No malicious patterns detected; the file contains standard HTTP error fallback utilities for Next.js with no network, filesystem, credential access, or dynamic code execution. |
| dist/client/components/instant-samples.browser.js | safe | No malicious patterns detected |
| dist/client/components/instant-samples.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal module for instrumenting route params and search params during client-side validation. |
| dist/client/components/instant-validation/boundary.js | safe | No malicious patterns detected; this is a standard Next.js client-side re-export module for validation boundary components. |
| dist/client/components/instant-validation/impl.browser.js | safe | This is a benign ES module export shim with no network, filesystem, process, or dynamic execution behavior; all exported values are null stubs. |
| dist/client/components/instant-validation/impl.js | safe | No malicious patterns detected |
| dist/client/components/is-next-router-error.js | safe | No malicious patterns detected |
| dist/client/components/links.js | safe | No malicious patterns detected; this is standard Next.js client-side link prefetching code with no data exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/client/components/match-segments.js | safe | No malicious patterns detected; the file contains a simple segment matching utility with no network, filesystem, or dynamic code execution activity. |
| dist/client/components/nav-failure-handler.js | safe | No malicious patterns detected; the code is a legitimate navigation failure handler from Next.js that recovers from errors by performing a hard navigation. |
| dist/client/components/navigation-devtools.js | safe | Legitimate Next.js dev-only instrumentation code with no malicious patterns, no network calls, no credential harvesting, and no dynamic code execution. |
| dist/client/components/navigation-dynamic-rendering.browser.js | safe | This is a benign browser stub module from Next.js that exports undefined placeholder hooks with no malicious patterns, network activity, or code execution. |
| dist/client/components/navigation-dynamic-rendering.js | safe | The module is a standard conditional re-export for browser/server code splitting in Next.js; it contains no network, filesystem, process, or code-execution activity. |
| dist/client/components/navigation-untracked.js | safe | The file contains standard React/Next.js internal navigation logic with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution. |
| dist/client/components/navigation.js | safe | This is a legitimate Next.js client navigation module that only re-exports React hooks and server navigation utilities without any malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or shell access. |
| dist/client/components/navigation.react-server.js | safe | No malicious patterns detected |
| dist/client/components/noop-head.js | safe | No malicious patterns detected |
| dist/client/components/not-found.js | safe | No malicious patterns detected; the file is a standard Next.js internal implementation of the notFound() function. |
| dist/client/components/offline.js | safe | No malicious patterns detected; the code implements legitimate offline detection and connectivity retry logic for a client-side web application. |
| dist/client/components/promise-queue.js | safe | No malicious patterns detected; the code is a straightforward promise queue implementation with no network, filesystem, or process manipulation. |
| dist/client/components/readonly-url-search-params.js | safe | No malicious patterns detected; the file is a legitimate Next.js ReadonlyURLSearchParams implementation that only disables mutating URLSearchParams methods. |
| dist/client/components/redirect-boundary.js | safe | No malicious patterns detected |
| dist/client/components/redirect-error.js | safe | No malicious patterns detected; the code is a standard Next.js redirect error handler with no data exfiltration, dynamic execution, or other security concerns. |
| dist/client/components/redirect-status-code.js | safe | No malicious patterns detected |
| dist/client/components/redirect.js | safe | This is a legitimate Next.js internal module for handling redirect errors; no malicious patterns detected. |
| dist/client/components/render-from-template-context.js | safe | This is a benign React server component that reads a template context and renders its children, with no malicious patterns detected. |
| dist/client/components/router-reducer/compute-changed-path.js | safe | No malicious patterns detected; the file contains legitimate Next.js router path computation logic with no network, filesystem, process execution, or obfuscated code. |
| dist/client/components/router-reducer/create-href-from-url.js | safe | No malicious patterns detected |
| dist/client/components/router-reducer/create-initial-router-state.js | safe | This file is part of Next.js's client-side router initialization logic and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or network requests to untrusted endpoints. |
| dist/client/components/router-reducer/create-router-cache-key.js | safe | No malicious patterns detected |
| dist/client/components/router-reducer/fetch-server-response.js | safe | This is a legitimate Next.js internal client-side RSC fetch/decode module; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were found. |
| dist/client/components/router-reducer/is-navigating-to-new-root-layout.js | safe | No malicious patterns detected; the code is a pure recursive comparison function for Next.js router state with no network, filesystem, process, or dynamic code execution activity. |
| dist/client/components/router-reducer/ppr-navigations.js | safe | No malicious patterns detected; this is legitimate Next.js PPR navigation internals without exfiltration, credential harvesting, obfuscation, or harmful dynamic execution. |
| dist/client/components/router-reducer/reducers/committed-state.js | safe | The file contains only benign module export logic and a simple in-memory state variable with no suspicious network, filesystem, process, or dynamic execution behavior. |
| dist/client/components/router-reducer/reducers/find-head-in-cache.js | safe | No malicious patterns detected; the code is a straightforward recursive cache lookup utility without network, filesystem, process, or dynamic execution behavior. |
| dist/client/components/router-reducer/reducers/has-interception-route-in-current-tree.js | safe | No malicious patterns detected; the code is a standard Next.js router utility for checking interception routes in the current tree. |
| dist/client/components/router-reducer/reducers/hmr-refresh-reducer.js | safe | No malicious patterns detected; the file is a standard Next.js router reducer for HMR refresh handling. |
| dist/client/components/router-reducer/reducers/navigate-reducer.js | safe | No malicious patterns detected; this is standard Next.js router reducer code that only reads environment variables for staleness configuration and performs client-side navigation without exfiltration, dynamic execution, or filesystem/process access. |
| dist/client/components/router-reducer/reducers/refresh-reducer.js | safe | This is a legitimate Next.js client-side router refresh reducer with no malicious patterns detected; all imports are internal framework modules, no network calls, no filesystem/process access, and no dynamic code execution. |
| dist/client/components/router-reducer/reducers/restore-reducer.js | safe | No malicious patterns detected; the code is a legitimate React/Next.js router reducer for restoring navigation state. |
| dist/client/components/router-reducer/reducers/server-action-reducer.js | safe | This is a legitimate Next.js internal client router reducer implementing server action handling; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or backdoors were detected. |
| dist/client/components/router-reducer/reducers/server-patch-reducer.js | safe | No malicious patterns detected |
| dist/client/components/router-reducer/router-reducer-types.js | safe | No malicious patterns detected |
| dist/client/components/router-reducer/router-reducer.js | safe | No malicious patterns detected; the file is a standard Next.js router reducer with conditional development-only dynamic require. |
| dist/client/components/router-reducer/set-cache-busting-search-param.js | safe | The file is a legitimate Next.js client-side router utility that computes and sets a cache-busting search parameter, with no malicious patterns detected. |
| dist/client/components/router-transition.js | safe | No malicious patterns detected; the code is a legitimate Next.js router transition instrumentation module with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/client/components/segment-cache/bfcache.js | safe | The file is a legitimate Next.js client-side back/forward cache module with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/client/components/segment-cache/cache-key.js | safe | No malicious patterns detected; the code only defines utility functions for cache key creation and pathname splitting. |
| dist/client/components/segment-cache/cache-map.js | safe | No malicious patterns detected; the file is a standard LRU cache map implementation using only internal imports and no network, filesystem, process, or dynamic code execution. |
| dist/client/components/segment-cache/fetch.js | safe | No malicious patterns detected; the code is a benign internal fetch wrapper with controlled feature-flag gating and no external data flows or dangerous operations. |
| dist/client/components/segment-cache/lru.js | safe | The code implements a standard LRU cache for memory management in Next.js and contains no malicious patterns, network activity, credential harvesting, or dynamic code execution. |
| dist/client/components/segment-cache/navigation-testing-lock.disabled.js | safe | This is a benign inert stub module for Next.js's navigation testing lock, exporting no-op functions with no network, filesystem, process, or dynamic code execution behavior. |
| dist/client/components/segment-cache/navigation.js | safe | No malicious patterns detected; this is legitimate Next.js client-side navigation code with normal framework imports and no exfiltration, dynamic execution, or suspicious behavior. |
| dist/client/components/segment-cache/optimistic-routes.js | safe | No malicious patterns detected; the module is a legitimate Next.js client-side route prediction mechanism with no network, filesystem, process, or credential access. |
| dist/client/components/segment-cache/prefetch.js | safe | No malicious patterns detected; the code is a standard client-side prefetch utility that only performs internal cache scheduling and URL validation. |
| dist/client/components/segment-cache/scheduler.js | safe | This is a legitimate Next.js prefetch scheduler module containing only queue management, cache coordination, and heap logic with no malicious patterns. |
| dist/client/components/segment-cache/types.js | safe | This file only defines TypeScript-style enums and CommonJS export boilerplate for the Segment Cache; no malicious patterns, network activity, dynamic execution, or install-time behavior were detected. |
| dist/client/components/segment-cache/vary-path.js | safe | No malicious patterns detected; the code is a pure vary-path cache key construction module with no network, filesystem, process, or dynamic execution activity. |
| dist/client/components/server-async-storage.browser.js | safe | No malicious patterns detected; the file is a trivial browser stub that exports undefined async-storage singletons with no network, filesystem, process, or dynamic code activity. |
| dist/client/components/server-async-storage.js | safe | No malicious patterns detected; the module is a straightforward re-export of server-side AsyncLocalStorage singletons with a documented browser-safe alias mechanism. |
| dist/client/components/static-generation-bailout.js | safe | No malicious patterns detected; the file is a benign Next.js error utility with standard module exports and no I/O, network, or execution of untrusted code. |
| dist/client/components/styles/access-error-styles.js | safe | No malicious patterns detected |
| dist/client/components/unauthorized.js | safe | No malicious patterns detected; this is a standard Next.js experimental error-throwing utility with no data exfiltration, credential harvesting, obfuscation, network calls, or suspicious behavior. |
| dist/client/components/unrecognized-action-error.js | safe | No malicious patterns detected; the file only defines a custom error class and a type guard for Next.js internal use. |
| dist/client/components/unresolved-thenable.js | safe | No malicious patterns detected |
| dist/client/components/unstable-rethrow.browser.js | safe | No malicious patterns detected |
| dist/client/components/unstable-rethrow.js | safe | No malicious patterns detected; the file is a standard Next.js internal utility for rethrowing framework-specific errors. |
| dist/client/components/use-action-queue.js | safe | No malicious patterns detected; this is a legitimate Next.js internal React hook module for app router action queue management with no exfiltration, obfuscation, process spawning, or suspicious network/filesystem activity. |
| dist/client/components/use-offline.js | safe | No malicious patterns detected; the module is a standard React context provider for offline state management using only local React APIs with no network, filesystem, process, or obfuscated code. |
| dist/client/detect-domain-locale.js | safe | No malicious patterns detected; the code is a standard Next.js i18n module with conditional dynamic require gated by an environment variable. |
| dist/client/dev/debug-channel.js | safe | This Next.js debug-channel module uses IndexedDB and navigation timing APIs for legitimate client-side debug chunk persistence and restoration; no exfiltration, credential harvesting, obfuscation, process spawning, or other malicious patterns are present. |
| dist/client/dev/error-overlay/websocket.js | safe | No malicious patterns detected; the file only re-exports addMessageListener from an internal Next.js hot-reloader websocket module. |
| dist/client/dev/fouc.js | safe | No malicious patterns detected; the code is a legitimate FOUC removal utility that safely schedules DOM cleanup. |
| dist/client/dev/hot-middleware-client.js | safe | This is a legitimate Next.js development hot-reload middleware client that handles HMR events via WebSocket and page reloads without any malicious patterns. |
| dist/client/dev/hot-reloader/app/hot-reloader-app.js | safe | This is Next.js's development hot-reload client code; it uses only expected HMR/dev-tooling APIs with no exfiltration, credential harvesting, obfuscation, process spawning, or other malicious patterns. |
| dist/client/dev/hot-reloader/get-socket-url.js | safe | No malicious patterns detected; the file only computes a WebSocket URL for Next.js hot reloading using standard browser APIs and a local utility module. |
| dist/client/dev/hot-reloader/shared.js | safe | No malicious patterns detected; the file only exports constants and a warning helper for React Fast Refresh HMR messaging. |
| dist/client/dev/hot-reloader/turbopack-hot-reloader-common.js | safe | This is a legitimate Next.js Turbopack HMR utility module with no malicious patterns: it only uses console logging, timers, and message parsing for hot-module reloading, with no network, filesystem, process, or dynamic code execution. |
| dist/client/dev/noop-turbopack-hmr.js | safe | This is a benign no-op stub for Turbopack HMR used in webpack builds, containing no malicious patterns, network activity, credential access, or dynamic code execution. |
| dist/client/dev/on-demand-entries-client.js | safe | No malicious patterns detected; the code is a standard Next.js development client that sends periodic ping messages to the local dev websocket server. |
| dist/client/dev/report-hmr-latency.js | safe | No malicious patterns detected; the file only logs HMR latency and sends telemetry to the dev server as documented. |
| dist/client/dev/runtime-error-handler.js | safe | No malicious patterns detected; the file only defines a simple runtime error handler object with standard CommonJS export interop. |
| dist/client/flight-data-helpers.js | safe | No malicious patterns detected; this is a standard Next.js flight data helper module with no signs of data exfiltration, credential harvesting, obfuscated code, or backdoor behavior. |
| dist/client/form-shared.js | safe | The code is a legitimate Next.js client-side form validation utility with no malicious patterns, exfiltration, or suspicious behavior detected. |
| dist/client/form.js | safe | No malicious patterns detected; the file is a legitimate Next.js client-side Form component that handles navigation and form submission without any exfiltration, obfuscation, or suspicious behavior. |
| dist/client/get-domain-locale.js | safe | No malicious patterns detected; the code is a standard Next.js utility for resolving domain locales with only static require calls and no external I/O. |
| dist/client/has-base-path.js | safe | The file contains standard Next.js base path utility logic with no malicious patterns, data exfiltration, or dynamic code execution. |
| dist/client/image-component.js | safe | This is the legitimate Next.js Image component with no malicious patterns or security concerns detected. |
| dist/client/index.js | safe | This is a legitimate Next.js client runtime bundle; no malicious patterns such as exfiltration, credential harvesting, obfuscated payloads, or shell execution were detected. |
| dist/client/legacy/image.js | safe | No malicious patterns detected; this is a legitimate Next.js legacy image component with only standard image optimization, URL handling, and deprecation warnings. |
| dist/client/lib/console.js | safe | No malicious patterns detected; the code is a benign console argument formatter and parser for a Next.js-like client library. |
| dist/client/lib/javascript-url.js | safe | The code is a defensive utility for detecting javascript: URL schemes, adapted from React's sanitizeURL, with no malicious patterns detected. |
| dist/client/lib/promise.js | safe | No malicious patterns detected |
| dist/client/link.js | safe | No malicious patterns detected; this is a standard Next.js Link component implementation with no data exfiltration, credential harvesting, obfuscated code, or suspicious behavior. |
| dist/client/navigation-build-id.js | safe | No malicious patterns detected; the module only manages a global build ID string used for client-server synchronization. |
| dist/client/next-dev-turbopack.js | safe | This file is a legitimate Next.js development client entry point for Turbopack HMR with no malicious patterns detected. |
| dist/client/next-dev.js | safe | No malicious patterns detected; this is standard Next.js development client initialization code. |
| dist/client/next-turbopack.js | safe | No malicious patterns detected; the file is a standard Next.js Turbopack client entry point with expected initialization and hydration logic. |
| dist/client/next.js | safe | No malicious patterns detected; this is a standard Next.js client entry point with no obfuscation, data exfiltration, or suspicious runtime behavior. |
| dist/client/normalize-trailing-slash.js | safe | No malicious patterns detected |
| dist/client/page-bootstrap.js | safe | This is Next.js's legitimate development-time HMR page bootstrap module; all network activity and dynamic behavior are expected dev-server features with no malicious patterns detected. |
| dist/client/page-loader.js | safe | This is a legitimate Next.js client-side page loader module with no malicious patterns detected. |
| dist/client/portal/index.js | safe | This is a standard React Portal component implementation with no malicious patterns detected. |
| dist/client/react-client-callbacks/error-boundary-callbacks.js | safe | This is a legitimate Next.js error boundary callback module with no malicious patterns, exfiltration, or suspicious behavior detected. |
| dist/client/react-client-callbacks/on-recoverable-error.js | safe | This is a standard Next.js internal error handling module with no malicious patterns, no data exfiltration, no credential harvesting, and no dynamic code execution. |
| dist/client/react-client-callbacks/report-global-error.js | safe | No malicious patterns detected; the file only re-exports a global error reporting helper using console.error or reportError with no external calls or dangerous operations. |
| dist/client/register-deployment-id-global.js | safe | No malicious patterns detected; the code simply retrieves a deployment ID and assigns it to a global variable. |
| dist/client/remove-base-path.js | safe | No malicious patterns detected |
| dist/client/remove-locale.js | safe | No malicious patterns detected; the code is a benign utility for removing locale prefixes from URL paths in Next.js. |
| dist/client/request-idle-callback.js | safe | No malicious patterns detected |
| dist/client/request/io.browser.js | safe | No malicious patterns detected |
| dist/client/request/params.browser.dev.js | safe | No malicious patterns detected; this is a Next.js development module that wraps params in a Proxy for synchronous access warnings. |
| dist/client/request/params.browser.js | safe | No malicious patterns detected; the file only conditionally requires development or production parameter modules based on NODE_ENV and re-exports a helper function. |
| dist/client/request/params.browser.prod.js | safe | No malicious patterns detected |
| dist/client/request/search-params.browser.dev.js | safe | No malicious patterns detected; the code is a legitimate Next.js development helper that proxies searchParams to warn about synchronous access, with no exfiltration, obfuscation, or other security red flags. |
| dist/client/request/search-params.browser.prod.js | safe | No malicious patterns detected; the code is a straightforward Next.js browser production module for caching search params with no network, filesystem, or code execution behavior. |
| dist/client/resolve-href.js | safe | No malicious patterns detected; the file contains standard Next.js URL resolution logic without any security concerns. |
| dist/client/route-announcer.js | safe | No malicious patterns detected; the file is a legitimate Next.js RouteAnnouncer accessibility component with no network, filesystem, process, or code execution risks. |
| dist/client/route-loader.js | safe | This is a legitimate Next.js client-side route loader module with no malicious patterns detected. |
| dist/client/route-params.js | safe | No malicious patterns detected; the file contains legitimate Next.js route parameter handling utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious execution. |
| dist/client/router-transition-types.js | safe | No malicious patterns detected; the file contains only standard module export boilerplate and a source map reference. |
| dist/client/router.js | safe | No malicious patterns detected; the code is a standard Next.js client router module with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/client/set-attributes-from-props.js | safe | No malicious patterns detected; the code is a legitimate utility for setting DOM attributes from React props, consistent with Next.js internals. |
| dist/client/tracing/report-to-socket.js | safe | The file is a standard Next.js tracing utility that forwards span data to an internal dev websocket; no malicious patterns, credential harvesting, or obfuscation were detected. |
| dist/client/tracing/tracer.js | safe | No malicious patterns detected; the code is a legitimate tracing implementation using expected modules. |
| dist/client/trusted-types.js | safe | No malicious patterns detected; the code is a standard Next.js Trusted Types polyfill that creates a permissive policy but does not exfiltrate data, execute dynamic code, or perform any suspicious operations. |
| dist/client/use-client-disallowed.js | safe | No malicious patterns detected; the code is a Next.js internal guard that throws an error when Client Components are imported in an unsupported environment. |
| dist/client/use-intersection.js | safe | No malicious patterns detected |
| dist/client/use-merged-ref.js | safe | The file contains a standard React hook utility for merging refs with no suspicious behavior, network access, filesystem operations, or dynamic code execution. |
| dist/client/web-vitals.js | safe | No malicious patterns detected; the file is a standard Next.js React hook for reporting Web Vitals metrics to a user-provided callback. |
| dist/client/webpack.js | safe | This is a standard Next.js client webpack runtime module that conditionally appends a deployment ID asset token to chunk filenames; it contains no network requests, process spawning, credential access, obfuscation, or other malicious patterns. |
| dist/client/with-router.js | safe | No malicious patterns detected; the file is a standard Next.js withRouter HOC helper with no exfiltration, code execution, or suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/AwaitValue.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/OverloadYield.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/applyDecoratedDescriptor.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/applyDecs.js | safe | No malicious patterns detected in this Babel decorators helper, which contains only legitimate decorator transformation logic without network, file system, process, or credential access. |
| dist/compiled/@babel/runtime/helpers/applyDecs2203.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/applyDecs2203R.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/applyDecs2301.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/applyDecs2305.js | safe | No malicious patterns detected; this is a standard Babel helper for decorator semantics with no network, filesystem, process, or obfuscated code. |
| dist/compiled/@babel/runtime/helpers/applyDecs2311.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/arrayLikeToArray.js | safe | This is a benign Babel helper function that converts array-like objects to arrays with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/arrayWithHoles.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/arrayWithoutHoles.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/assertClassBrand.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/assertThisInitialized.js | safe | No malicious patterns detected; the file is a standard Babel helper that validates this initialization. |
| dist/compiled/@babel/runtime/helpers/asyncGeneratorDelegate.js | safe | No malicious patterns detected; this is a standard Babel helper for async generator delegation. |
| dist/compiled/@babel/runtime/helpers/asyncIterator.js | safe | No malicious patterns detected; this is a standard Babel helper for async iteration with no network, filesystem, process, or dynamic code execution activity. |
| dist/compiled/@babel/runtime/helpers/asyncToGenerator.js | safe | No malicious patterns detected; this is the standard Babel asyncToGenerator helper for converting async functions to generator-based promise chains. |
| dist/compiled/@babel/runtime/helpers/awaitAsyncGenerator.js | safe | No malicious patterns detected; the file is a simple Babel helper that wraps a value in an OverloadYield object without any dangerous operations. |
| dist/compiled/@babel/runtime/helpers/callSuper.js | safe | This is a standard Babel helper function for calling super constructors, with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/checkInRHS.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/checkPrivateRedeclaration.js | safe | No malicious patterns detected; the code is a standard Babel helper for private field redeclaration checks with no network, filesystem, process, or dynamic execution behavior. |
| dist/compiled/@babel/runtime/helpers/classApplyDescriptorDestructureSet.js | safe | No malicious patterns detected; the file is a standard Babel helper for private field destructuring assignment. |
| dist/compiled/@babel/runtime/helpers/classApplyDescriptorGet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classApplyDescriptorSet.js | safe | No malicious patterns detected; the code is a standard Babel helper for setting private class fields with proper validation and no external interactions. |
| dist/compiled/@babel/runtime/helpers/classCallCheck.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classCheckPrivateStaticAccess.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classCheckPrivateStaticFieldDescriptor.js | safe | No malicious patterns detected; the file is a benign Babel helper function for checking private static field declarations. |
| dist/compiled/@babel/runtime/helpers/classExtractFieldDescriptor.js | safe | No malicious patterns detected; the file is a simple Babel helper that delegates to another local module. |
| dist/compiled/@babel/runtime/helpers/classNameTDZError.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldGet.js | safe | No malicious patterns detected; this is a standard Babel helper for accessing private class fields. |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldGet2.js | safe | No malicious patterns detected; this is a standard Babel helper for private field access with no external, network, filesystem, or process activity. |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldInitSpec.js | safe | This is a standard Babel helper for private field initialization with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldLooseBase.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private field access checks. |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldLooseKey.js | safe | No malicious patterns detected in this small utility module that generates unique private field key names. |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldSet.js | safe | No malicious patterns detected; this is a standard Babel helper for setting private class fields. |
| dist/compiled/@babel/runtime/helpers/classPrivateFieldSet2.js | safe | No malicious patterns detected; the helper performs a standard private field set using class brand assertion without any external calls, dynamic execution, or I/O. |
| dist/compiled/@babel/runtime/helpers/classPrivateGetter.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private getter access. |
| dist/compiled/@babel/runtime/helpers/classPrivateMethodGet.js | safe | No malicious patterns detected; this is a standard Babel helper for private method access. |
| dist/compiled/@babel/runtime/helpers/classPrivateMethodInitSpec.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classPrivateMethodSet.js | safe | The file contains a standard Babel helper that throws a TypeError when attempting to reassign a private method; no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/classPrivateSetter.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classStaticPrivateFieldDestructureSet.js | safe | No malicious patterns detected; this is a standard Babel helper for private static field destructuring assignment. |
| dist/compiled/@babel/runtime/helpers/classStaticPrivateFieldSpecGet.js | safe | No malicious patterns detected; this is a standard Babel helper for private static field access with no network, filesystem, process, or dynamic code execution behavior. |
| dist/compiled/@babel/runtime/helpers/classStaticPrivateFieldSpecSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/classStaticPrivateMethodGet.js | safe | No malicious patterns detected; the file is a standard Babel helper for accessing static private methods. |
| dist/compiled/@babel/runtime/helpers/classStaticPrivateMethodSet.js | safe | No malicious patterns detected in this Babel runtime helper that only throws a TypeError for read-only static private field assignments. |
| dist/compiled/@babel/runtime/helpers/construct.js | safe | No malicious patterns detected; this is a standard Babel helper for Reflect.construct fallback. |
| dist/compiled/@babel/runtime/helpers/createClass.js | safe | No malicious patterns detected; the code is a standard Babel helper for defining class properties. |
| dist/compiled/@babel/runtime/helpers/createForOfIteratorHelper.js | safe | No malicious patterns detected; this is a standard Babel transpilation helper for for-of iteration. |
| dist/compiled/@babel/runtime/helpers/createForOfIteratorHelperLoose.js | safe | No malicious patterns detected; the file is a standard Babel helper for loose for-of iteration with no network, filesystem, process, or dynamic code execution behavior. |
| dist/compiled/@babel/runtime/helpers/createSuper.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for creating superclass constructors. |
| dist/compiled/@babel/runtime/helpers/decorate.js | safe | This is a standard Babel helper for JavaScript decorator transforms with no malicious patterns, network calls, credential access, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/defaults.js | safe | No malicious patterns detected; the code is a standard utility for copying default properties, with no network, filesystem, or process activity. |
| dist/compiled/@babel/runtime/helpers/defineAccessor.js | safe | No malicious patterns detected; the code is a standard Babel helper for defining object properties. |
| dist/compiled/@babel/runtime/helpers/defineEnumerableProperties.js | safe | This is a standard Babel helper function that defines enumerable properties; it contains no malicious patterns, network activity, credential access, dynamic code execution, or lifecycle scripts. |
| dist/compiled/@babel/runtime/helpers/defineProperty.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/dispose.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing the explicit resource management dispose protocol with SuppressedError support, containing no network, filesystem, process, or dynamic execution behavior. |
| dist/compiled/@babel/runtime/helpers/esm/AwaitValue.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/OverloadYield.js | safe | No malicious patterns detected; the file defines a simple constructor function and exports it as default. |
| dist/compiled/@babel/runtime/helpers/esm/applyDecoratedDescriptor.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/applyDecs.js | safe | No malicious patterns detected; the code is a standard Babel helper for implementing decorators and metadata, with no network, filesystem, process execution, or obfuscated behavior. |
| dist/compiled/@babel/runtime/helpers/esm/applyDecs2203.js | safe | No malicious patterns detected in this Babel decorator helper implementation. |
| dist/compiled/@babel/runtime/helpers/esm/applyDecs2203R.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/applyDecs2301.js | safe | No malicious patterns detected; this is a standard Babel runtime decorator helper with no network, filesystem, process, or dynamic code execution concerns. |
| dist/compiled/@babel/runtime/helpers/esm/applyDecs2305.js | safe | This is a legitimate Babel helper implementing the ES decorators proposal (applyDecs2305) with no malicious patterns, network access, file system manipulation, or obfuscated code. |
| dist/compiled/@babel/runtime/helpers/esm/applyDecs2311.js | safe | Legitimate Babel runtime helper for decorator application, no malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/arrayLikeToArray.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/arrayWithHoles.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/arrayWithoutHoles.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/assertClassBrand.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/assertThisInitialized.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/asyncGeneratorDelegate.js | safe | No malicious patterns detected; this is a standard Babel helper for async generator delegation. |
| dist/compiled/@babel/runtime/helpers/esm/asyncIterator.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for async iterator support with no network, filesystem, or code execution behavior. |
| dist/compiled/@babel/runtime/helpers/esm/asyncToGenerator.js | safe | No malicious patterns detected; the code is a standard Babel async-to-generator helper with no network, filesystem, process, or obfuscation activity. |
| dist/compiled/@babel/runtime/helpers/esm/awaitAsyncGenerator.js | safe | The file is a trivial Babel helper that wraps a value in an OverloadYield object with no malicious behavior or side effects. |
| dist/compiled/@babel/runtime/helpers/esm/callSuper.js | safe | No malicious patterns detected; this is a standard Babel transpilation helper for calling super constructors with no external network, filesystem, or code execution activity. |
| dist/compiled/@babel/runtime/helpers/esm/checkInRHS.js | safe | No malicious patterns detected; the file is a standard Babel helper function for validating the right-hand side of 'in' operators. |
| dist/compiled/@babel/runtime/helpers/esm/checkPrivateRedeclaration.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classApplyDescriptorDestructureSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classApplyDescriptorGet.js | safe | No malicious patterns detected; the code only provides a simple helper for accessing class descriptor values via getters or direct values. |
| dist/compiled/@babel/runtime/helpers/esm/classApplyDescriptorSet.js | safe | This is a standard Babel helper function for applying values to class private fields with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/esm/classCallCheck.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classCheckPrivateStaticAccess.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/@babel/runtime/helpers/esm/classCheckPrivateStaticFieldDescriptor.js | safe | No malicious patterns detected; the code is a simple helper function that throws a TypeError when a private static field is accessed before its declaration. |
| dist/compiled/@babel/runtime/helpers/esm/classExtractFieldDescriptor.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classNameTDZError.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldGet.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for private class field access with no suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldGet2.js | safe | No malicious patterns detected; the code is a legitimate Babel helper for private field access with no suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldInitSpec.js | safe | This is a standard Babel helper for initializing private class fields; it performs no network, filesystem, or process operations and contains no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldLooseBase.js | safe | This is a standard Babel helper function for private field access with no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldLooseKey.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldSet2.js | safe | This is a standard Babel transpilation helper for setting private class fields, with no malicious patterns or security concerns. |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateGetter.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateMethodGet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateMethodInitSpec.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateMethodSet.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/@babel/runtime/helpers/esm/classPrivateSetter.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateFieldDestructureSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateFieldSpecGet.js | safe | No malicious patterns detected; this is a standard Babel helper for accessing private static fields. |
| dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateFieldSpecSet.js | safe | No malicious patterns detected in this Babel helper module; it is a straightforward static private field setter with no network, filesystem, or code execution behavior. |
| dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateMethodGet.js | safe | No malicious patterns detected; the file is a small helper that asserts a class brand and returns a method reference. |
| dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateMethodSet.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/@babel/runtime/helpers/esm/construct.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/createClass.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/createForOfIteratorHelper.js | safe | The file is a standard Babel transpilation helper for iterating over iterables and contains no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/esm/createForOfIteratorHelperLoose.js | safe | No malicious patterns detected; this is a standard Babel helper for iterating objects safely. |
| dist/compiled/@babel/runtime/helpers/esm/createSuper.js | safe | The code is a standard Babel helper for extending ES6 classes, using only safe reflection and prototype utilities with no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/esm/decorate.js | safe | No malicious patterns detected; the code is a standard Babel helper for implementing the JavaScript decorators proposal. |
| dist/compiled/@babel/runtime/helpers/esm/defaults.js | safe | No malicious patterns detected; the code is a standard utility function for copying configurable own properties from a source object to a target object. |
| dist/compiled/@babel/runtime/helpers/esm/defineAccessor.js | safe | This is a standard Babel helper function for defining object accessors; no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/esm/defineEnumerableProperties.js | safe | No malicious patterns detected; this is a standard Babel helper function for defining enumerable properties. |
| dist/compiled/@babel/runtime/helpers/esm/defineProperty.js | safe | Legitimate Babel helper for defining object properties with no malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/dispose.js | safe | No malicious patterns detected; the code is a standard polyfill/polyfill-like implementation for resource disposal (using SuppressedError) with no network, filesystem, process, or dynamic code execution behavior. |
| dist/compiled/@babel/runtime/helpers/esm/extends.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/get.js | safe | This is a standard Babel helper for Reflect.get with super property fallback, containing no malicious patterns or suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/esm/getPrototypeOf.js | safe | No malicious patterns detected; this is a standard Babel helper for getPrototypeOf with no network, filesystem, process, or dynamic execution behavior. |
| dist/compiled/@babel/runtime/helpers/esm/identity.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/importDeferProxy.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/inherits.js | safe | No malicious patterns detected; this is a standard Babel helper for prototypal inheritance. |
| dist/compiled/@babel/runtime/helpers/esm/inheritsLoose.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/initializerDefineProperty.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/initializerWarningHelper.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/instanceof.js | safe | No malicious patterns detected; the code is a standard Babel helper implementing an instanceof polyfill with no network, filesystem, process, or dynamic execution behavior. |
| dist/compiled/@babel/runtime/helpers/esm/interopRequireDefault.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/interopRequireWildcard.js | safe | This is a standard Babel runtime helper for interoperating CommonJS modules with ES modules, containing no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/esm/isNativeFunction.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/isNativeReflectConstruct.js | safe | This is a standard Babel helper for detecting native Reflect.construct support with no malicious patterns, network calls, filesystem access, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/esm/iterableToArray.js | safe | No malicious patterns detected; the code is a standard Babel helper that safely converts iterables to arrays without side effects or external access. |
| dist/compiled/@babel/runtime/helpers/esm/iterableToArrayLimit.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays. |
| dist/compiled/@babel/runtime/helpers/esm/jsx.js | safe | No malicious patterns detected; the code is a standard React element creation helper with no network, filesystem, process, or obfuscation concerns. |
| dist/compiled/@babel/runtime/helpers/esm/maybeArrayLike.js | safe | No malicious patterns detected; this is a benign Babel helper for array-like handling. |
| dist/compiled/@babel/runtime/helpers/esm/newArrowCheck.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/nonIterableRest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/@babel/runtime/helpers/esm/nonIterableSpread.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/@babel/runtime/helpers/esm/nullishReceiverError.js | safe | No malicious patterns detected; the file only defines a helper that throws a TypeError. |
| dist/compiled/@babel/runtime/helpers/esm/objectDestructuringEmpty.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/objectSpread.js | safe | No malicious patterns detected; the file is a standard Babel helper for object spread compatibility. |
| dist/compiled/@babel/runtime/helpers/esm/objectSpread2.js | safe | No malicious patterns detected; this is a standard Babel helper for object spread syntax with no network, filesystem, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/esm/objectWithoutProperties.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/objectWithoutPropertiesLoose.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/possibleConstructorReturn.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/readOnlyError.js | safe | The file contains a trivial Babel-style helper that throws a TypeError for read-only property assignments, with no network, filesystem, process, credential, or obfuscation concerns. |
| dist/compiled/@babel/runtime/helpers/esm/regeneratorRuntime.js | safe | This is a legitimate copy of Facebook's regenerator-runtime helper from Babel, containing only generator/async runtime polyfill code with no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/esm/set.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/setFunctionName.js | safe | No malicious patterns detected; the code is a straightforward utility for setting function names with safe property definition and error handling. |
| dist/compiled/@babel/runtime/helpers/esm/setPrototypeOf.js | safe | No malicious patterns detected; this is a standard Babel helper for setting an object's prototype. |
| dist/compiled/@babel/runtime/helpers/esm/skipFirstGeneratorNext.js | safe | No malicious patterns detected; the code is a standard helper for skipping the first yield of a generator function. |
| dist/compiled/@babel/runtime/helpers/esm/slicedToArray.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/superPropBase.js | safe | No malicious patterns detected; the file is a standard Babel helper for accessing superclass properties. |
| dist/compiled/@babel/runtime/helpers/esm/superPropGet.js | safe | No malicious patterns detected; the file is a benign Babel helper for accessing superclass properties. |
| dist/compiled/@babel/runtime/helpers/esm/superPropSet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/taggedTemplateLiteral.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/taggedTemplateLiteralLoose.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/tdz.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/temporalRef.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/temporalUndefined.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/toArray.js | safe | No malicious patterns detected; the file implements a standard Babel helper for converting iterables to arrays with no suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/esm/toConsumableArray.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/@babel/runtime/helpers/esm/toPrimitive.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/toPropertyKey.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting values to property keys. |
| dist/compiled/@babel/runtime/helpers/esm/toSetter.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/tsRewriteRelativeImportExtensions.js | safe | No malicious patterns detected; the code is a benign utility that rewrites TypeScript import extensions to JavaScript equivalents. |
| dist/compiled/@babel/runtime/helpers/esm/typeof.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/esm/unsupportedIterableToArray.js | safe | No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays. |
| dist/compiled/@babel/runtime/helpers/esm/using.js | safe | No malicious patterns detected; this is a standard Babel helper implementing the TC39 'using' declaration disposal mechanism using Symbol.dispose/Symbol.asyncDispose. |
| dist/compiled/@babel/runtime/helpers/esm/usingCtx.js | safe | This is a standard Babel/TypeScript helper for transpiling the 'using' declarations proposal (explicit resource management); it contains no malicious patterns such as network access, credential harvesting, obfuscation, or code execution. |
| dist/compiled/@babel/runtime/helpers/esm/wrapAsyncGenerator.js | safe | No malicious patterns detected; the file is a standard Babel async generator helper with no network, filesystem, process, or eval activity. |
| dist/compiled/@babel/runtime/helpers/esm/wrapNativeSuper.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper implementing _wrapNativeSuper with no network, filesystem, process, or dynamic code execution activity. |
| dist/compiled/@babel/runtime/helpers/esm/wrapRegExp.js | safe | No malicious patterns detected; this is a legitimate Babel helper for extending RegExp with named groups. |
| dist/compiled/@babel/runtime/helpers/esm/writeOnlyError.js | safe | The file contains a trivial helper function that throws a TypeError for write-only property access, with no malicious patterns or suspicious behavior detected. |
| dist/compiled/@babel/runtime/helpers/extends.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/get.js | safe | No malicious patterns detected; this is a standard Babel helper for ES6 Reflect.get/super property access with no network, filesystem, or execution risks. |
| dist/compiled/@babel/runtime/helpers/getPrototypeOf.js | safe | No malicious patterns detected; the file is a standard Babel runtime helper for getting an object's prototype. |
| dist/compiled/@babel/runtime/helpers/identity.js | safe | The file contains a simple identity function with standard module exports and no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/importDeferProxy.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/inherits.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/inheritsLoose.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/initializerDefineProperty.js | safe | This is a standard Babel helper function that safely defines object properties with no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/initializerWarningHelper.js | safe | This is a standard Babel runtime helper function that only throws an error when decorators are misconfigured; no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/instanceof.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/interopRequireDefault.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/interopRequireWildcard.js | safe | No malicious patterns detected; this is a standard Babel runtime helper for ES module interop with no network, filesystem, process, or dynamic execution behavior. |
| dist/compiled/@babel/runtime/helpers/isNativeFunction.js | safe | The file contains only a standard utility function to detect native functions via Function.prototype.toString, with no malicious patterns, network activity, file access, or code execution. |
| dist/compiled/@babel/runtime/helpers/isNativeReflectConstruct.js | safe | The code is a standard Babel helper for detecting native Reflect.construct support, with no malicious patterns, network activity, or suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/iterableToArray.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/iterableToArrayLimit.js | safe | No malicious patterns detected; this is a standard Babel helper for safely converting iterables to arrays with length limits. |
| dist/compiled/@babel/runtime/helpers/jsx.js | safe | This is a standard Babel/React JSX runtime helper that creates React elements; no malicious patterns, network calls, file access, or dynamic code execution were found. |
| dist/compiled/@babel/runtime/helpers/maybeArrayLike.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/newArrowCheck.js | safe | No malicious patterns detected; this is a standard Babel helper for arrow function instantiation checks. |
| dist/compiled/@babel/runtime/helpers/nonIterableRest.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/nonIterableSpread.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/nullishReceiverError.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/objectDestructuringEmpty.js | safe | No malicious patterns detected; the code is a standard Babel helper for throwing a TypeError on null/undefined destructuring. |
| dist/compiled/@babel/runtime/helpers/objectSpread.js | safe | This is a standard Babel helper for object spread syntax with no malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/objectSpread2.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/objectWithoutProperties.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/objectWithoutPropertiesLoose.js | safe | No malicious patterns detected; the code is a standard Babel helper that safely copies own enumerable properties excluding specified keys. |
| dist/compiled/@babel/runtime/helpers/possibleConstructorReturn.js | safe | This is a standard Babel helper function for handling derived constructor return values, containing no malicious patterns, network calls, file system access, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/readOnlyError.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/regeneratorRuntime.js | safe | No malicious patterns detected; this is the standard @babel/runtime regenerator helper with no exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| dist/compiled/@babel/runtime/helpers/set.js | safe | No malicious patterns detected; the code is a standard Babel helper for property setting using Reflect.set or a fallback implementation. |
| dist/compiled/@babel/runtime/helpers/setFunctionName.js | safe | No malicious patterns detected; the code is a benign utility for setting function names with a safe try/catch and no external operations. |
| dist/compiled/@babel/runtime/helpers/setPrototypeOf.js | safe | This is a standard Babel helper function for setting object prototypes with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/skipFirstGeneratorNext.js | safe | The code is a benign utility function that wraps a generator to skip its first yield, with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/slicedToArray.js | safe | This is a Babel helper function for array destructuring with no malicious patterns, network activity, environment access, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/superPropBase.js | safe | This is a standard Babel helper function for accessing super class properties; no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/superPropGet.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/superPropSet.js | safe | No malicious patterns detected; the file is a Babel-generated helper for super property assignment with only local module requires and no external I/O, dynamic execution, or install-time behavior. |
| dist/compiled/@babel/runtime/helpers/taggedTemplateLiteral.js | safe | The file is a standard Babel helper for tagged template literals and contains no malicious patterns. |
| dist/compiled/@babel/runtime/helpers/taggedTemplateLiteralLoose.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/tdz.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/temporalRef.js | safe | The code is a standard Babel helper for temporal dead zone (TDZ) references, with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/temporalUndefined.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/toArray.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/toConsumableArray.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/toPrimitive.js | safe | No malicious patterns detected; the code is a standard Babel helper for ToPrimitive conversion. |
| dist/compiled/@babel/runtime/helpers/toPropertyKey.js | safe | No malicious patterns detected; the code is a standard Babel helper for converting values to property keys. |
| dist/compiled/@babel/runtime/helpers/toSetter.js | safe | No malicious patterns detected; the code is a standard Babel helper for creating setter functions via Object.defineProperty. |
| dist/compiled/@babel/runtime/helpers/tsRewriteRelativeImportExtensions.js | safe | The code is a benign utility function that rewrites TypeScript import extensions to JavaScript equivalents, with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/@babel/runtime/helpers/typeof.js | safe | No malicious patterns detected |
| dist/compiled/@babel/runtime/helpers/unsupportedIterableToArray.js | safe | The file is a standard Babel helper function for iterable conversion with no malicious patterns or security concerns. |
| dist/compiled/@babel/runtime/helpers/using.js | safe | This is a legitimate Babel helper function implementing the 'using' declaration spec, with no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/usingCtx.js | safe | This is a standard Babel helper implementation for the JavaScript 'using' declarations (explicit resource management) proposal; it contains no network, filesystem, process, or obfuscated code patterns. |
| dist/compiled/@babel/runtime/helpers/wrapAsyncGenerator.js | safe | No malicious patterns detected; the code is a standard Babel/TypeScript async generator runtime helper with no network, file, process, or dynamic code execution. |
| dist/compiled/@babel/runtime/helpers/wrapNativeSuper.js | safe | No malicious patterns detected; the code is a standard Babel helper for wrapping native super classes without any obfuscation, network, filesystem, or process manipulation. |
| dist/compiled/@babel/runtime/helpers/wrapRegExp.js | safe | This is a legitimate Babel helper for extending RegExp with named capture groups; no malicious patterns detected. |
| dist/compiled/@babel/runtime/helpers/writeOnlyError.js | safe | No malicious patterns detected; the file contains a simple Babel helper that throws a TypeError for write-only property access. |
| dist/compiled/@edge-runtime/cookies/index.js | safe | This is a legitimate Edge Runtime cookies library with no malicious patterns, network requests, credential harvesting, or code execution detected. |
| dist/compiled/@edge-runtime/ponyfill/index.js | safe | No malicious patterns detected |
| dist/compiled/@edge-runtime/primitives/abort-controller.js.text.js | safe | No malicious patterns detected; the code is a legitimate polyfill/implementation of the AbortController and AbortSignal APIs with no network, filesystem, or process activity. |
| dist/compiled/@edge-runtime/primitives/console.js.text.js | safe | No malicious patterns detected; the file is a bundled JavaScript implementation of a console formatting utility for the edge-runtime package. |
| dist/compiled/@edge-runtime/primitives/crypto.js | safe | No malicious patterns detected; the file is a standard wrapper around Node.js's built-in webcrypto module with no exfiltration, obfuscation, or suspicious behavior. |
| dist/compiled/@edge-runtime/primitives/events.js.text.js | safe | The file contains a bundled/transpiled implementation of FetchEvent and PromiseRejectionEvent classes for the @edge-runtime/primitives package with no malicious patterns detected. |
| dist/compiled/@edge-runtime/primitives/stream.js | safe | No malicious patterns detected; the code is a simple re-export of Node.js web stream primitives with no data exfiltration, dynamic code execution, process spawning, or suspicious network activity. |
| dist/compiled/@edge-runtime/primitives/url.js.text.js | safe | The file is a bundled polyfill for URLPattern and related URL parsing utilities with no malicious behavior, network activity, or dynamic code execution. |
| dist/compiled/@hapi/accept/index.js | safe | No malicious patterns detected; the code is a bundled version of the @hapi/accept HTTP content negotiation library with no obfuscation, data exfiltration, credential harvesting, or arbitrary code execution. |
| dist/compiled/@modelcontextprotocol/sdk/server/streamableHttp.js | safe | No malicious patterns detected; the code is a legitimate MCP Streamable HTTP server transport implementation with standard request handling, validation, and SSE streaming. |
| dist/compiled/@napi-rs/triples/index.js | safe | No malicious patterns detected; the file is a benign platform/architecture triple mapping bundled by ncc with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/@next/font/dist/constants.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/dist/format-available-values.js | safe | No malicious patterns detected; the code is a simple utility that formats an array of values into a string for error messages. |
| dist/compiled/@next/font/dist/google/fetch-resource.js | safe | The code is a straightforward HTTP/HTTPS resource fetcher for Google Fonts with no malicious patterns detected. |
| dist/compiled/@next/font/dist/google/find-font-files-in-css.js | safe | No malicious patterns detected; the code is a pure text-parsing utility for extracting font file URLs from CSS, with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/@next/font/dist/google/get-fallback-font-override-metrics.js | safe | No malicious patterns detected; the file is a standard TypeScript-compiled Next.js font utility that only imports internal modules and logs errors locally. |
| dist/compiled/@next/font/dist/google/get-font-axes.js | safe | No malicious patterns detected; the code only validates and formats Google Fonts axis metadata without network, filesystem, or process access. |
| dist/compiled/@next/font/dist/google/get-google-fonts-url.js | safe | No malicious patterns detected; the code only generates a Google Fonts URL from provided parameters. |
| dist/compiled/@next/font/dist/google/get-proxy-agent.js | safe | No malicious patterns detected; the code simply reads proxy environment variables and returns standard proxy agents. |
| dist/compiled/@next/font/dist/google/google-fonts-metadata.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/dist/google/index.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/dist/google/loader.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/dist/google/retry.js | safe | No malicious patterns detected; the code is a simple retry utility wrapping an internal async-retry module with no exfiltration, obfuscation, or unsafe operations. |
| dist/compiled/@next/font/dist/google/sort-fonts-variant-values.js | safe | No malicious patterns detected; the file contains a pure sorting utility function with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/@next/font/dist/google/validate-google-font-function-call.js | safe | No malicious patterns detected; the code performs only static validation of Google font arguments with no network, filesystem, process, or dynamic code execution. |
| dist/compiled/@next/font/dist/local/get-fallback-metrics-from-font-file.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/dist/local/index.js | safe | No malicious patterns detected; the file only defines a stub function that throws an error. |
| dist/compiled/@next/font/dist/local/loader.js | safe | No malicious patterns detected; the code is a legitimate Next.js font loader that reads local font files and generates @font-face CSS without any suspicious activity. |
| dist/compiled/@next/font/dist/local/pick-font-file-for-fallback-generation.js | safe | No malicious patterns detected; the code is a benign utility for selecting font files based on weight for Next.js font fallback generation. |
| dist/compiled/@next/font/dist/local/validate-local-font-function-call.js | safe | The code is a standard validation utility for next/font/local that only performs input validation and error handling, with no malicious patterns, network activity, or dynamic code execution. |
| dist/compiled/@next/font/dist/next-font-error.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/dist/types.js | safe | No malicious patterns detected |
| dist/compiled/@next/font/google/index.js | safe | No malicious patterns detected; the file performs a version check and throws a configuration error message without any suspicious behavior. |
| dist/compiled/@next/font/google/loader.js | safe | This file is a simple re-export shim for Next.js's Google Font loader and contains no malicious patterns. |
| dist/compiled/@next/font/local/index.js | safe | No malicious patterns detected; the code only performs a version check and throws an error if requirements are not met. |
| dist/compiled/@next/react-refresh-utils/dist/ReactRefreshRspackPlugin.js | safe | No malicious patterns detected; the code is a standard webpack/rspack plugin for React Refresh runtime integration. |
| dist/compiled/@next/react-refresh-utils/dist/ReactRefreshWebpackPlugin.js | safe | No malicious patterns detected; the code is a legitimate React Fast Refresh webpack plugin that only manipulates webpack runtime hooks and does not perform any exfiltration, credential harvesting, or suspicious activity. |
| dist/compiled/@next/react-refresh-utils/dist/internal/ReactRefreshModule.runtime.js | safe | No malicious patterns detected; the code is a standard Next.js React Refresh runtime with no exfiltration, credential harvesting, obfuscation, or other security concerns. |
| dist/compiled/@next/react-refresh-utils/dist/internal/RspackReactRefresh.js | safe | No malicious patterns detected; the file is a legitimate React Refresh runtime utility for Next.js/Rspack. |
| dist/compiled/@next/react-refresh-utils/dist/internal/helpers.js | safe | No malicious patterns detected; the code is a legitimate React Refresh helper from Next.js with no data exfiltration, dynamic code execution, or other security concerns. |
| dist/compiled/@next/react-refresh-utils/dist/rspack-runtime.js | safe | No malicious patterns detected; the code is a standard React Refresh runtime injection for Next.js development. |
| dist/compiled/@next/react-refresh-utils/dist/runtime.js | safe | No malicious patterns detected; the code is a standard React Refresh runtime integration for Next.js that registers global hooks and helpers without any data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/compiled/@opentelemetry/api/index.js | safe | No malicious patterns detected; the file is a standard minified build of the @opentelemetry/api package with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/compiled/@vercel/detect-agent/index.js | safe | The code is a bundled agent-detection utility that reads environment variables and checks for a known Devin installation path, with no exfiltration, dynamic code execution, or other malicious patterns. |
| dist/compiled/@vercel/routing-utils/superstatic.js | safe | No malicious patterns detected; the code implements routing utilities and path-to-regexp logic without any data exfiltration, credential access, obfuscated payloads, or suspicious system calls. |
| dist/compiled/anser/index.js | safe | No malicious patterns detected; the code is a standard ANSI-to-HTML converter with no network, file system, or process execution activity. |
| dist/compiled/assert/assert.js | safe | This is a bundled polyfill for Node.js's assert module and related utility functions; no malicious patterns, obfuscated code, data exfiltration, or dynamic execution were detected. |
| dist/compiled/async-retry/index.js | safe | The code is a standard async retry library with no obfuscation, network calls, file system access, or process spawning; it is safe to use. |
| dist/compiled/async-sema/index.js | safe | This is a legitimate semaphore and rate-limiting library with no malicious patterns detected. |
| dist/compiled/babel/core-lib-block-hoist-plugin.js | safe | No malicious patterns detected |
| dist/compiled/babel/core-lib-normalize-file.js | safe | No malicious patterns detected; the file is a simple module re-export from a local bundle. |
| dist/compiled/babel/core-lib-normalize-opts.js | safe | No malicious patterns detected |
| dist/compiled/babel/eslint-parser.js | safe | No malicious patterns detected; the file simply re-exports a bundled ESLint parser module from a local path. |
| dist/compiled/babel/generator.js | safe | No malicious patterns detected |
| dist/compiled/babel/parser.js | safe | No malicious patterns detected |
| dist/compiled/babel/plugin-proposal-class-properties.js | safe | The file is a simple Babel plugin re-export that requires a local bundle with no malicious patterns detected |
| dist/compiled/babel/plugin-proposal-export-namespace-from.js | safe | No malicious patterns detected; the file is a simple Babel plugin re-export that loads a shared bundle module at import time. |
| dist/compiled/babel/plugin-proposal-numeric-separator.js | safe | This is a simple re-export shim for Babel's numeric separator plugin with no malicious patterns. |
| dist/compiled/babel/plugin-proposal-object-rest-spread.js | safe | No malicious patterns detected |
| dist/compiled/babel/plugin-syntax-bigint.js | safe | This is a simple re-export of a Babel plugin from a local bundle, with no malicious patterns detected. |
| dist/compiled/babel/plugin-syntax-import-attributes.js | safe | This is a simple Babel plugin wrapper that delegates to a sibling bundle module with no malicious patterns. |
| dist/compiled/babel/plugin-syntax-jsx.js | safe | Simple module re-export from a local bundle with no suspicious patterns detected |
| dist/compiled/babel/plugin-syntax-typescript.js | safe | No malicious patterns detected |
| dist/compiled/babel/plugin-transform-define.js | safe | The file is a simple re-export wrapper that requires a bundled module and invokes a transform function, with no malicious patterns detected. |
| dist/compiled/babel/plugin-transform-modules-commonjs.js | safe | No malicious patterns detected; the file merely re-exports a Babel plugin from a local bundle. |
| dist/compiled/babel/plugin-transform-react-remove-prop-types.js | safe | The file is a simple Babel plugin loader that requires a local bundle module and calls a factory function, with no suspicious patterns detected. |
| dist/compiled/babel/plugin-transform-runtime.js | safe | No malicious patterns detected |
| dist/compiled/babel/preset-env.js | safe | The file is a simple Babel preset-env re-export with no malicious patterns, network access, or credential harvesting. |
| dist/compiled/babel/preset-react.js | safe | No malicious patterns detected |
| dist/compiled/babel/preset-typescript.js | safe | No malicious patterns detected |
| dist/compiled/babel/traverse.js | safe | No malicious patterns detected |
| dist/compiled/browserify-zlib/index.js | safe | No malicious patterns detected; the file is a standard browserify-bundled zlib implementation with no exfiltration, credential harvesting, obfuscated payloads, or suspicious process/network activity. |
| dist/compiled/buffer/index.js | safe | This is the standard browser Buffer polyfill (feross/buffer) with no malicious patterns, network activity, credential access, or dynamic code execution. |
| dist/compiled/busboy/index.js | safe | No malicious patterns detected; this is the legitimate busboy multipart/form-data parser with no network, filesystem, or code execution activity. |
| dist/compiled/bytes/index.js | safe | No malicious patterns detected |
| dist/compiled/ci-info/index.js | safe | No malicious patterns detected; the code is a legitimate CI environment detection library that reads environment variables to identify CI providers. |
| dist/compiled/cli-select/index.js | safe | No malicious patterns detected; the code is a legitimate terminal selection menu library with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| dist/compiled/client-only/error.js | safe | No malicious patterns detected |
| dist/compiled/client-only/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/commander/index.js | safe | This is the standard Commander.js CLI argument parsing library; no malicious behavior or security concerns were identified. |
| dist/compiled/content-disposition/index.js | safe | No malicious patterns detected; this is the standard content-disposition npm package bundled with webpack/ncc, with no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/compiled/content-type/index.js | safe | No malicious patterns detected |
| dist/compiled/cookie/index.js | safe | No malicious patterns detected; the code is a standard, unmodified implementation of the 'cookie' library for parsing and serializing HTTP cookies. |
| dist/compiled/css.escape/css.escape.js | safe | No malicious patterns detected; the code is a benign polyfill for CSS.escape bundled with webpack, containing no network, filesystem, process, obfuscation, or credential harvesting behavior. |
| dist/compiled/data-uri-to-buffer/index.js | safe | The code is a standard, bundled implementation of data-uri-to-buffer with no malicious patterns, network calls, file system access, or dynamic code execution. |
| dist/compiled/debug/index.js | safe | No malicious patterns detected; this is the standard debug logging library bundled with ncc, performing only local logging and environment variable reads for configuration. |
| dist/compiled/devalue/devalue.umd.js | safe | The code is a minified UMD bundle of the devalue serialization library with no malicious patterns detected. |
| dist/compiled/domain-browser/index.js | safe | The file is a benign webpack bundle of the domain-browser shim and contains no malicious patterns. |
| dist/compiled/events/events.js | safe | No malicious patterns detected; the code is a standard bundled event emitter module. |
| dist/compiled/find-up/index.js | safe | The code is a standard bundled implementation of the 'find-up' utility with no malicious patterns, network activity, credential harvesting, or dynamic code execution. |
| dist/compiled/fresh/index.js | safe | No malicious patterns detected |
| dist/compiled/glob/glob.js | safe | No malicious patterns detected; this is a bundled copy of the standard 'glob' file-matching library. |
| dist/compiled/gzip-size/index.js | safe | No malicious patterns detected; the code is a compiled JavaScript library for calculating gzip size with standard Node.js modules and no suspicious behavior. |
| dist/compiled/hash.js/sha256/256.js | safe | No malicious patterns detected; this is a standard, minified SHA-256 hash implementation with no network, filesystem, process, or dynamic code execution activity. |
| dist/compiled/http-proxy-agent/index.js | safe | This is a legitimate bundled version of the http-proxy-agent library; no malicious patterns were detected. |
| dist/compiled/https-browserify/index.js | safe | No malicious patterns detected; the code is a standard browserify shim for Node's https module that enforces HTTPS protocol without any exfiltration, obfuscation, or suspicious behavior. |
| dist/compiled/https-proxy-agent/index.js | safe | No malicious patterns detected; the code is a legitimate HTTPS proxy agent implementation bundled with ncc. |
| dist/compiled/icss-utils/index.js | safe | No malicious patterns detected |
| dist/compiled/ignore-loader/index.js | safe | No malicious patterns detected |
| dist/compiled/image-size/index.js | safe | No malicious patterns detected; the code is a legitimate image size detection library with standard file system operations and no data exfiltration, credential harvesting, obfuscated payloads, or other security concerns. |
| dist/compiled/ipaddr.js/ipaddr.js | safe | No malicious patterns detected; the code is a standard IPv4/IPv6 address parsing and manipulation library. |
| dist/compiled/is-animated/index.js | safe | No malicious patterns detected; the code is a standard Webpack-bundled utility for detecting animated GIF, PNG, and WebP images with no network, filesystem, or code execution activity. |
| dist/compiled/is-docker/index.js | safe | No malicious patterns detected |
| dist/compiled/is-wsl/index.js | safe | The compiled is-wsl package contains only benign WSL detection logic with no malicious patterns such as exfiltration, backdoors, or dynamic code execution. |
| dist/compiled/jest-worker/index.js | safe | No malicious patterns detected; the code is a legitimate Jest worker pool implementation with expected worker process management and no data exfiltration or obfuscation. |
| dist/compiled/json5/index.js | safe | The code is a standard JSON5 parser and serializer implementation (bundled with webpack) with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, network activity, shell commands, or dynamic code execution. |
| dist/compiled/loader-utils2/index.js | safe | No malicious patterns detected; the code is a legitimate Webpack loader-utils library with standard utility functions and no exfiltration, obfuscation, or suspicious behavior. |
| dist/compiled/loader-utils3/index.js | safe | No malicious patterns detected; the code is a legitimate utility library (loader-utils) implementing hash digests, URL handling, and name interpolation without data exfiltration, obfuscation, or process spawning. |
| dist/compiled/lodash.curry/index.js | safe | No malicious patterns detected; the code is a standard Lodash curry implementation with no network, filesystem, or process operations. |
| dist/compiled/lru-cache/index.js | safe | This is a standard, minified build of the well-known lru-cache npm package with no malicious patterns detected. |
| dist/compiled/mini-css-extract-plugin/cjs.js | safe | No malicious patterns detected; the file is a standard webpack/ncc bundle wrapper that re-exports the local index.js module. |
| dist/compiled/mini-css-extract-plugin/hmr/hotModuleReplacement.js | safe | No malicious patterns detected; the code implements standard Hot Module Replacement (HMR) for CSS via DOM manipulation with no exfiltration, dynamic code execution, or suspicious network activity. |
| dist/compiled/mini-css-extract-plugin/index.js | safe | No malicious patterns detected |
| dist/compiled/nanoid/index.cjs | safe | No malicious patterns detected; this is a legitimate bundled version of the nanoid library that only uses crypto.randomFillSync for random ID generation. |
| dist/compiled/native-url/index.js | safe | This is a minified URL parsing/polyfill library (native-url) with no malicious patterns, no network calls, no filesystem access, and no dynamic code execution. |
| dist/compiled/neo-async/async.js | safe | No malicious patterns detected; the code is a minified bundle of the legitimate neo-async library with no network, filesystem, process execution, credential harvesting, or dynamic code execution. |
| dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js-experimental.runtime.dev.js | safe | No malicious patterns detected |
| dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js-turbo-experimental.runtime.dev.js | safe | No malicious patterns detected; the file is a benign Next.js dev no-op HMR stub containing an empty connect function and standard module export boilerplate. |
| dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js-turbo.runtime.dev.js | safe | This is a benign Next.js development no-op HMR module with no network, filesystem, process execution, or obfuscated code patterns. |
| dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js.runtime.dev.js | safe | No malicious patterns detected; the file is a benign Next.js no-op Turbopack HMR module with an empty connect function. |
| dist/compiled/ora/index.js | safe | The bundled code is the ora spinner package and its dependencies (chalk, cli-spinners, ansi-styles, etc.), containing only terminal styling and spinner logic with no malicious patterns detected. |
| dist/compiled/os-browserify/browser.js | safe | This is a standard browser polyfill for Node.js os module with no malicious patterns detected. |
| dist/compiled/p-limit/index.js | safe | This is a legitimate, minified/compiled implementation of the p-limit concurrency control library with no malicious patterns, network calls, credential access, dynamic code execution, or install-time hooks. |
| dist/compiled/p-queue/index.js | safe | No malicious patterns detected; the code is a standard bundled implementation of the p-queue library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/compiled/path-browserify/index.js | safe | This is a minified, bundled copy of the well-known path-browserify package containing only pure POSIX path manipulation functions with no malicious patterns detected. |
| dist/compiled/path-to-regexp/index.js | safe | This is a standard bundled version of the path-to-regexp library with no malicious patterns; it contains only routing-related logic and no network, filesystem, credential, or code-execution abuse. |
| dist/compiled/picomatch/index.js | safe | No malicious patterns detected; the code is a legitimate picomatch glob matching library with no data exfiltration, environment harvesting, obfuscation, or process execution. |
| dist/compiled/postcss-flexbugs-fixes/index.js | safe | No malicious patterns detected; the code is a standard PostCSS plugin for flexbugs fixes with no network, filesystem, or process manipulation. |
| dist/compiled/postcss-modules-extract-imports/index.js | safe | No malicious patterns detected; the code is a legitimate PostCSS plugin for extracting CSS modules imports and contains no network, credential, execution, or filesystem abuse. |
| dist/compiled/postcss-modules-local-by-default/index.js | safe | No malicious patterns detected; the code is a standard bundled PostCSS plugin for handling local-by-default CSS modules. |
| dist/compiled/postcss-modules-scope/index.js | safe | The code is a compiled PostCSS plugin for scoping CSS selectors and contains no malicious patterns such as data exfiltration, obfuscated payloads, or network requests. |
| dist/compiled/postcss-modules-values/index.js | safe | No malicious patterns detected; the code is a legitimate PostCSS plugin for handling CSS Modules values. |
| dist/compiled/postcss-plugin-stub-for-cssnano-simple/index.js | safe | This is a benign webpack/ncc-bundled PostCSS stub plugin containing no malicious patterns. |
| dist/compiled/postcss-safe-parser/safe-parse.js | safe | The code is a bundled build of postcss-safe-parser; it parses CSS with an error-tolerant tokenizer and imports postcss as expected, with no data exfiltration, credential harvesting, obfuscated payloads, shell execution, or other malicious patterns. |
| dist/compiled/postcss-scss/scss-syntax.js | safe | No malicious patterns detected; the code is a bundled PostCSS SCSS syntax parser/stringifier with no network, filesystem, process, or credential access. |
| dist/compiled/postcss-value-parser/index.js | safe | No malicious patterns detected |
| dist/compiled/process/browser.js | safe | This is a standard browser polyfill for the Node.js 'process' module (using nextTick, timers, and noop stubs) with no malicious patterns detected. |
| dist/compiled/punycode/punycode.js | safe | No malicious patterns detected; the file is a standard punycode implementation with no network, filesystem, process, or dynamic code execution behavior. |
| dist/compiled/querystring-es3/index.js | safe | This is a standard querystring parsing/stringifying polyfill with no malicious patterns, network activity, filesystem access, or code execution beyond normal module loading. |
| dist/compiled/react-dom-experimental/cjs/react-dom-test-utils.production.js | safe | No malicious patterns detected |
| dist/compiled/react-dom-experimental/cjs/react-dom.development.js | safe | This is the official React DOM development build from Meta; no malicious patterns, credential harvesting, obfuscation, network exfiltration, or dynamic code execution were detected. |
| dist/compiled/react-dom-experimental/cjs/react-dom.production.js | safe | This is a legitimate React DOM production build shim that only exposes standard React APIs, preloading helpers, and error formatting with no malicious patterns detected. |
| dist/compiled/react-dom-experimental/cjs/react-dom.react-server.development.js | safe | This is an official React DOM server build that only performs input validation, emits developer warnings, and delegates resource hint operations to internal React internals; no malicious patterns detected. |
| dist/compiled/react-dom-experimental/cjs/react-dom.react-server.production.js | safe | This is a legitimate React DOM server production build with no malicious patterns detected. |
| dist/compiled/react-dom-experimental/client.js | safe | No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check. |
| dist/compiled/react-dom-experimental/client.react-server.js | safe | No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components. |
| dist/compiled/react-dom-experimental/index.js | safe | This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns. |
| dist/compiled/react-dom-experimental/profiling.js | safe | No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export. |
| dist/compiled/react-dom-experimental/profiling.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-dom-experimental/react-dom.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-dom-experimental/server.browser.js | safe | This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected. |
| dist/compiled/react-dom-experimental/server.edge.js | safe | No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV. |
| dist/compiled/react-dom-experimental/server.js | safe | No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds. |
| dist/compiled/react-dom-experimental/server.node.js | safe | No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV. |
| dist/compiled/react-dom-experimental/server.react-server.js | safe | No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components. |
| dist/compiled/react-dom-experimental/static.edge.js | safe | This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected. |
| dist/compiled/react-dom-experimental/static.node.js | safe | No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs. |
| dist/compiled/react-dom-experimental/static.react-server.js | safe | The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected. |
| dist/compiled/react-dom-experimental/unstable_testing.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-dom/cjs/react-dom-test-utils.production.js | safe | No malicious patterns detected; this is a legitimate React DOM test-utils shim that warns about deprecation and delegates to React.act. |
| dist/compiled/react-dom/cjs/react-dom.development.js | safe | No malicious patterns detected |
| dist/compiled/react-dom/cjs/react-dom.production.js | safe | This is a legitimate minified React DOM production build from the official React package with no malicious patterns detected. |
| dist/compiled/react-dom/cjs/react-dom.react-server.development.js | safe | This is a legitimate React DOM development build file from Meta's React package; no malicious patterns, data exfiltration, obfuscation, or suspicious behavior detected. |
| dist/compiled/react-dom/cjs/react-dom.react-server.production.js | safe | This is a legitimate React DOM server build with no malicious patterns, obfuscation, data exfiltration, or unexpected side effects. |
| dist/compiled/react-dom/client.js | safe | No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check. |
| dist/compiled/react-dom/client.react-server.js | safe | No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components. |
| dist/compiled/react-dom/index.js | safe | This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns. |
| dist/compiled/react-dom/profiling.js | safe | No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export. |
| dist/compiled/react-dom/profiling.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-dom/react-dom.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-dom/server.browser.js | safe | This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected. |
| dist/compiled/react-dom/server.edge.js | safe | No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV. |
| dist/compiled/react-dom/server.js | safe | No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds. |
| dist/compiled/react-dom/server.node.js | safe | No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV. |
| dist/compiled/react-dom/server.react-server.js | safe | No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components. |
| dist/compiled/react-dom/static.edge.js | safe | This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected. |
| dist/compiled/react-dom/static.node.js | safe | No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs. |
| dist/compiled/react-dom/static.react-server.js | safe | The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected. |
| dist/compiled/react-experimental/cjs/react-compiler-runtime.development.js | safe | No malicious patterns detected; the code only accesses React internals for hook validation and useMemoCache. |
| dist/compiled/react-experimental/cjs/react-compiler-runtime.production.js | safe | No malicious patterns detected; the file only exposes a React internal hook wrapper and contains no obfuscation, network activity, or credential harvesting. |
| dist/compiled/react-experimental/cjs/react-compiler-runtime.profiling.js | safe | No malicious patterns detected; the file is a thin React experimental runtime shim that re-exports a memo cache hook from a bundled Next.js dependency. |
| dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.development.js | safe | Legitimate React JSX development runtime with only standard developer warnings and debugging helpers; no malicious patterns detected. |
| dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.production.js | safe | No malicious patterns detected |
| dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.profiling.js | safe | This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export. |
| dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.react-server.development.js | safe | This is the standard React JSX development runtime for server components with only debugging and warning logic, no malicious patterns detected. |
| dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.react-server.production.js | safe | This is a legitimate React JSX runtime module with no malicious patterns detected. |
| dist/compiled/react-experimental/cjs/react-jsx-runtime.development.js | safe | The file is the legitimate, unmodified React experimental JSX runtime development build with no malicious patterns detected. |
| dist/compiled/react-experimental/cjs/react-jsx-runtime.production.js | safe | No malicious patterns detected |
| dist/compiled/react-experimental/cjs/react-jsx-runtime.profiling.js | safe | This is the official React JSX runtime profiling build containing only element creation logic with no malicious patterns, network activity, or code execution. |
| dist/compiled/react-experimental/cjs/react-jsx-runtime.react-server.development.js | safe | No malicious patterns detected; this is a legitimate React JSX runtime development build from Meta with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| dist/compiled/react-experimental/cjs/react-jsx-runtime.react-server.production.js | safe | No malicious patterns detected; this is a legitimate React JSX runtime compilation artifact from the next/dist/compiled directory. |
| dist/compiled/react-experimental/cjs/react.production.js | safe | This is the official React production build and contains no malicious patterns, network requests, credential harvesting, obfuscation, or process spawning beyond expected React internals. |
| dist/compiled/react-experimental/cjs/react.react-server.development.js | safe | This is the official React 19.3.0-experimental server-side development build from Meta, containing only expected React internals (element creation, taint tracking, lazy/Memo/forwardRef, Children helpers, and transition handling) with no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or install-time hooks. |
| dist/compiled/react-experimental/cjs/react.react-server.production.js | safe | This is the official production build of React's experimental react-server package; it contains no malicious patterns, no network exfiltration, no credential harvesting, no obfuscated code, and no install/build/import-time side effects beyond normal module initialization. |
| dist/compiled/react-experimental/compiler-runtime.js | safe | No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV. |
| dist/compiled/react-experimental/index.js | safe | This is a standard React environment-based module export switch with no malicious patterns detected. |
| dist/compiled/react-experimental/jsx-dev-runtime.js | safe | No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV. |
| dist/compiled/react-experimental/jsx-dev-runtime.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-experimental/jsx-runtime.js | safe | This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected. |
| dist/compiled/react-experimental/jsx-runtime.react-server.js | safe | This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected. |
| dist/compiled/react-experimental/react.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react-is/cjs/react-is.development.js | safe | No malicious patterns detected |
| dist/compiled/react-is/cjs/react-is.production.js | safe | This is the legitimate React is.production.js module from the official react-is package, containing only type-checking utilities for React elements with no malicious patterns. |
| dist/compiled/react-is/index.js | safe | No malicious patterns detected |
| dist/compiled/react-refresh/babel.js | safe | No malicious patterns detected; the file is a standard conditional module export that loads the React Refresh Babel plugin's production or development build based on NODE_ENV. |
| dist/compiled/react-refresh/cjs/react-refresh-babel.development.js | safe | This is the official React Refresh Babel plugin with no malicious patterns detected; it performs expected AST transformations and uses crypto for hashing signatures only. |
| dist/compiled/react-refresh/cjs/react-refresh-runtime.development.js | safe | The code is the official React Refresh runtime for development mode and contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, or unauthorized network/file/process operations. |
| dist/compiled/react-refresh/runtime.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack-experimental/cjs/react-server-dom-turbopack-client.browser.production.js | safe | This is the official React Server DOM Turbopack client runtime; no malicious patterns, exfiltration, credential harvesting, obfuscation, or backdoors were detected. |
| dist/compiled/react-server-dom-turbopack-experimental/cjs/react-server-dom-turbopack-client.edge.production.js | safe | This is a legitimate React Server Components client runtime file from Meta's official React repository with no malicious patterns detected. |
| dist/compiled/react-server-dom-turbopack-experimental/cjs/react-server-dom-turbopack-client.node.production.js | safe | This is an official React production build for server components; no malicious patterns, data exfiltration, credential harvesting, or backdoor mechanisms were detected. |
| dist/compiled/react-server-dom-turbopack-experimental/client.browser.js | safe | No malicious patterns detected; the file is a standard environment-based conditional export for React Server DOM Turbopack. |
| dist/compiled/react-server-dom-turbopack-experimental/client.edge.js | safe | No malicious patterns detected; the file is a standard conditional re-export shim for React Server DOM Turbopack client edge builds. |
| dist/compiled/react-server-dom-turbopack-experimental/client.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack-experimental/client.node.js | safe | This is a standard React Server DOM Turbopack client entry point that conditionally re-exports production or development builds based on NODE_ENV, with no malicious patterns detected. |
| dist/compiled/react-server-dom-turbopack-experimental/index.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack-experimental/server.browser.js | safe | No malicious patterns detected; this is a standard React Server DOM Turbopack entry point that conditionally loads production or development builds and re-exports their APIs. |
| dist/compiled/react-server-dom-turbopack-experimental/server.edge.js | safe | No malicious patterns detected; the file is a standard conditional re-export shim for the React Server DOM Turbopack package. |
| dist/compiled/react-server-dom-turbopack-experimental/server.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-turbopack-experimental/server.node.js | safe | No malicious patterns detected; the file is a standard entry point that conditionally re-exports symbols from a React Server DOM Turbopack implementation. |
| dist/compiled/react-server-dom-turbopack-experimental/static.browser.js | safe | No malicious patterns detected; the file is a standard conditional re-export wrapper for React Server DOM Turbopack. |
| dist/compiled/react-server-dom-turbopack-experimental/static.edge.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack-experimental/static.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-turbopack-experimental/static.node.js | safe | This is a simple environment-based module loader for React Server DOM Turbopack that contains no malicious patterns. |
| dist/compiled/react-server-dom-turbopack/cjs/react-server-dom-turbopack-client.browser.production.js | safe | This is the official React Server DOM Turbopack client runtime; no malicious patterns, exfiltration, credential harvesting, obfuscation, or backdoors were detected. |
| dist/compiled/react-server-dom-turbopack/cjs/react-server-dom-turbopack-client.edge.production.js | safe | This is a legitimate React Server Components client runtime file from Meta's official React repository with no malicious patterns detected. |
| dist/compiled/react-server-dom-turbopack/cjs/react-server-dom-turbopack-client.node.production.js | safe | This is an official React production build for server components; no malicious patterns, data exfiltration, credential harvesting, or backdoor mechanisms were detected. |
| dist/compiled/react-server-dom-turbopack/client.browser.js | safe | No malicious patterns detected; the file is a standard environment-based conditional export for React Server DOM Turbopack. |
| dist/compiled/react-server-dom-turbopack/client.edge.js | safe | No malicious patterns detected; the file is a standard conditional re-export shim for React Server DOM Turbopack client edge builds. |
| dist/compiled/react-server-dom-turbopack/client.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack/client.node.js | safe | This is a standard React Server DOM Turbopack client entry point that conditionally re-exports production or development builds based on NODE_ENV, with no malicious patterns detected. |
| dist/compiled/react-server-dom-turbopack/index.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack/server.browser.js | safe | No malicious patterns detected; this is a standard React Server DOM Turbopack entry point that conditionally loads production or development builds and re-exports their APIs. |
| dist/compiled/react-server-dom-turbopack/server.edge.js | safe | No malicious patterns detected; the file is a standard conditional re-export shim for the React Server DOM Turbopack package. |
| dist/compiled/react-server-dom-turbopack/server.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-turbopack/server.node.js | safe | No malicious patterns detected; the file is a standard entry point that conditionally re-exports symbols from a React Server DOM Turbopack implementation. |
| dist/compiled/react-server-dom-turbopack/static.browser.js | safe | No malicious patterns detected; the file is a standard conditional re-export wrapper for React Server DOM Turbopack. |
| dist/compiled/react-server-dom-turbopack/static.edge.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-turbopack/static.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-turbopack/static.node.js | safe | This is a simple environment-based module loader for React Server DOM Turbopack that contains no malicious patterns. |
| dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-client.browser.production.js | safe | No malicious patterns detected; this is the legitimate React Server Components client runtime for webpack with standard serialization, chunk loading, and reference handling logic. |
| dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-client.edge.production.js | safe | This is the legitimate production build of React Server DOM Webpack client code containing no malicious patterns, exfiltration, or code execution risks. |
| dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-client.node.production.js | safe | This is the official React Server Components client runtime for Webpack; no malicious patterns, obfuscation, exfiltration, or suspicious behavior detected. |
| dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-plugin.js | safe | No malicious patterns detected; the code is a legitimate React Server Components Webpack plugin from Meta with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behaviors. |
| dist/compiled/react-server-dom-webpack-experimental/client.browser.js | safe | No malicious patterns detected; the file is a standard React Server DOM Webpack client entry point that conditionally re-exports production or development builds based on NODE_ENV. |
| dist/compiled/react-server-dom-webpack-experimental/client.edge.js | safe | No malicious patterns detected; the file is a simple environment-based module re-export with no suspicious behavior. |
| dist/compiled/react-server-dom-webpack-experimental/client.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack-experimental/client.node.js | safe | No malicious patterns detected; this is a standard conditional re-export shim for React Server DOM Webpack client Node build. |
| dist/compiled/react-server-dom-webpack-experimental/index.js | safe | No malicious patterns detected; the file only throws an error directing users to the correct entry point. |
| dist/compiled/react-server-dom-webpack-experimental/node-register.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/react-server-dom-webpack-experimental/plugin.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/react-server-dom-webpack-experimental/server.browser.js | safe | No malicious patterns detected; the file is a standard environment-based re-export shim for React Server DOM Webpack. |
| dist/compiled/react-server-dom-webpack-experimental/server.edge.js | safe | No malicious patterns detected; the file is a standard React Server DOM Webpack entry point that conditionally re-exports from React's official CJS bundles based on NODE_ENV. |
| dist/compiled/react-server-dom-webpack-experimental/server.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-webpack-experimental/server.node.js | safe | No malicious patterns detected; this is a standard React Server DOM Webpack entry point that conditionally re-exports functions from bundled CJS files based on NODE_ENV. |
| dist/compiled/react-server-dom-webpack-experimental/static.browser.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack-experimental/static.edge.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack-experimental/static.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-webpack-experimental/static.node.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-client.browser.production.js | safe | No malicious patterns detected; this is the legitimate React Server Components client runtime for webpack with standard serialization, chunk loading, and reference handling logic. |
| dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-client.edge.production.js | safe | This is the legitimate production build of React Server DOM Webpack client code containing no malicious patterns, exfiltration, or code execution risks. |
| dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-client.node.production.js | safe | This is the official React Server Components client runtime for Webpack; no malicious patterns, obfuscation, exfiltration, or suspicious behavior detected. |
| dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-plugin.js | safe | No malicious patterns detected; the code is a legitimate React Server Components Webpack plugin from Meta with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behaviors. |
| dist/compiled/react-server-dom-webpack/client.browser.js | safe | No malicious patterns detected; the file is a standard React Server DOM Webpack client entry point that conditionally re-exports production or development builds based on NODE_ENV. |
| dist/compiled/react-server-dom-webpack/client.edge.js | safe | No malicious patterns detected; the file is a simple environment-based module re-export with no suspicious behavior. |
| dist/compiled/react-server-dom-webpack/client.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack/client.node.js | safe | No malicious patterns detected; this is a standard conditional re-export shim for React Server DOM Webpack client Node build. |
| dist/compiled/react-server-dom-webpack/index.js | safe | No malicious patterns detected; the file only throws an error directing users to the correct entry point. |
| dist/compiled/react-server-dom-webpack/node-register.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/react-server-dom-webpack/plugin.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/react-server-dom-webpack/server.browser.js | safe | No malicious patterns detected; the file is a standard environment-based re-export shim for React Server DOM Webpack. |
| dist/compiled/react-server-dom-webpack/server.edge.js | safe | No malicious patterns detected; the file is a standard React Server DOM Webpack entry point that conditionally re-exports from React's official CJS bundles based on NODE_ENV. |
| dist/compiled/react-server-dom-webpack/server.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-webpack/server.node.js | safe | No malicious patterns detected; this is a standard React Server DOM Webpack entry point that conditionally re-exports functions from bundled CJS files based on NODE_ENV. |
| dist/compiled/react-server-dom-webpack/static.browser.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack/static.edge.js | safe | No malicious patterns detected |
| dist/compiled/react-server-dom-webpack/static.js | safe | No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment. |
| dist/compiled/react-server-dom-webpack/static.node.js | safe | No malicious patterns detected |
| dist/compiled/react/cjs/react-compiler-runtime.development.js | safe | No malicious patterns detected; the code is a standard React compiler runtime shim with only a development-time error check and no external network, file system, or process interactions. |
| dist/compiled/react/cjs/react-compiler-runtime.production.js | safe | No malicious patterns detected |
| dist/compiled/react/cjs/react-compiler-runtime.profiling.js | safe | No malicious patterns detected; the file is a legitimate React compiler runtime shim that only re-exports a memoization cache hook from React's shared internals. |
| dist/compiled/react/cjs/react-jsx-dev-runtime.development.js | safe | This is the standard React 19 development JSX runtime from Meta; it contains only normal React element creation, validation, and warning logic with no malicious patterns. |
| dist/compiled/react/cjs/react-jsx-dev-runtime.production.js | safe | No malicious patterns detected |
| dist/compiled/react/cjs/react-jsx-dev-runtime.profiling.js | safe | This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export. |
| dist/compiled/react/cjs/react-jsx-dev-runtime.react-server.development.js | safe | No malicious patterns detected; this is a legitimate development build of React's JSX dev runtime. |
| dist/compiled/react/cjs/react-jsx-dev-runtime.react-server.production.js | safe | No malicious patterns detected; this is a legitimate React JSX runtime production build with no suspicious behavior. |
| dist/compiled/react/cjs/react-jsx-runtime.development.js | safe | This is a legitimate development build of React's JSX runtime from Meta Platforms, containing only React's standard JSX element creation, validation, and development warnings with no malicious patterns. |
| dist/compiled/react/cjs/react-jsx-runtime.production.js | safe | No malicious patterns detected |
| dist/compiled/react/cjs/react-jsx-runtime.profiling.js | safe | No malicious patterns detected; this is a legitimate React JSX runtime profiling build with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/react/cjs/react-jsx-runtime.react-server.development.js | safe | Legitimate React development build with no malicious patterns detected. |
| dist/compiled/react/cjs/react-jsx-runtime.react-server.production.js | safe | This is legitimate React JSX runtime production code with no malicious patterns detected. |
| dist/compiled/react/cjs/react.development.js | safe | This is the legitimate React 19 development build (react.development.js) from Meta, containing only standard React runtime internals, deprecation warnings, hook dispatchers, and dev-only error messages with no malicious patterns. |
| dist/compiled/react/cjs/react.production.js | safe | No malicious patterns detected; this is the standard React production build with no network, filesystem, process-spawning, or obfuscated behavior. |
| dist/compiled/react/cjs/react.react-server.development.js | safe | This is the official React 19 server-side development build with no malicious patterns detected. |
| dist/compiled/react/cjs/react.react-server.production.js | safe | This is a legitimate, minified production build of React's react-server package from Meta; no malicious patterns, exfiltration, dynamic execution, or lifecycle-script abuse were detected. |
| dist/compiled/react/compiler-runtime.js | safe | No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV. |
| dist/compiled/react/index.js | safe | This is a standard React environment-based module export switch with no malicious patterns detected. |
| dist/compiled/react/jsx-dev-runtime.js | safe | No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV. |
| dist/compiled/react/jsx-dev-runtime.react-server.js | safe | No malicious patterns detected |
| dist/compiled/react/jsx-runtime.js | safe | This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected. |
| dist/compiled/react/jsx-runtime.react-server.js | safe | This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected. |
| dist/compiled/react/react.react-server.js | safe | No malicious patterns detected |
| dist/compiled/regenerator-runtime/path.js | safe | No malicious patterns detected |
| dist/compiled/safe-stable-stringify/index.js | safe | No malicious patterns detected; this is a bundled, minified implementation of the safe-stable-stringify JSON serializer with no network, filesystem, process, or dynamic code execution behavior. |
| dist/compiled/scheduler-experimental/cjs/scheduler-unstable_mock.development.js | safe | No malicious patterns detected; this is the legitimate React scheduler mock implementation with no network, filesystem, process, or obfuscated code activity. |
| dist/compiled/scheduler-experimental/cjs/scheduler-unstable_mock.production.js | safe | No malicious patterns detected; this is the legitimate React scheduler unstable mock production build with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/scheduler-experimental/cjs/scheduler-unstable_post_task.development.js | safe | This is the legitimate React Scheduler package using the browser postTask API; no malicious patterns detected. |
| dist/compiled/scheduler-experimental/cjs/scheduler-unstable_post_task.production.js | safe | No malicious patterns detected; the file is a legitimate React scheduler implementation that uses standard browser APIs and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/compiled/scheduler-experimental/cjs/scheduler.development.js | safe | This is a legitimate React scheduler development build with no malicious patterns detected. |
| dist/compiled/scheduler-experimental/cjs/scheduler.native.development.js | safe | No malicious patterns detected; the file is the standard React scheduler native development build with only benign timer and message-channel scheduling logic. |
| dist/compiled/scheduler-experimental/cjs/scheduler.native.production.js | safe | This is the standard React Scheduler production build with no malicious patterns, external network calls, credential harvesting, or suspicious code execution. |
| dist/compiled/scheduler-experimental/cjs/scheduler.production.js | safe | This is the standard React Scheduler production build with no malicious patterns detected. |
| dist/compiled/scheduler-experimental/index.js | safe | No malicious patterns detected |
| dist/compiled/scheduler-experimental/index.native.js | safe | No malicious patterns detected; the file is a standard React Scheduler environment-based module loader. |
| dist/compiled/scheduler-experimental/unstable_mock.js | safe | Standard React Scheduler mock entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected. |
| dist/compiled/scheduler-experimental/unstable_post_task.js | safe | No malicious patterns detected |
| dist/compiled/scheduler/cjs/scheduler-unstable_mock.development.js | safe | No malicious patterns detected; this is the legitimate React scheduler mock implementation with no network, filesystem, process, or obfuscated code activity. |
| dist/compiled/scheduler/cjs/scheduler-unstable_mock.production.js | safe | No malicious patterns detected; this is the legitimate React scheduler unstable mock production build with no network, filesystem, process, or dynamic execution activity. |
| dist/compiled/scheduler/cjs/scheduler-unstable_post_task.development.js | safe | This is the legitimate React Scheduler package using the browser postTask API; no malicious patterns detected. |
| dist/compiled/scheduler/cjs/scheduler-unstable_post_task.production.js | safe | No malicious patterns detected; the file is a legitimate React scheduler implementation that uses standard browser APIs and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/compiled/scheduler/cjs/scheduler.development.js | safe | This is the legitimate React scheduler development build from Meta with no malicious patterns detected; it only contains standard task scheduling logic, timer/heap management, and React DevTools hook integration. |
| dist/compiled/scheduler/cjs/scheduler.native.development.js | safe | No malicious patterns detected |
| dist/compiled/scheduler/cjs/scheduler.native.production.js | safe | This is the official React scheduler production build for React Native, containing only legitimate task scheduling logic with no malicious patterns. |
| dist/compiled/scheduler/cjs/scheduler.production.js | safe | No malicious patterns detected; this is the standard React Scheduler production build with expected internal task scheduling logic and no suspicious behavior. |
| dist/compiled/scheduler/index.js | safe | No malicious patterns detected |
| dist/compiled/scheduler/index.native.js | safe | No malicious patterns detected; the file is a standard React Scheduler environment-based module loader. |
| dist/compiled/scheduler/unstable_mock.js | safe | Standard React Scheduler mock entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected. |
| dist/compiled/scheduler/unstable_post_task.js | safe | No malicious patterns detected |
| dist/compiled/semver/index.js | safe | This is a standard minified build of the semver library with no malicious patterns detected. |
| dist/compiled/send/index.js | safe | No malicious patterns detected |
| dist/compiled/server-only/empty.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/compiled/server-only/index.js | safe | No malicious patterns detected; the code simply throws an error to enforce server-only usage. |
| dist/compiled/shell-quote/index.js | safe | This is the legitimate shell-quote npm package that parses and quotes shell commands; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or process spawning were detected. |
| dist/compiled/source-map/source-map.js | safe | The code is a standard source-map library with no malicious patterns, data exfiltration, or dynamic code execution detected. |
| dist/compiled/source-map08/source-map.js | safe | This is the standard Mozilla source-map library with no malicious patterns detected. |
| dist/compiled/stacktrace-parser/stack-trace-parser.cjs.js | safe | No malicious patterns detected; the file is a standard stack trace parser compiled by ncc with no network, filesystem, or process execution activity. |
| dist/compiled/stream-browserify/index.js | safe | No malicious patterns detected |
| dist/compiled/stream-http/index.js | safe | No malicious patterns detected; this is a standard polyfill/browser build of the Node.js stream-http package. |
| dist/compiled/string-hash/index.js | safe | The code implements a standard djb2 string hash function bundled with ncc, with no malicious patterns, external communications, or system interactions. |
| dist/compiled/string_decoder/string_decoder.js | safe | No malicious patterns detected; this is a bundled version of the standard Node.js string_decoder module with only a safe fallback for older Buffer implementations. |
| dist/compiled/strip-ansi/index.js | safe | The code is a minified/compiled version of the strip-ansi package that only performs ANSI escape code stripping with no malicious behavior. |
| dist/compiled/superstruct/index.cjs | safe | No malicious patterns detected |
| dist/compiled/text-table/index.js | safe | No malicious patterns detected; the file is a minified bundle of the text-table npm package containing only table formatting logic with no network, filesystem, or execution risks. |
| dist/compiled/tty-browserify/index.js | safe | This is a standard browserify shim for the Node.js tty module that safely stubs out isatty and stream constructors without any malicious patterns. |
| dist/compiled/ua-parser-js/ua-parser.js | safe | The code is a legitimate User-Agent parser (ua-parser-js) with no malicious patterns, obfuscation, data exfiltration, or suspicious behavior detected. |
| dist/compiled/unistore/unistore.js | safe | No malicious patterns detected; the code is a minified implementation of the 'unistore' state management library with no network, filesystem, or process operations. |
| dist/compiled/util/util.js | safe | This is a minified/bundled version of the Node.js built-in 'util' module (polyfills from browserify) with no malicious patterns, network calls, credential harvesting, or dynamic execution beyond standard capability checks. |
| dist/compiled/watchpack/watchpack.js | safe | No malicious patterns detected |
| dist/compiled/web-vitals-attribution/web-vitals.attribution.js | safe | This is a legitimate minified build of Google's web-vitals attribution library; no malicious patterns detected. |
| dist/compiled/web-vitals/web-vitals.js | safe | No malicious patterns detected; this is a standard web-vitals performance monitoring library. |
| dist/compiled/webpack-sources1/index.js | safe | This is a legitimate webpack-sources library bundle for source map generation and manipulation, with no malicious patterns detected. |
| dist/compiled/webpack-sources3/index.js | safe | No malicious patterns detected; this is a standard Webpack source helper library with no network, filesystem, credential, or subprocess abuse. |
| dist/compiled/webpack/BasicEvaluatedExpression.js | safe | No malicious patterns detected |
| dist/compiled/webpack/ExternalsPlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/FetchCompileAsyncWasmPlugin.js | safe | The file is a simple re-export of a webpack plugin with no executable logic or suspicious patterns. |
| dist/compiled/webpack/FetchCompileWasmPlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/FetchCompileWasmTemplatePlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/GraphHelpers.js | safe | No malicious patterns detected; this is a simple webpack internal module re-export with no dynamic behavior. |
| dist/compiled/webpack/HotModuleReplacement.runtime.js | safe | This is a standard Webpack Hot Module Replacement runtime file with no malicious patterns detected. |
| dist/compiled/webpack/JavascriptHotModuleReplacement.runtime.js | safe | No malicious patterns detected; this is standard webpack Hot Module Replacement runtime code with no network, credential, obfuscation, or process-spawning behavior. |
| dist/compiled/webpack/LibraryTemplatePlugin.js | safe | No malicious patterns detected; the file simply re-exports a webpack internal module. |
| dist/compiled/webpack/LimitChunkCountPlugin.js | safe | This file is a simple re-export of the LimitChunkCountPlugin from the webpack main module and contains no malicious patterns. |
| dist/compiled/webpack/ModuleFilenameHelpers.js | safe | This file simply re-exports a webpack helper module and contains no malicious patterns, network activity, or dynamic code execution. |
| dist/compiled/webpack/NodeEnvironmentPlugin.js | safe | This is a simple re-export shim that imports NodeEnvironmentPlugin from the webpack module with no suspicious behavior. |
| dist/compiled/webpack/NodeTargetPlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/NodeTemplatePlugin.js | safe | No malicious patterns detected; the file is a simple re-export of a webpack plugin from the webpack module. |
| dist/compiled/webpack/NormalModule.js | safe | No malicious patterns detected |
| dist/compiled/webpack/SingleEntryPlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/SourceMapDevToolModuleOptionsPlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/WebWorkerTemplatePlugin.js | safe | No malicious patterns detected |
| dist/compiled/webpack/lazy-compilation-web.js | safe | No malicious patterns detected; the code is a standard webpack lazy-compilation helper using EventSource for hot module replacement. |
| dist/compiled/webpack/package.js | safe | The file is a one-line re-export of a module from webpack.js with no malicious patterns or suspicious behavior. |
| dist/compiled/webpack/sources.js | safe | No malicious patterns detected |
| dist/compiled/webpack/webpack-lib.js | safe | No malicious patterns detected |
| dist/compiled/webpack/webpack.js | safe | No malicious patterns detected; the code performs conditional module loading for webpack/rspack bundler exports without exfiltration, obfuscation, or execution of untrusted input. |
| dist/compiled/write-file-atomic/index.js | safe | This is a legitimate, minified build of the write-file-atomic npm package, implementing atomic file writes with no malicious patterns or suspicious behavior. |
| dist/compiled/ws/index.js | safe | No malicious patterns detected |
| dist/compiled/zod-validation-error/index.js | safe | No malicious patterns detected; the code is a legitimate Zod validation error formatting library with no network, filesystem, process, or credential access. |
| dist/compiled/zod/index.cjs | safe | No malicious patterns detected; this is a standard webpack/ncc-bundled build of the Zod validation library with no data exfiltration, credential harvesting, obfuscated payloads, or suspicious runtime behavior. |
| dist/diagnostics/build-diagnostics.js | safe | No malicious patterns detected; this file only writes build diagnostics to local files under the configured distDir. |
| dist/esm/api/app-dynamic.js | safe | The file is a simple re-export module that only forwards exports from a shared internal library, with no suspicious or malicious code patterns. |
| dist/esm/api/app.js | safe | No malicious patterns detected; this is a simple re-export module pointing to a local _app file with no external network, process, filesystem, or dynamic code execution behavior. |
| dist/esm/api/constants.js | safe | This file is a simple re-export of constants from a shared library with no malicious patterns detected. |
| dist/esm/api/document.js | safe | No malicious patterns detected; the file only re-exports a local _document module. |
| dist/esm/api/dynamic.js | safe | No malicious patterns detected |
| dist/esm/api/error.js | safe | This file only contains standard re-export statements with no malicious patterns detected |
| dist/esm/api/error.react-server.js | safe | No malicious patterns detected |
| dist/esm/api/form.js | safe | No malicious patterns detected |
| dist/esm/api/head.js | safe | No malicious patterns detected |
| dist/esm/api/headers.js | safe | No malicious patterns detected |
| dist/esm/api/image.js | safe | This file only re-exports an image library from a shared internal module with no suspicious code patterns. |
| dist/esm/api/link.js | safe | No malicious patterns detected |
| dist/esm/api/navigation.js | safe | No malicious patterns detected; the file is a simple re-export from a local client component. |
| dist/esm/api/navigation.react-server.js | safe | No malicious patterns detected |
| dist/esm/api/og.js | safe | No malicious patterns detected |
| dist/esm/api/router.js | safe | This is a simple re-export module that only re-exports from a relative client router module, with no malicious patterns detected. |
| dist/esm/api/script.js | safe | No malicious patterns detected |
| dist/esm/api/server.js | safe | No malicious patterns detected; the file only re-exports from an internal module. |
| dist/esm/build/adapter/setup-node-env.external.js | safe | No malicious patterns detected; the file only conditionally requires trusted Next.js server modules to initialize the Node.js environment. |
| dist/esm/build/analysis/extract-const-value.js | safe | No malicious patterns detected; the code is a pure static AST value extraction utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/build/analysis/get-page-static-info.js | safe | This is a legitimate Next.js internal module for analyzing page static info; no malicious patterns detected. |
| dist/esm/build/analysis/parse-module.js | safe | No malicious patterns detected; the code performs benign cached parsing of module content using SWC with Node's crypto for hashing. |
| dist/esm/build/analyze/index.js | safe | No malicious patterns detected; the file is a legitimate Next.js build analyzer entry point that reads config, writes local build artifacts, and serves a local HTTP bundle analyzer. |
| dist/esm/build/babel/loader/get-config.js | safe | The file is a legitimate Next.js Babel loader configuration module with only standard dynamic require and readFileSync for loading user-provided Babel configs; no malicious patterns were found. |
| dist/esm/build/babel/loader/index.js | safe | No malicious patterns detected; this is a legitimate Babel loader for Next.js that transforms source code without any suspicious behavior. |
| dist/esm/build/babel/loader/transform.js | safe | No malicious patterns detected |
| dist/esm/build/babel/loader/util.js | safe | No malicious patterns detected |
| dist/esm/build/babel/plugins/commonjs.js | safe | The code is a legitimate Babel plugin that conditionally applies the CommonJS transform and contains no malicious patterns. |
| dist/esm/build/babel/plugins/jsx-pragma.js | safe | This is a standard Next.js Babel plugin that adds JSX pragma imports/requires for React; no malicious patterns, network calls, process spawning, or obfuscation were detected. |
| dist/esm/build/babel/plugins/next-font-unsupported.js | safe | This Babel plugin only throws a descriptive error when specific next/font imports are detected; it performs no network, filesystem, process, or dynamic code execution, and contains no malicious patterns. |
| dist/esm/build/babel/plugins/next-page-config.js | safe | This is a legitimate Next.js Babel plugin that validates page config exports and contains no malicious patterns. |
| dist/esm/build/babel/plugins/next-page-disallow-re-export-all-exports.js | safe | This is a legitimate Next.js Babel plugin that throws a SyntaxError when export * from '...' is used in a page, and contains no malicious patterns. |
| dist/esm/build/babel/plugins/next-ssg-transform.js | safe | No malicious patterns detected |
| dist/esm/build/babel/plugins/optimize-hook-destructuring.js | safe | This is a legitimate Babel plugin that optimizes React hook destructuring; no malicious patterns were detected. |
| dist/esm/build/babel/plugins/react-loadable-plugin.js | safe | This Babel plugin for Next.js dynamic imports performs static code transformations and does not exhibit any malicious behavior such as data exfiltration, credential harvesting, or dynamic code execution. |
| dist/esm/build/babel/preset.js | safe | No malicious patterns detected; the file is a standard Babel preset configuration for Next.js with expected requires and environment variable usage. |
| dist/esm/build/browser-variant-modules.js | safe | The file is a static, auto-generated array of module path strings used for browser build aliasing; it contains no executable logic, network activity, credential access, dynamic imports, or other malicious patterns. |
| dist/esm/build/build-context.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/collect-build-traces.js | safe | No malicious patterns detected; the code is standard Next.js build tracing logic without exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| dist/esm/build/compiler.js | safe | No malicious patterns detected; the code is a standard webpack compiler wrapper for Next.js with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/build/create-compiler-aliases.js | safe | This file contains Next.js webpack alias configuration logic with no malicious patterns, no network activity, no credential access, and no dynamic code execution. |
| dist/esm/build/define-env.js | safe | This file is part of Next.js build tooling that serializes environment variables into define-env expressions for bundler replacement, with no malicious patterns detected. |
| dist/esm/build/duration-to-string.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/entries.js | safe | No malicious patterns detected; the code is a legitimate Next.js build entry configuration module. |
| dist/esm/build/file-classifier.js | safe | No malicious patterns detected |
| dist/esm/build/generate-build-id.js | safe | No malicious patterns detected |
| dist/esm/build/generate-routes-manifest.js | safe | No malicious patterns detected; the file contains legitimate Next.js route manifest generation logic with no network, filesystem, or dynamic code execution concerns. |
| dist/esm/build/get-babel-config-file.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/get-babel-loader-config.js | safe | No malicious patterns detected; the code performs legitimate Babel/React Compiler loader configuration using only local module resolution and path operations. |
| dist/esm/build/get-static-info-including-layouts.js | safe | No malicious patterns detected |
| dist/esm/build/get-supported-browsers.js | safe | No malicious patterns detected; the code safely reads browserslist configuration and returns browser targets without any exfiltration, execution, or filesystem manipulation. |
| dist/esm/build/handle-entrypoints.js | safe | This file contains only Next.js/Turbopack entrypoint processing logic with no network, filesystem, process execution, or obfuscated malicious patterns. |
| dist/esm/build/handle-externals.js | safe | No malicious patterns detected; the code is legitimate Next.js webpack external-handling logic with no data exfiltration, credential harvesting, obfuscation, or command execution. |
| dist/esm/build/is-writeable.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/load-entrypoint.js | safe | No malicious patterns detected; the code performs local template file loading and string replacement using known SWC bindings and standard Node.js APIs. |
| dist/esm/build/lockfile.js | safe | No malicious patterns detected; the code implements a legitimate cross-platform advisory lockfile utility for a Next.js dev server. |
| dist/esm/build/manifests/formatter/format-manifest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/next-dir-paths.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/normalize-catchall-routes.js | safe | No malicious patterns detected; the code only normalizes catch-all route paths using local utilities. |
| dist/esm/build/output/format.js | safe | No malicious patterns detected; the file only contains pure functions for formatting time durations and cache-control values. |
| dist/esm/build/output/index.js | safe | No malicious patterns detected; the file is part of Next.js build-utility code for managing webpack compiler state and reporting errors/warnings. |
| dist/esm/build/output/log.js | safe | No malicious patterns detected; the file only provides console logging utilities with no network, filesystem, process, or credential access. |
| dist/esm/build/output/store.js | safe | No malicious patterns detected; the code is standard Next.js build store logic with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| dist/esm/build/page-extensions-type.js | safe | No malicious patterns detected |
| dist/esm/build/polyfills/fetch/index.js | safe | No malicious patterns detected |
| dist/esm/build/polyfills/fetch/whatwg-fetch.js | safe | The file simply re-exports fetch API primitives from the global self object and contains no malicious patterns. |
| dist/esm/build/polyfills/object-assign.js | safe | No malicious patterns detected |
| dist/esm/build/polyfills/object.assign/auto.js | safe | The file contains only a no-op comment and a source map reference, with no executable code or malicious patterns. |
| dist/esm/build/polyfills/object.assign/implementation.js | safe | No malicious patterns detected |
| dist/esm/build/polyfills/object.assign/index.js | safe | The code is a standard polyfill or shim for Object.assign, containing no malicious patterns, network activity, or suspicious behavior. |
| dist/esm/build/polyfills/object.assign/polyfill.js | safe | No malicious patterns detected |
| dist/esm/build/polyfills/object.assign/shim.js | safe | No malicious patterns detected |
| dist/esm/build/polyfills/process.js | safe | No malicious patterns detected; the code is a standard environment-detection polyfill for Next.js process. |
| dist/esm/build/print-build-errors.js | safe | No malicious patterns detected; the code is a benign Turbopack build error/warning formatter with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/build/progress.js | safe | No malicious patterns detected; the file implements a benign progress bar utility using only local logging and terminal output. |
| dist/esm/build/rendering-mode.js | safe | No malicious patterns detected |
| dist/esm/build/segment-config/app/app-segment-config.js | safe | This file is a legitimate Next.js configuration schema validator using Zod with no malicious patterns, network calls, process spawning, or file system manipulation. |
| dist/esm/build/segment-config/app/app-segments.js | safe | No malicious patterns detected |
| dist/esm/build/segment-config/app/collect-root-param-keys.js | safe | No malicious patterns detected; the code is a standard Next.js utility for collecting route parameter keys with no exfiltration, dynamic execution, or suspicious behavior. |
| dist/esm/build/segment-config/middleware/middleware-config.js | safe | This is a legitimate Next.js middleware configuration validation module using zod schemas and picomatch; no malicious patterns, external requests, dynamic code execution, or file system manipulation were detected. |
| dist/esm/build/segment-config/pages/pages-segment-config.js | safe | No malicious patterns detected |
| dist/esm/build/sort-by-page-exts.js | safe | No malicious patterns detected |
| dist/esm/build/spinner.js | safe | No malicious patterns detected; the code is a standard terminal spinner utility with console method interception for UI purposes only. |
| dist/esm/build/static-paths/app.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal module for generating static paths and route parameters without any data exfiltration, credential harvesting, obfuscation, or other suspicious behaviors. |
| dist/esm/build/static-paths/app/extract-pathname-route-param-segments-from-loader-tree.js | safe | No malicious patterns detected |
| dist/esm/build/static-paths/pages.js | safe | No malicious patterns detected; the code implements Next.js static path generation with proper input validation and no external communication or dangerous operations. |
| dist/esm/build/static-paths/types.js | safe | No malicious patterns detected |
| dist/esm/build/static-paths/utils.js | safe | No malicious patterns detected in the provided JavaScript utility file. |
| dist/esm/build/swc/helpers.js | safe | The file contains only a trivial identity helper function with no malicious patterns. |
| dist/esm/build/swc/index.js | safe | This is the standard Next.js SWC native bindings loader that conditionally loads platform-specific binaries from expected package locations and environment-configured testing paths, with no malicious patterns detected. |
| dist/esm/build/swc/install-bindings.js | safe | The file only contains a lazy, static require of a sibling module to control NODE_ENV-dependent loading order; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution were found. |
| dist/esm/build/swc/jest-transformer.js | safe | The file is a legitimate Jest transformer for SWC, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized network/file system access. |
| dist/esm/build/swc/options.js | safe | This is legitimate Next.js SWC configuration code with no malicious patterns detected. |
| dist/esm/build/swc/types.js | safe | No malicious patterns detected |
| dist/esm/build/templates/app-page.js | safe | This is a standard Next.js App Router page entrypoint template with no malicious patterns, external data flows, or dynamic execution. |
| dist/esm/build/templates/app-route.js | safe | This is a legitimate Next.js internal App Route module handler template with no malicious patterns detected; the dynamic require('VAR_USERLAND') is a framework placeholder for user route code, not obfuscated or externally controlled execution. |
| dist/esm/build/templates/edge-app-route.js | safe | This is a standard Next.js edge route build template with no malicious patterns; the placeholders and env var reads are legitimate framework internals, not exfiltration or backdoors. |
| dist/esm/build/templates/edge-ssr-app.js | safe | This is a legitimate Next.js Edge SSR app template file that contains no malicious patterns; it imports local modules, sets up rendering context, and handles requests using standard Next.js server APIs. |
| dist/esm/build/templates/edge-ssr.js | safe | No malicious patterns detected; this is a standard Next.js edge SSR runtime template with expected server-side rendering logic and no data exfiltration, credential harvesting, obfuscation, or backdoor indicators. |
| dist/esm/build/templates/helpers.js | safe | No malicious patterns detected; the code is a simple utility function for hoisting named exports from modules or promises. |
| dist/esm/build/templates/middleware.js | safe | This is legitimate Next.js middleware runtime code with no malicious patterns; dynamic require calls reference internal Next.js modules only and all imports are static and internal. |
| dist/esm/build/templates/pages-api.js | safe | No malicious patterns detected; the file is a standard Next.js Pages API route module template with legitimate framework imports and no exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/build/templates/pages-edge-api.js | safe | This is a standard Next.js Edge API page template with no malicious patterns; the VAR_* placeholders are build-time substitutions and all imports reference internal server modules. |
| dist/esm/build/templates/pages.js | safe | This file is a standard Next.js pages route module template with only static imports, re-exports, and configuration object creation; no malicious patterns detected. |
| dist/esm/build/turbopack-analyze/index.js | safe | No malicious patterns detected; the file is a legitimate Next.js/Turbopack analysis module that configures and runs the build analyzer without exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/esm/build/turbopack-build/impl.js | safe | This is legitimate Next.js/Turbopack build implementation code with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors detected. |
| dist/esm/build/turbopack-build/index.js | safe | No malicious patterns detected; the code is a standard Next.js Turbopack build worker implementation with legitimate dynamic imports and environment variable usage. |
| dist/esm/build/turborepo-access-trace/helpers.js | safe | No malicious patterns detected; the code performs legitimate access tracing for Turborepo with no exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/build/turborepo-access-trace/index.js | safe | No malicious patterns detected |
| dist/esm/build/turborepo-access-trace/result.js | safe | No malicious patterns detected; the file contains a pure data-aggregation class for Turborepo access tracing with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/build/turborepo-access-trace/types.js | safe | The file contains only TypeScript-style comments and an empty export statement with no executable logic or malicious patterns. |
| dist/esm/build/type-check.js | safe | No malicious patterns detected; the code is a standard Next.js TypeScript type-checking orchestration module using a worker, with no data exfiltration, credential harvesting, obfuscation, or suspicious process execution. |
| dist/esm/build/utils.js | safe | This is a legitimate Next.js build utility module from the official next package; no malicious patterns, exfiltration, credential harvesting, obfuscation, or unauthorized process execution were detected. |
| dist/esm/build/validate-app-paths.js | safe | This is a legitimate Next.js internal route validation module with no malicious patterns, network activity, credential access, or dynamic code execution. |
| dist/esm/build/warn-about-edge-runtime.js | safe | No malicious patterns detected |
| dist/esm/build/webpack-build/impl.js | safe | No malicious patterns detected; the code is part of Next.js build tooling with standard compilation operations. |
| dist/esm/build/webpack-build/index.js | safe | No malicious patterns detected; the code is a legitimate Next.js build orchestration module that spawns internal webpack worker processes and manages build telemetry state without exfiltration or obfuscation. |
| dist/esm/build/webpack-config-rules/resolve.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/alias/react-dom-server-experimental.js | safe | No malicious patterns detected; the file is a standard Next.js compatibility shim that conditionally loads official React DOM server builds based on environment and throws errors for legacy APIs. |
| dist/esm/build/webpack/alias/react-dom-server.js | safe | This is a legitimate Next.js shim that conditionally requires official React DOM server builds and throws an error for deprecated legacy APIs, with no malicious patterns detected. |
| dist/esm/build/webpack/cache-invalidation.js | safe | No malicious patterns detected; the code performs legitimate filesystem cache invalidation and cleanup operations within the provided cache directory. |
| dist/esm/build/webpack/config/blocks/base.js | safe | This is a legitimate Next.js webpack configuration module with no malicious patterns detected. |
| dist/esm/build/webpack/config/blocks/css/loaders/client.js | safe | This is a standard Next.js webpack CSS loader configuration with no malicious patterns detected. |
| dist/esm/build/webpack/config/blocks/css/loaders/file-resolve.js | safe | No malicious patterns detected; the code is a simple URL validation helper for CSS file resolution in a webpack config. |
| dist/esm/build/webpack/config/blocks/css/loaders/getCssModuleLocalIdent.js | safe | No malicious patterns detected; the code is a standard CSS module local identifier generator with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/build/webpack/config/blocks/css/loaders/global.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/config/blocks/css/loaders/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/config/blocks/css/loaders/modules.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/config/blocks/css/loaders/next-font.js | safe | This module is a standard Next.js webpack loader configuration that assembles CSS/font loaders without any malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or file system/process manipulation. |
| dist/esm/build/webpack/config/blocks/css/messages.js | safe | No malicious patterns detected; the file only contains static error message helper functions for Next.js CSS import validation. |
| dist/esm/build/webpack/config/blocks/images/index.js | safe | No malicious patterns detected; the file is a standard Next.js webpack configuration block for handling images. |
| dist/esm/build/webpack/config/blocks/images/messages.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/config/helpers.js | safe | No malicious patterns detected; the file contains only standard webpack configuration helper functions with no exfiltration, obfuscation, or dangerous operations. |
| dist/esm/build/webpack/config/index.js | safe | No malicious patterns detected; the file is a standard webpack configuration builder for Next.js with no network, filesystem, process execution, or obfuscation red flags. |
| dist/esm/build/webpack/config/utils.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/css-loader/src/CssSyntaxError.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/css-loader/src/camelcase.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/css-loader/src/index.js | safe | No malicious patterns detected; this is a legitimate css-loader source file for webpack that performs standard CSS import parsing and module handling. |
| dist/esm/build/webpack/loaders/css-loader/src/plugins/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-icss-parser.js | safe | No malicious patterns detected; this is a standard CSS Modules ICSS parser plugin from Next.js with no network, filesystem, process, or obfuscated code concerns. |
| dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-import-parser.js | safe | No malicious patterns detected; the code is a legitimate PostCSS import parser from Next.js CSS loader with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/build/webpack/loaders/css-loader/src/runtime/api.js | safe | No malicious patterns detected; this is the standard css-loader runtime API for building CSS strings with source maps. |
| dist/esm/build/webpack/loaders/css-loader/src/runtime/getUrl.js | safe | This is a legitimate CSS loader utility function for URL handling with no malicious patterns detected |
| dist/esm/build/webpack/loaders/css-loader/src/utils.js | safe | No malicious patterns detected; the file contains standard CSS-loader utility functions without data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning. |
| dist/esm/build/webpack/loaders/devtool/devtool-style-inject.js | safe | This is a benign Next.js devtools utility that injects styles into a shadow DOM element and observes DOM mutations; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or command execution were found. |
| dist/esm/build/webpack/loaders/empty-loader.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/error-loader.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/get-module-build-info.js | safe | No malicious patterns detected; the code is a simple getter function for webpack module build info. |
| dist/esm/build/webpack/loaders/instrumentation-client-stub.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/loaders/lightningcss-loader/src/codegen.js | safe | No malicious patterns detected; the code is a legitimate webpack CSS loader code generator that only produces import/export strings and CSS module code without network, filesystem, or process access. |
| dist/esm/build/webpack/loaders/lightningcss-loader/src/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/loaders/lightningcss-loader/src/interface.js | safe | The file only defines a simple enum-like object for cache keys and contains no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| dist/esm/build/webpack/loaders/lightningcss-loader/src/loader.js | safe | This is a legitimate Next.js lightningcss-loader module for webpack that handles CSS transformation with no malicious patterns detected. |
| dist/esm/build/webpack/loaders/lightningcss-loader/src/minify.js | safe | This webpack plugin for CSS minification using lightningcss contains no malicious patterns; it performs legitimate asset transformation using local bindings and standard webpack APIs. |
| dist/esm/build/webpack/loaders/lightningcss-loader/src/utils.js | safe | No malicious patterns detected; the code only converts browserslist targets to Lightning CSS target versions with simple caching. |
| dist/esm/build/webpack/loaders/metadata/types.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/modularize-import-loader.js | safe | No malicious patterns detected; the loader performs a straightforward re-export transformation without any security-sensitive operations. |
| dist/esm/build/webpack/loaders/next-app-loader/create-app-route-code.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-app-loader/index.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-barrel-loader.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-client-pages-loader.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack loader that generates a client-side page registration snippet using standard module APIs. |
| dist/esm/build/webpack/loaders/next-edge-app-route-loader/index.js | safe | This is a standard Next.js webpack loader that processes module options and constructs entrypoints; no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or shell commands were detected. |
| dist/esm/build/webpack/loaders/next-edge-function-loader.js | safe | The loader only reads build options provided by the invoking webpack config, parses trusted base64 middleware config, and generates an ESM wrapper for a Next.js Edge Function; no malicious patterns detected. |
| dist/esm/build/webpack/loaders/next-edge-ssr-loader/index.js | safe | No malicious patterns detected; the code is a legitimate Next.js webpack loader for edge SSR bundling. |
| dist/esm/build/webpack/loaders/next-error-browser-binary-loader.js | safe | No malicious patterns detected; the loader simply throws an error when a Node.js binary module is imported in the browser. |
| dist/esm/build/webpack/loaders/next-flight-action-entry-loader.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-flight-client-entry-loader.js | safe | No malicious patterns detected; the code is a legitimate Next.js webpack loader that generates dynamic import statements for client modules. |
| dist/esm/build/webpack/loaders/next-flight-client-module-loader.js | safe | No malicious patterns detected in the webpack loader; it performs expected build-time source transformation and metadata assignment without exfiltration, obfuscation, or process execution. |
| dist/esm/build/webpack/loaders/next-flight-css-loader.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-flight-loader/action-client-wrapper.js | safe | The file only re-exports internal Next.js and React server component utilities with no malicious patterns, network calls, or dynamic code execution. |
| dist/esm/build/webpack/loaders/next-flight-loader/action-validate.js | safe | No malicious patterns detected; the code is a straightforward runtime validation helper for Next.js server action exports. |
| dist/esm/build/webpack/loaders/next-flight-loader/cache-wrapper.js | safe | This file is a simple re-export of a cache function from an internal Next.js module with no malicious patterns. |
| dist/esm/build/webpack/loaders/next-flight-loader/index.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack loader for React Server Components. |
| dist/esm/build/webpack/loaders/next-flight-loader/module-proxy.js | safe | No malicious patterns detected; the file only re-exports a React Server Components proxy helper without any suspicious behavior. |
| dist/esm/build/webpack/loaders/next-flight-loader/server-reference.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-flight-loader/track-dynamic-import.js | safe | This is a simple re-export module from Next.js internal code with no malicious patterns detected. |
| dist/esm/build/webpack/loaders/next-flight-server-reference-proxy-loader.js | safe | No malicious patterns detected; the loader only generates a static import and call to a trusted internal helper using validated option values. |
| dist/esm/build/webpack/loaders/next-font-loader/postcss-next-font.js | safe | The code is a legitimate Next.js PostCSS plugin for next/font that processes @font-face declarations with no malicious patterns, network requests, or dynamic code execution. |
| dist/esm/build/webpack/loaders/next-image-loader/blur.js | safe | No malicious patterns detected in the Next.js image blur loader; it performs legitimate image resizing and base64 encoding with no external data exfiltration, credential harvesting, or command execution. |
| dist/esm/build/webpack/loaders/next-image-loader/index.js | safe | Next.js image loader that computes image metadata/hashes and emits files; no malicious patterns detected. |
| dist/esm/build/webpack/loaders/next-invalid-import-error-loader.js | safe | No malicious patterns detected; the loader simply throws an error with a custom message and conditionally clears the stack. |
| dist/esm/build/webpack/loaders/next-metadata-image-loader.js | safe | The code is a legitimate Next.js webpack loader for metadata images with no malicious patterns detected; minor dynamic code generation and file reads are expected loader behaviors. |
| dist/esm/build/webpack/loaders/next-metadata-route-loader.js | safe | No malicious patterns detected; this is Next.js's legitimate metadata route webpack loader that reads local asset files and generates route code for sitemaps, robots, manifest, and social images. |
| dist/esm/build/webpack/loaders/next-middleware-asset-loader.js | safe | No malicious patterns detected; the loader performs standard webpack asset emission and path interpolation without any suspicious behavior. |
| dist/esm/build/webpack/loaders/next-middleware-loader.js | safe | The file is a standard Next.js webpack loader that decodes base64-encoded matcher and middleware configuration options and loads the middleware entrypoint, with no malicious patterns detected. |
| dist/esm/build/webpack/loaders/next-middleware-wasm-loader.js | safe | No malicious patterns detected; the loader only computes a SHA-1 hash of the WASM source for naming and emits the file via the webpack build API. |
| dist/esm/build/webpack/loaders/next-root-params-loader.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/loaders/next-route-loader/index.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/next-style-loader/index.js | safe | The file is a legitimate Next.js style loader that generates code for injecting CSS, with no malicious patterns such as data exfiltration, credential harvesting, or arbitrary code execution. |
| dist/esm/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoLinkTag.js | safe | This is a legitimate Next.js style-loader runtime that injects <link> tags for stylesheets with no malicious patterns, external calls, or obfuscation. |
| dist/esm/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoStyleTag.js | safe | This is a standard Next.js/webpack style-loader runtime for injecting CSS into the DOM; it contains no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| dist/esm/build/webpack/loaders/next-style-loader/runtime/isEqualLocals.js | safe | No malicious patterns detected; the file is a simple utility function for comparing CSS module locals with no network, file system, process, or dynamic execution behavior. |
| dist/esm/build/webpack/loaders/next-swc-loader.js | safe | No malicious patterns detected; this is the legitimate Next.js SWC webpack loader that transforms source code via the SWC compiler. |
| dist/esm/build/webpack/loaders/postcss-loader/src/Error.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/postcss-loader/src/Warning.js | safe | No malicious patterns detected; the file is a benign PostCSS warning wrapper class with a harmless Next.js error code annotation. |
| dist/esm/build/webpack/loaders/postcss-loader/src/index.js | safe | The code is a standard PostCSS loader for webpack that performs legitimate CSS processing and does not contain any malicious patterns. |
| dist/esm/build/webpack/loaders/postcss-loader/src/utils.js | safe | No malicious patterns detected; the code only normalizes source map paths without network, filesystem, or execution risks. |
| dist/esm/build/webpack/loaders/resolve-url-loader/index.js | safe | No malicious patterns detected; the file is a legitimate webpack loader for resolving url() paths in CSS, with standard use of source maps, PostCSS, and async callbacks. |
| dist/esm/build/webpack/loaders/resolve-url-loader/lib/file-protocol.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/loaders/resolve-url-loader/lib/join-function.js | safe | No malicious patterns detected; the code is a standard resolve-url-loader utility for resolving file paths with debug logging and contains no exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior. |
| dist/esm/build/webpack/loaders/resolve-url-loader/lib/postcss.js | safe | The code is a legitimate PostCSS plugin for resolving URLs in CSS, with no malicious patterns detected. |
| dist/esm/build/webpack/loaders/resolve-url-loader/lib/value-processor.js | safe | No malicious patterns detected; the code is a legitimate webpack loader utility for resolving url() statements in CSS values. |
| dist/esm/build/webpack/loaders/utils.js | safe | No malicious patterns detected; the code is a legitimate Next.js webpack loader utility with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/build/webpack/plugins/build-manifest-plugin-utils.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/build-manifest-plugin.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/copy-file-plugin.js | safe | No malicious patterns detected; the code is a standard webpack plugin that reads a local file and emits it as an asset with caching, using only approved Next.js compiled dependencies. |
| dist/esm/build/webpack/plugins/css-chunking-plugin.js | safe | No malicious patterns detected; the code is a legitimate webpack CSS chunking plugin that only manipulates compilation chunks and reads a non-sensitive environment variable for optional summary output. |
| dist/esm/build/webpack/plugins/css-minimizer-plugin.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/deferred-entries-plugin.js | safe | This is a legitimate Next.js webpack plugin that manages deferred entrypoints without any malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/build/webpack/plugins/devtools-ignore-list-plugin.js | safe | The webpack plugin only manipulates source map assets to add an ignore list for devtools; no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or shell commands were detected. |
| dist/esm/build/webpack/plugins/flight-client-entry-plugin.js | safe | No malicious patterns detected; code is a legitimate Next.js webpack plugin for managing client entries and server action manifests. |
| dist/esm/build/webpack/plugins/flight-manifest-plugin.js | safe | No malicious patterns detected; this is a standard Next.js webpack plugin that generates React Server Component client reference manifests. |
| dist/esm/build/webpack/plugins/force-complete-runtime.js | safe | No malicious patterns detected; the plugin is a benign Webpack runtime configuration helper with no network, filesystem, process, or credential access. |
| dist/esm/build/webpack/plugins/jsconfig-paths-plugin.js | safe | No malicious patterns detected; the code is a legitimate webpack resolver plugin for TypeScript/jsconfig path aliases. |
| dist/esm/build/webpack/plugins/memory-with-gc-cache-plugin.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/plugins/middleware-plugin.js | safe | This is a legitimate Next.js webpack plugin implementing Edge Runtime security controls; no malicious patterns such as exfiltration, credential harvesting, backdoors, or unauthorized code execution were detected. |
| dist/esm/build/webpack/plugins/mini-css-extract-plugin.js | safe | No malicious patterns detected; the file only extends a bundled webpack plugin with a simple flag, with no external calls, obfuscation, or install-time behavior. |
| dist/esm/build/webpack/plugins/minify-webpack-plugin/src/index.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/next-font-manifest-plugin.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/next-trace-entrypoints-plugin.js | safe | No malicious patterns detected; the file is a legitimate Next.js webpack trace entrypoints plugin performing file tracing and asset emission without exfiltration, credential harvesting, obfuscation, or suspicious process execution. |
| dist/esm/build/webpack/plugins/next-types-plugin/index.js | safe | No malicious patterns detected; this is a legitimate Next.js webpack plugin that generates TypeScript type definition files for App Router pages, layouts, and routes. |
| dist/esm/build/webpack/plugins/next-types-plugin/shared.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/nextjs-require-cache-hot-reloader.js | safe | No malicious patterns detected; this is a standard Webpack plugin for Next.js hot reloading that clears require cache entries. |
| dist/esm/build/webpack/plugins/optional-peer-dependency-resolve-plugin.js | safe | This webpack resolver plugin only implements standard optional-peer-dependency resolution logic with no malicious patterns detected. |
| dist/esm/build/webpack/plugins/pages-manifest-plugin.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/profiling-plugin.js | safe | No malicious patterns detected; the code is a legitimate webpack profiling plugin that instruments compiler hooks without exfiltration, credential harvesting, or dynamic code execution. |
| dist/esm/build/webpack/plugins/react-loadable-plugin.js | safe | This is a legitimate Next.js webpack plugin for React Loadable manifest generation with no malicious patterns detected. |
| dist/esm/build/webpack/plugins/rspack-flight-client-entry-plugin.js | safe | No malicious patterns detected; the code is a standard build-time plugin for Rspack that manages client entries and does not perform any suspicious network, filesystem, or process operations. |
| dist/esm/build/webpack/plugins/rspack-profiling-plugin.js | safe | No malicious patterns detected; the code is a legitimate Rspack profiling plugin that tracks compilation spans using WeakMaps without network, filesystem, or process manipulation. |
| dist/esm/build/webpack/plugins/slow-module-detection-plugin.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/plugins/subresource-integrity-plugin.js | safe | No malicious patterns detected; the code is a legitimate webpack plugin for generating Subresource Integrity (SRI) hashes, with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/esm/build/webpack/plugins/telemetry-plugin/telemetry-plugin.js | safe | No malicious patterns detected; the code is a standard Webpack telemetry plugin for tracking Next.js feature usage. |
| dist/esm/build/webpack/plugins/telemetry-plugin/update-telemetry-loader-context-from-swc.js | safe | No malicious patterns detected; the code only parses telemetry data and updates in-memory tracking objects without network, filesystem, or execution activity. |
| dist/esm/build/webpack/plugins/telemetry-plugin/use-cache-tracker-utils.js | safe | No malicious patterns detected; the file contains only simple utility functions for creating and merging use-cache tracker maps. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/getModuleTrace.js | safe | The code is a legitimate Next.js build-time utility that formats webpack module trace information and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious network activity. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/index.js | safe | No malicious patterns detected; the code is a standard webpack plugin that filters warnings and processes build errors. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parse-dynamic-code-evaluation-error.js | safe | No malicious patterns detected; the file is a standard webpack error parsing utility with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseBabel.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseCss.js | safe | The code is a benign webpack error parser for CSS syntax errors and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious process/network activity. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNextAppLoaderError.js | safe | No malicious patterns detected; the code only inspects webpack module loaders and formats error messages without network, filesystem, or process manipulation. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNextFontError.js | safe | This file is a legitimate Next.js webpack error parser for @next/font errors with no malicious patterns detected. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNextInvalidImportError.js | safe | No malicious patterns detected; the code only processes Next.js webpack build errors locally without network, filesystem, or dynamic execution concerns. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNotFoundError.js | safe | No malicious patterns detected; the file is a standard Next.js webpack error-formatting plugin that only reads source maps and module metadata for developer error messages, with no network, file system, process, or dynamic code execution behavior. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseScss.js | safe | No malicious patterns detected; the file only parses Sass error messages and formats them for Webpack error reporting. |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/simpleWebpackError.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/build/webpack/plugins/wellknown-errors-plugin/webpackModuleError.js | safe | No malicious patterns detected; the code is a legitimate webpack error-parsing plugin that only reads files within the build context to enrich error messages. |
| dist/esm/build/webpack/stringify-request.js | safe | No malicious patterns detected |
| dist/esm/build/webpack/utils.js | safe | No malicious patterns detected; the code is a standard webpack utility module for module traversal and entry processing without data exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/build/write-build-id.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/add-base-path.js | safe | No malicious patterns detected; the file only performs base path manipulation using environment variables for Next.js routing. |
| dist/esm/client/add-locale.js | safe | No malicious patterns detected; the code is a benign Next.js locale utility using a conditional dynamic require gated by an environment variable. |
| dist/esm/client/app-bootstrap.js | safe | No malicious patterns detected in this Next.js app bootstrap module, which only loads polyfills and beforeInteractive scripts and triggers hydration. |
| dist/esm/client/app-call-server.js | safe | No malicious patterns detected |
| dist/esm/client/app-dir/form.js | safe | No malicious patterns detected; the code is a standard Next.js client-side Form component handling navigation and prefetching without any exfiltration, obfuscation, or dangerous operations. |
| dist/esm/client/app-dir/link.react-server.js | safe | This is a standard Next.js React Server Component wrapper for the Link component with no malicious patterns, network calls, dynamic execution, or file system access. |
| dist/esm/client/app-find-source-map-url.js | safe | No malicious patterns detected; the code only constructs a local URL for Next.js dev-server source map lookups, guarded by a dev-server environment check with no data exfiltration, credential access, or dynamic execution. |
| dist/esm/client/app-index.js | safe | This is a standard Next.js client-side entry point module with no malicious patterns; dynamic requires and global stream handling are legitimate framework internals. |
| dist/esm/client/app-link-gc.js | safe | This is a legitimate Next.js development-only link garbage collection utility that manages duplicate stylesheet links; no malicious patterns detected. |
| dist/esm/client/app-next-dev.js | safe | No malicious patterns detected; the code is a standard Next.js development entry point that bootstraps the app and renders a dev overlay. |
| dist/esm/client/app-next-turbopack.js | safe | This is standard Next.js Turbopack client bootstrap code with no malicious patterns detected. |
| dist/esm/client/app-next.js | safe | No malicious patterns detected; the file is a standard Next.js client bootstrap module with legitimate imports and dynamic requires. |
| dist/esm/client/app-webpack.js | safe | No malicious patterns detected |
| dist/esm/client/asset-prefix.js | safe | No malicious patterns detected |
| dist/esm/client/assign-location.js | safe | No malicious patterns detected; the code is a simple URL resolution utility with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/client/compat/router.js | safe | No malicious patterns detected |
| dist/esm/client/components/app-router-announcer.js | safe | No malicious patterns detected; the code is a standard Next.js route announcer for accessibility that manipulates DOM and uses React hooks without any exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| dist/esm/client/components/app-router-headers.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/app-router-instance.js | safe | This is legitimate Next.js app router client-side code with standard navigation, prefetching, and action queue handling; it includes security checks against javascript: URLs and contains no malicious patterns. |
| dist/esm/client/components/app-router-utils.js | safe | No malicious patterns detected |
| dist/esm/client/components/bfcache-state-manager.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/app-error.js | safe | No malicious patterns detected; the file is a static Next.js 500 error page, with only a benign but noteworthy use of dangerouslySetInnerHTML for a bundled stylesheet constant. |
| dist/esm/client/components/builtin/default-null.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/default.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/empty-stub.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/error-styles.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/forbidden.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/global-error.js | safe | No malicious patterns detected; the file is a legitimate Next.js global error boundary component with no data exfiltration, code execution, or suspicious network/file system activity. |
| dist/esm/client/components/builtin/global-not-found.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/layout.js | safe | This is a simple React layout component with no malicious patterns, network requests, file system access, or dynamic code execution. |
| dist/esm/client/components/builtin/not-found.js | safe | No malicious patterns detected |
| dist/esm/client/components/builtin/unauthorized.js | safe | No malicious patterns detected |
| dist/esm/client/components/catch-error.js | safe | This is a legitimate Next.js client-side error boundary component with no malicious patterns detected. |
| dist/esm/client/components/client-boundary-params.browser.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/client-boundary-params.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/client-page.js | safe | This is legitimate Next.js internal client component code with no malicious patterns detected |
| dist/esm/client/components/client-segment.js | safe | No malicious patterns detected; the code is a standard Next.js client segment wrapper that passes params to a component. |
| dist/esm/client/components/dev-root-http-access-fallback-boundary.js | safe | No malicious patterns detected; the file contains legitimate Next.js client-side error boundary logic with no external calls, credential access, or dynamic code execution. |
| dist/esm/client/components/error-boundary.js | safe | The code is a standard Next.js React error boundary for client components with no malicious patterns detected. |
| dist/esm/client/components/errors/root-error-boundary.js | safe | No malicious patterns detected; the code is a standard React error boundary with bot detection and no external data handling, dynamic execution, or filesystem/network operations. |
| dist/esm/client/components/forbidden.js | safe | No malicious patterns detected; the code is a legitimate Next.js experimental forbidden() helper that only checks an environment variable and throws a structured error. |
| dist/esm/client/components/handle-isr-error.js | safe | No malicious patterns detected |
| dist/esm/client/components/hooks-server-context.js | safe | No malicious patterns detected |
| dist/esm/client/components/http-access-fallback/error-boundary.js | safe | No malicious patterns detected; the file is a legitimate Next.js HTTP access fallback error boundary with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/client/components/http-access-fallback/error-fallback.js | safe | No malicious patterns detected; the file is a standard React error fallback component with static inline CSS and no network, filesystem, or process operations. |
| dist/esm/client/components/http-access-fallback/http-access-fallback.js | safe | No malicious patterns detected; the file only contains pure helper functions for identifying HTTP access fallback errors. |
| dist/esm/client/components/instant-samples.browser.js | safe | No malicious patterns detected |
| dist/esm/client/components/instant-samples.js | safe | This appears to be legitimate Next.js internal instrumentation code for validating route params and search params in client validation contexts, with no malicious patterns detected. |
| dist/esm/client/components/instant-validation/boundary.js | safe | This file only re-exports React context and component symbols for a client-side validation boundary, with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/client/components/instant-validation/impl.browser.js | safe | No malicious patterns detected |
| dist/esm/client/components/instant-validation/impl.js | safe | No malicious patterns detected; the file only re-exports internal modules and includes a source map reference. |
| dist/esm/client/components/is-next-router-error.js | safe | No malicious patterns detected |
| dist/esm/client/components/layout-router.js | safe | This is legitimate Next.js App Router internal code handling scroll/focus management, layout rendering, and error boundaries with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor installation. |
| dist/esm/client/components/match-segments.js | safe | No malicious patterns detected; the file contains a pure segment-matching utility function with no I/O, network, process, or dynamic execution behavior. |
| dist/esm/client/components/nav-failure-handler.js | safe | No malicious patterns detected; the code is a standard Next.js navigation error handler that performs a client-side redirect on uncaught errors, with no data exfiltration, credential access, or suspicious behavior. |
| dist/esm/client/components/navigation-devtools.js | safe | No malicious patterns detected; this is legitimate React DevTools instrumentation code with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/client/components/navigation-dynamic-rendering.browser.js | safe | No malicious patterns detected |
| dist/esm/client/components/navigation-dynamic-rendering.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/navigation-untracked.js | safe | No malicious patterns detected; the file only reads React context and an async storage store for route parameter checks. |
| dist/esm/client/components/navigation.js | safe | No malicious patterns detected |
| dist/esm/client/components/navigation.react-server.js | safe | No malicious patterns detected; the file only contains safe re-exports and a server-side guard for a client-only error helper. |
| dist/esm/client/components/noop-head.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/not-found.js | safe | This is a benign Next.js internal utility for throwing a 404 not-found error; no malicious patterns detected. |
| dist/esm/client/components/offline.js | safe | No malicious patterns detected; the code implements legitimate offline detection, connectivity polling, and retry logic with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| dist/esm/client/components/promise-queue.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/readonly-url-search-params.js | safe | No malicious patterns detected; the code is a standard read-only wrapper around URLSearchParams that only throws errors on mutating methods. |
| dist/esm/client/components/redirect-boundary.js | safe | No malicious patterns detected; this is a standard Next.js client-side redirect error boundary implementing navigation on redirect errors. |
| dist/esm/client/components/redirect-error.js | safe | No malicious patterns detected; the code is a simple redirect error validation utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/client/components/redirect-status-code.js | safe | No malicious patterns detected; this file only defines an enum of HTTP redirect status codes with a source map reference. |
| dist/esm/client/components/redirect.js | safe | No malicious patterns detected; this is legitimate Next.js redirect utility code with no exfiltration, obfuscation, process spawning, or filesystem manipulation. |
| dist/esm/client/components/render-from-template-context.js | safe | No malicious patterns detected |
| dist/esm/client/components/router-reducer/compute-changed-path.js | safe | No malicious patterns detected; the code is a standard Next.js router utility for computing changed paths and extracting params from flight router state. |
| dist/esm/client/components/router-reducer/create-href-from-url.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/router-reducer/create-initial-router-state.js | safe | No malicious patterns detected; the code is a legitimate Next.js router state initializer with no network exfiltration, credential harvesting, dynamic execution, or process spawning. |
| dist/esm/client/components/router-reducer/create-router-cache-key.js | safe | No malicious patterns detected |
| dist/esm/client/components/router-reducer/fetch-server-response.js | safe | This is legitimate Next.js App Router client-side RSC fetch logic with no malicious patterns detected. |
| dist/esm/client/components/router-reducer/is-navigating-to-new-root-layout.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/router-reducer/ppr-navigations.js | safe | This is legitimate Next.js App Router client-side navigation code with no malicious patterns detected. |
| dist/esm/client/components/router-reducer/reducers/committed-state.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/router-reducer/reducers/find-head-in-cache.js | safe | No malicious patterns detected; the code is a pure recursive cache lookup function with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/client/components/router-reducer/reducers/has-interception-route-in-current-tree.js | safe | No malicious patterns detected |
| dist/esm/client/components/router-reducer/reducers/hmr-refresh-reducer.js | safe | No malicious patterns detected; the file contains a straightforward HMR refresh reducer with no network, filesystem, process execution, or obfuscated behavior. |
| dist/esm/client/components/router-reducer/reducers/navigate-reducer.js | safe | No malicious patterns detected; the code is a standard Next.js client-side navigation reducer. |
| dist/esm/client/components/router-reducer/reducers/refresh-reducer.js | safe | This is a standard Next.js client-side router refresh reducer that manipulates internal navigation state and caches, with no malicious patterns detected. |
| dist/esm/client/components/router-reducer/reducers/restore-reducer.js | safe | No malicious patterns detected; the file is a legitimate Next.js router reducer with only internal imports and no network, filesystem, process, or dynamic code execution activity. |
| dist/esm/client/components/router-reducer/reducers/server-action-reducer.js | safe | This file is standard Next.js App Router internals implementing Server Actions; no malicious patterns, credential harvesting, obfuscation, or external data exfiltration were found. |
| dist/esm/client/components/router-reducer/reducers/server-patch-reducer.js | safe | No malicious patterns detected; this is a Next.js internal router reducer that handles server-patch retry navigation without any suspicious network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/client/components/router-reducer/router-reducer-types.js | safe | No malicious patterns detected |
| dist/esm/client/components/router-reducer/router-reducer.js | safe | No malicious patterns detected; the code is a standard Next.js router reducer with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| dist/esm/client/components/router-reducer/set-cache-busting-search-param.js | safe | No malicious patterns detected; this is standard Next.js client-side cache-busting utility code using Web Crypto for hashing and URL manipulation. |
| dist/esm/client/components/router-transition.js | safe | No malicious patterns detected; the code is a legitimate Next.js router transition instrumentation module with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns. |
| dist/esm/client/components/segment-cache/bfcache.js | safe | The bfcache module implements in-memory caching for React Server Component payloads with no network, filesystem, process, or dynamic execution behavior detected. |
| dist/esm/client/components/segment-cache/cache-key.js | safe | No malicious patterns detected |
| dist/esm/client/components/segment-cache/cache-map.js | safe | This is a standard LRU-based cache map implementation with fallback lookup logic; no malicious patterns, network calls, dynamic code execution, or credential access were detected. |
| dist/esm/client/components/segment-cache/fetch.js | safe | No malicious patterns detected; the code is a benign internal fetch wrapper for Next.js router with a testing API bypass mechanism. |
| dist/esm/client/components/segment-cache/lru.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/segment-cache/navigation-testing-lock.disabled.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/segment-cache/navigation-testing-lock.js | safe | This is legitimate Next.js internal code for the Instant Navigation Testing API; it contains no malicious patterns, exfiltration, credential harvesting, or command execution. |
| dist/esm/client/components/segment-cache/navigation.js | safe | The code is part of Next.js client-side router navigation logic and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or unauthorized process execution. |
| dist/esm/client/components/segment-cache/optimistic-routes.js | safe | No malicious patterns detected |
| dist/esm/client/components/segment-cache/prefetch.js | safe | The prefetch module only orchestrates internal cache prefetching using validated URL inputs and imported utilities, with no suspicious network, filesystem, code execution, or credential-handling patterns. |
| dist/esm/client/components/segment-cache/scheduler.js | safe | This is a legitimate Next.js App Router prefetch scheduler module with no malicious patterns detected. |
| dist/esm/client/components/segment-cache/types.js | safe | No malicious patterns detected; the file only defines static TypeScript-style enums and constants for a segment cache with no executable logic, network activity, or file/process access. |
| dist/esm/client/components/segment-cache/vary-path.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/server-async-storage.browser.js | safe | No malicious patterns detected |
| dist/esm/client/components/server-async-storage.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/static-generation-bailout.js | safe | No malicious patterns detected |
| dist/esm/client/components/styles/access-error-styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/unauthorized.js | safe | No malicious patterns detected |
| dist/esm/client/components/unrecognized-action-error.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/components/unresolved-thenable.js | safe | No malicious patterns detected; the file only defines an inert thenable used to suspend indefinitely. |
| dist/esm/client/components/unstable-rethrow.browser.js | safe | No malicious patterns detected; the file is a standard error rethrow utility with no network, filesystem, process, or obfuscated code. |
| dist/esm/client/components/unstable-rethrow.js | safe | No malicious patterns detected; this is legitimate Next.js error-handling utility code with only static imports and error type checks. |
| dist/esm/client/components/use-action-queue.js | safe | No malicious patterns detected; the file is legitimate Next.js App Router client internals with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/esm/client/components/use-offline.js | safe | The file implements a standard React offline-state context with no malicious patterns, network calls, credential access, or dynamic code execution. |
| dist/esm/client/dev/debug-channel.js | safe | The file implements local Next.js debug-channel buffering in IndexedDB and request ID handling with no external network calls, credential harvesting, dynamic code execution, or process spawning; no malicious patterns detected. |
| dist/esm/client/dev/error-overlay/websocket.js | safe | This file is a simple re-export of a message listener function with no malicious patterns, network activity, or code execution. |
| dist/esm/client/dev/fouc.js | safe | No malicious patterns detected; the code is a standard Next.js development utility for removing no-FOUC style workarounds before hydration. |
| dist/esm/client/dev/hot-middleware-client.js | safe | No malicious patterns detected; the file is a Next.js development hot-reload client with no exfiltration, obfuscation, or process execution behavior. |
| dist/esm/client/dev/hot-reloader/app/hot-reloader-app.js | safe | This is a legitimate Next.js dev hot-reloader client module with no malicious patterns detected; all network activity is via the existing HMR WebSocket, code execution is limited to standard webpack HMR APIs, and no credential harvesting, exfiltration, or obfuscated payloads are present. |
| dist/esm/client/dev/hot-reloader/get-socket-url.js | safe | No malicious patterns detected; the code only computes a WebSocket URL for a development hot-reloader using standard browser APIs. |
| dist/esm/client/dev/hot-reloader/pages/hot-reloader-pages.js | safe | No malicious patterns detected; the file is legitimate Next.js HMR client code for development builds only. |
| dist/esm/client/dev/hot-reloader/pages/websocket.js | safe | No malicious patterns detected; this is a standard Next.js HMR WebSocket client with reconnection logic. |
| dist/esm/client/dev/hot-reloader/shared.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/client/dev/hot-reloader/turbopack-hot-reloader-common.js | safe | No malicious patterns detected; the code is a legitimate Turbopack HMR client utility that manages HMR update reporting without any network, filesystem, or process-related risks. |
| dist/esm/client/dev/noop-turbopack-hmr.js | safe | No malicious patterns detected |
| dist/esm/client/dev/on-demand-entries-client.js | safe | No malicious patterns detected; the code is a standard Next.js dev-time on-demand entries client that sends periodic ping messages over the existing dev websocket. |
| dist/esm/client/dev/report-hmr-latency.js | safe | No malicious patterns detected |
| dist/esm/client/dev/runtime-error-handler.js | safe | No malicious patterns detected |
| dist/esm/client/flight-data-helpers.js | safe | This is a Next.js internal Flight data helper module containing only data parsing, URL parameter extraction, and state normalization logic with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/client/form-shared.js | safe | This is a legitimate Next.js form handling utility with proper URL validation and no malicious patterns detected. |
| dist/esm/client/form.js | safe | No malicious patterns detected; the code is a standard React form component for Next.js with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/client/get-domain-locale.js | safe | No malicious patterns detected; the code is a standard Next.js i18n utility for domain/locale resolution with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/client/has-base-path.js | safe | No malicious patterns detected; the file only exports a simple utility that checks a path prefix against a build-time base path environment variable. |
| dist/esm/client/image-component.js | safe | No malicious patterns detected; this is legitimate Next.js Image component code with standard React patterns and no data exfiltration, credential harvesting, or dynamic code execution. |
| dist/esm/client/index.js | safe | This is a legitimate Next.js client-side hydration entry point with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/esm/client/legacy/image.js | safe | No malicious patterns detected; this is legitimate Next.js legacy image component code with standard image loading, URL generation, and performance optimization logic. |
| dist/esm/client/lib/console.js | safe | The code is a standard console argument formatting utility with no malicious patterns detected. |
| dist/esm/client/lib/javascript-url.js | safe | No malicious patterns detected; the code is a standard JavaScript URL protocol sanitization check adapted from React. |
| dist/esm/client/lib/promise.js | safe | No malicious patterns detected; the code is a legitimate promise timeout helper using requestIdleCallback. |
| dist/esm/client/link.js | safe | No malicious patterns detected; this is a standard Next.js Link component with expected client-side routing and prefetching logic. |
| dist/esm/client/navigation-build-id.js | safe | No malicious patterns detected |
| dist/esm/client/next-dev-turbopack.js | safe | This is a legitimate Next.js Turbopack development client module with no malicious patterns detected. |
| dist/esm/client/next-dev.js | safe | No malicious patterns detected; the file is a standard Next.js development client bootstrap module. |
| dist/esm/client/next.js | safe | No malicious patterns detected; the file contains standard Next.js client-side initialization code. |
| dist/esm/client/normalize-locale-path.js | safe | No malicious patterns detected; the code is a standard Next.js i18n locale path normalization utility with a conditional dynamic require gated by an environment flag. |
| dist/esm/client/normalize-trailing-slash.js | safe | No malicious patterns detected; the code only normalizes URL trailing slashes using standard string and regex operations. |
| dist/esm/client/page-bootstrap.js | safe | No malicious patterns detected |
| dist/esm/client/page-loader.js | safe | No malicious patterns detected; this is a legitimate Next.js page loader module with standard client-side routing and data fetching logic. |
| dist/esm/client/portal/index.js | safe | No malicious patterns detected |
| dist/esm/client/react-client-callbacks/on-recoverable-error.js | safe | No malicious patterns detected; the code is standard Next.js client error handling with a development-only static require and environment-gated test suppression. |
| dist/esm/client/react-client-callbacks/report-global-error.js | safe | No malicious patterns detected |
| dist/esm/client/register-deployment-id-global.js | safe | No malicious patterns detected; the code only reads a deployment ID and assigns it to a global variable at import time. |
| dist/esm/client/remove-base-path.js | safe | No malicious patterns detected; the code is a simple, side-effect-free utility for removing a base path from URLs. |
| dist/esm/client/remove-locale.js | safe | No malicious patterns detected; the file contains a benign locale-removal utility from Next.js with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/client/request-idle-callback.js | safe | No malicious patterns detected |
| dist/esm/client/request/io.browser.js | safe | No malicious patterns detected; the file only defines a pre-resolved Promise for React's use() hook. |
| dist/esm/client/request/params.browser.dev.js | safe | No malicious patterns detected |
| dist/esm/client/request/params.browser.prod.js | safe | No malicious patterns detected; the code only caches Promises in a WeakMap and exports a simple wrapper function. |
| dist/esm/client/request/search-params.browser.dev.js | safe | No malicious patterns detected; the code is a development-only Next.js proxy for searchParams that logs warnings on synchronous access. |
| dist/esm/client/request/search-params.browser.prod.js | safe | No malicious patterns detected |
| dist/esm/client/resolve-href.js | safe | No malicious patterns detected; the code is a standard Next.js URL resolution utility with no exfiltration, credential access, dynamic execution, or process spawning. |
| dist/esm/client/route-announcer.js | safe | No malicious patterns detected; the file is a legitimate Next.js route announcer component that uses only React and local router context without network, filesystem, or process access. |
| dist/esm/client/route-loader.js | safe | This is a legitimate Next.js client-side route loader with no malicious patterns; it only performs expected script/style loading and prefetching using same-origin assets and standard browser APIs. |
| dist/esm/client/route-params.js | safe | No malicious patterns detected |
| dist/esm/client/router-transition-types.js | safe | No malicious patterns detected |
| dist/esm/client/router.js | safe | No malicious patterns detected; this is legitimate Next.js Pages Router client code with no exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| dist/esm/client/set-attributes-from-props.js | safe | The code is a benign utility for setting DOM attributes from React props, with no network, filesystem, process, or dynamic execution patterns. |
| dist/esm/client/tracing/report-to-socket.js | safe | No malicious patterns detected; the code only sends local dev spans to an internal websocket for telemetry. |
| dist/esm/client/tracing/tracer.js | safe | No malicious patterns detected |
| dist/esm/client/use-client-disallowed.js | safe | This file is a legitimate Next.js internal module that intentionally throws an error when Client Components are used in disallowed environments, with no malicious patterns detected. |
| dist/esm/client/use-intersection.js | safe | No malicious patterns detected |
| dist/esm/client/use-merged-ref.js | safe | No malicious patterns detected; the code is a legitimate React ref-merging utility with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/client/web-vitals.js | safe | No malicious patterns detected; the file only wires up Next.js' bundled web-vitals reporting to a user-supplied callback inside a React effect. |
| dist/esm/client/with-router.js | safe | No malicious patterns detected; this is a standard React higher-order component for injecting a router. |
| dist/esm/export/helpers/get-params.js | safe | No malicious patterns detected; the code is a standard Next.js utility for matching route parameters. |
| dist/esm/export/helpers/is-dynamic-usage-error.js | safe | No malicious patterns detected |
| dist/esm/export/index.js | safe | No malicious patterns detected; this is standard Next.js static export orchestration code that reads/writes within the project's distDir/outDir and does not exfiltrate data, harvest credentials, execute dynamic code, or spawn suspicious processes. |
| dist/esm/export/routes/app-page.js | safe | No malicious patterns detected; the code is part of Next.js static export logic with no external data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/export/routes/app-route.js | safe | No malicious patterns detected; this is legitimate Next.js app-route export logic with no data exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/esm/export/routes/pages.js | safe | This is legitimate Next.js static export code with no malicious patterns detected. |
| dist/esm/export/routes/types.js | safe | No malicious patterns detected |
| dist/esm/export/types.js | safe | No malicious patterns detected |
| dist/esm/export/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/export/worker.js | safe | This is legitimate Next.js export worker code with no malicious patterns; it only performs normal build-time page rendering, caching, and filesystem writes within the build output directory. |
| dist/esm/lib/batcher.js | safe | No malicious patterns detected; the code is a legitimate batching utility with no suspicious network, filesystem, process, or dynamic execution behavior. |
| dist/esm/lib/build-custom-route.js | safe | No malicious patterns detected |
| dist/esm/lib/bundler.js | safe | The code only manages bundler selection via environment variables and flags, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/lib/client-and-server-references.js | safe | No malicious patterns detected; the code contains only React server/client reference type checks with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/lib/coalesced-function.js | safe | No malicious patterns detected; the code is a benign request-coalescing utility with no external I/O, credential access, code execution, or install-time behavior. |
| dist/esm/lib/compile-error.js | safe | No malicious patterns detected |
| dist/esm/lib/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/create-client-router-filter.js | safe | No malicious patterns detected; the code only builds Bloom filters for static and dynamic routes without any exfiltration, credential access, obfuscation, or process execution. |
| dist/esm/lib/detached-promise.js | safe | No malicious patterns detected |
| dist/esm/lib/detect-typo.js | safe | The code implements a Levenshtein distance algorithm for typo detection without any malicious patterns, network activity, or system access. |
| dist/esm/lib/error-telemetry-utils.js | safe | This utility module only formats and extracts error codes from error digests without any network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/lib/fallback.js | safe | No malicious patterns detected; the file contains only pure fallback-mode parsing logic with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/lib/file-exists.js | safe | No malicious patterns detected; the code only checks file existence and type using standard fs APIs. |
| dist/esm/lib/find-pages-dir.js | safe | No malicious patterns detected; the code only performs standard filesystem directory lookups for Next.js project structure. |
| dist/esm/lib/find-root.js | safe | No malicious patterns detected; code performs expected filesystem inspection for workspace root detection. |
| dist/esm/lib/format-cli-help-output.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/format-dynamic-import-path.js | safe | The code performs legitimate path resolution and URL formatting with no malicious patterns, network activity, environment harvesting, or dynamic code execution. |
| dist/esm/lib/format-server-error.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/framework/boundary-components.js | safe | No malicious patterns detected; the code only defines React boundary components that render children with no external effects, network calls, or obfuscation. |
| dist/esm/lib/framework/boundary-constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/fs/rename.js | safe | No malicious patterns detected; the code is a legitimate, MIT-licensed file rename utility based on Microsoft VS Code's pfs.ts, with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security concerns. |
| dist/esm/lib/fs/write-atomic.js | safe | The code implements a standard atomic file write pattern using temporary files and rename, with no suspicious network, process, credential, or obfuscation behavior. |
| dist/esm/lib/generate-interception-routes-rewrites.js | safe | No malicious patterns detected; the code performs deterministic route rewrite generation for Next.js interception routes without network, filesystem, process, or dynamic execution behavior. |
| dist/esm/lib/get-files-in-dir.js | safe | No malicious patterns detected |
| dist/esm/lib/get-network-host.js | safe | No malicious patterns detected |
| dist/esm/lib/get-package-version.js | safe | No malicious patterns detected; the code simply reads package.json to resolve dependency versions using Node.js built-ins and bundled libraries. |
| dist/esm/lib/get-project-dir.js | safe | No malicious patterns detected; the code only resolves project directory paths and prints typo warnings, which is normal CLI behavior. |
| dist/esm/lib/git-worktree.js | safe | No malicious patterns detected; the code only reads local Git worktree metadata and does not perform network, process, or credential-related operations. |
| dist/esm/lib/has-necessary-dependencies.js | safe | No malicious patterns detected; the code appears to be a legitimate dependency resolution utility using only local filesystem APIs. |
| dist/esm/lib/helpers/get-cache-directory.js | safe | No malicious patterns detected |
| dist/esm/lib/helpers/get-reserved-port.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/import-next-warning.js | safe | No malicious patterns detected; the code only logs a warning on import. |
| dist/esm/lib/inline-static-env.js | safe | No malicious patterns detected; the code performs legitimate static environment variable inlining and chunk hash updating. |
| dist/esm/lib/install-dependencies.js | safe | No malicious patterns detected |
| dist/esm/lib/interop-default.js | safe | The file contains only a standard ESM interop helper that returns the default export when present, with no malicious patterns detected. |
| dist/esm/lib/is-api-route.js | safe | The file contains a simple utility function to check API routes with no malicious patterns. |
| dist/esm/lib/is-app-page-route.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/is-app-route-route.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/is-edge-runtime.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/is-error.js | safe | No malicious patterns detected; the code only provides error-handling utilities with circular-reference-safe stringification and no network, filesystem, process, or dynamic-execution behavior. |
| dist/esm/lib/is-interception-route-rewrite.js | safe | No malicious patterns detected |
| dist/esm/lib/is-internal-component.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/is-serializable-props.js | safe | No malicious patterns detected |
| dist/esm/lib/load-custom-routes.js | safe | No malicious patterns detected |
| dist/esm/lib/memory/gc-observer.js | safe | No malicious patterns detected; the code is a benign garbage collection performance observer that only logs warnings locally. |
| dist/esm/lib/memory/shutdown.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/memory/trace.js | safe | The code is a legitimate memory tracing utility that records memory metrics and optionally writes a heap snapshot for debugging; no malicious patterns were detected. |
| dist/esm/lib/metadata/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/metadata/default-metadata.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/metadata/generate/icon-mark.js | safe | No malicious patterns detected |
| dist/esm/lib/metadata/generate/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/metadata/get-metadata-route.js | safe | No malicious patterns detected; the code contains pure path/route normalization logic for Next.js metadata routes with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/lib/metadata/is-metadata-route.js | safe | No malicious patterns detected; the module only performs regex-based file path matching for Next.js metadata routes with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/lib/metadata/metadata-context.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/metadata/metadata.js | safe | This is Next.js metadata rendering code with no malicious patterns, network calls, credential access, dynamic execution, or shell commands detected. |
| dist/esm/lib/metadata/resolve-metadata.js | safe | This is legitimate Next.js framework code for resolving page metadata; no malicious patterns, exfiltration, obfuscation, or suspicious behavior were detected. |
| dist/esm/lib/metadata/resolvers/resolve-basics.js | safe | No malicious patterns detected |
| dist/esm/lib/metadata/resolvers/resolve-icons.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/metadata/resolvers/resolve-opengraph.js | safe | No malicious patterns detected; the code is a legitimate Next.js metadata resolver that only processes Open Graph and Twitter metadata. |
| dist/esm/lib/metadata/resolvers/resolve-title.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/metadata/resolvers/resolve-url.js | safe | No malicious patterns detected; the code is a legitimate Next.js metadata URL resolver with no data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| dist/esm/lib/metadata/types/alternative-urls-types.js | safe | This file only contains an empty export statement and a source map comment, with no executable code or malicious patterns. |
| dist/esm/lib/metadata/types/extra-types.js | safe | The file contains only type declaration comments and an empty export statement with no executable or malicious code. |
| dist/esm/lib/metadata/types/icons.js | safe | This file contains only an empty export statement and a source map reference, with no executable code or malicious patterns. |
| dist/esm/lib/metadata/types/manifest-types.js | safe | No malicious patterns detected |
| dist/esm/lib/metadata/types/metadata-interface.js | safe | This file contains only TypeScript type declarations and documentation comments for the Next.js Metadata API with no executable code or malicious patterns. |
| dist/esm/lib/metadata/types/metadata-types.js | safe | No malicious patterns detected |
| dist/esm/lib/metadata/types/opengraph-types.js | safe | No malicious patterns detected |
| dist/esm/lib/metadata/types/resolvers.js | safe | No malicious patterns detected |
| dist/esm/lib/metadata/types/twitter-types.js | safe | No malicious patterns detected |
| dist/esm/lib/mime-type.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/multi-file-writer.js | safe | No malicious patterns detected; the code is a straightforward utility for parallel file writing with directory creation. |
| dist/esm/lib/needs-experimental-react.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/non-nullable.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/normalize-path.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/oxford-comma-list.js | safe | No malicious patterns detected |
| dist/esm/lib/page-types.js | safe | The file defines a simple enum-like object for page types with no malicious patterns, network activity, or dynamic code execution. |
| dist/esm/lib/pick.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/picocolors.js | safe | No malicious patterns detected |
| dist/esm/lib/pretty-bytes.js | safe | No malicious patterns detected in the pretty-bytes library; it is a benign byte formatting utility. |
| dist/esm/lib/profiles-dir.js | safe | No malicious patterns detected |
| dist/esm/lib/realpath.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/recursive-delete.js | safe | No malicious patterns detected |
| dist/esm/lib/recursive-readdir.js | safe | No malicious patterns detected; the code is a legitimate recursive directory reader with no data exfiltration, credential harvesting, obfuscation, or system command execution. |
| dist/esm/lib/redirect-status.js | safe | The code is a utility module for handling redirect status codes and modifying route regexes, with no malicious patterns or security concerns detected. |
| dist/esm/lib/require-instrumentation-client.js | safe | No malicious patterns detected; the module simply imports a Next.js client instrumentation hook and optionally logs timing in development. |
| dist/esm/lib/resolve-build-paths.js | safe | No malicious patterns detected; the code performs local file path resolution using glob and fs without network, process execution, or credential access. |
| dist/esm/lib/resolve-from.js | safe | This is a legitimate module resolution utility with no malicious patterns detected; the use of Module._resolveFilename is standard internal Node.js API usage for resolving module paths. |
| dist/esm/lib/route-pattern-normalizer.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/scheduler.js | safe | No malicious patterns detected; the file contains only benign scheduling utilities for Next.js runtime environments. |
| dist/esm/lib/semver-noop.js | safe | No malicious patterns detected; the file is a benign semver noop stub with only a hardcoded true return. |
| dist/esm/lib/setup-exception-listeners.js | safe | No malicious patterns detected |
| dist/esm/lib/static-env.js | safe | No malicious patterns detected; the code performs legitimate Next.js environment variable collection and validation without exfiltration, obfuscation, or unauthorized system access. |
| dist/esm/lib/try-to-parse-path.js | safe | The code is a utility for parsing route paths with error handling and normalization, with no malicious patterns detected. |
| dist/esm/lib/turbopack-cache-seed.js | safe | The code appears to be a legitimate Turbopack cache seeding mechanism that operates within the project's dist directory and does not exhibit any malicious patterns. |
| dist/esm/lib/typescript/diagnosticFormatter.js | safe | No malicious patterns detected |
| dist/esm/lib/typescript/getTypeScriptConfiguration.js | safe | No malicious patterns detected; the code performs legitimate TypeScript configuration parsing without data exfiltration, dynamic code execution, or suspicious behavior. |
| dist/esm/lib/typescript/getTypeScriptIntent.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/lib/typescript/loadTsConfig.js | safe | No malicious patterns detected; the code is a legitimate TypeScript config loader that only reads local files and resolves module paths within the project scope. |
| dist/esm/lib/typescript/missingDependencyError.js | safe | No malicious patterns detected; the code only formats and throws a user-friendly error message for missing TypeScript dependencies. |
| dist/esm/lib/typescript/runTypeCheck.js | safe | No malicious patterns detected; the code performs TypeScript type checking and diagnostic filtering without network, credential, or process execution behavior. |
| dist/esm/lib/typescript/runTypeCheckCli.js | safe | Code performs standard TypeScript type-checking via tsc with no malicious patterns detected. |
| dist/esm/lib/typescript/runTypeScriptCli.js | safe | The code is a legitimate TypeScript CLI runner with expected process spawning and filesystem reads, no malicious patterns such as exfiltration, obfuscation, credential theft, or network calls were found. |
| dist/esm/lib/typescript/type-paths.js | safe | No malicious patterns detected |
| dist/esm/lib/typescript/writeAppTypeDeclarations.js | safe | The file only generates and writes a TypeScript declaration file within the project directory using standard path and filesystem APIs, with no malicious patterns detected. |
| dist/esm/lib/typescript/writeConfigurationDefaults.js | safe | The code performs legitimate TypeScript configuration file reads/writes for Next.js project setup; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation were detected. |
| dist/esm/lib/url.js | safe | No malicious patterns detected; the code only performs standard URL parsing and query string manipulation with no data exfiltration, dynamic execution, or other security concerns. |
| dist/esm/lib/verify-root-layout.js | safe | No malicious patterns detected; the code is a standard Next.js utility for creating a root layout file. |
| dist/esm/lib/wait.js | safe | No malicious patterns detected; the file only provides a simple promise-based sleep utility. |
| dist/esm/lib/with-promise-cache.js | safe | No malicious patterns detected |
| dist/esm/lib/worker.js | safe | This is legitimate Next.js build worker management code with no malicious patterns detected; it uses standard child process spawning for build workers, propagates environment variables for worker configuration, and includes no data exfiltration, credential harvesting, obfuscation, or backdoor mechanisms. |
| dist/esm/next-devtools/server/dev-indicator-middleware.js | safe | No malicious patterns detected; the middleware only toggles a local dev-indicator state via an internal endpoint without external communication, credential access, or code execution. |
| dist/esm/next-devtools/server/font/get-dev-overlay-font-middleware.js | safe | This Next.js dev overlay font middleware is a static asset server for bundled font files with strict allowlist validation, path traversal protection, and no malicious patterns. |
| dist/esm/next-devtools/server/get-next-error-feedback-middleware.js | safe | No malicious patterns detected; the code is a standard Next.js middleware for collecting error feedback telemetry. |
| dist/esm/next-devtools/server/middleware-response.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/server/shared.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/shared/console-error.js | safe | No malicious patterns detected; the code only creates and tags Error objects for Next.js console error identification. |
| dist/esm/next-devtools/shared/deepmerge.js | safe | The deepMerge function is a standard recursive object-merge utility with no malicious patterns, network calls, dynamic code execution, or filesystem access. |
| dist/esm/next-devtools/shared/devtools-config-schema.js | safe | No malicious patterns detected; the file only defines a Zod validation schema for devtools configuration. |
| dist/esm/next-devtools/shared/forward-logs-shared.js | safe | No malicious patterns detected; the code only patches console methods and tags server-side errors for Next.js devtools log forwarding. |
| dist/esm/next-devtools/shared/hydration-error.js | safe | The file contains only an empty export statement and a source map reference, with no executable or suspicious code. |
| dist/esm/next-devtools/shared/react-18-hydration-error.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/shared/react-19-hydration-error.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/shared/request-insights.js | safe | The file only re-exports two utility functions from a shared module with no executable code, network calls, or other malicious patterns. |
| dist/esm/next-devtools/shared/stack-frame.js | safe | The code is a legitimate Next.js devtools utility for resolving stack frames, with only a same-origin fetch to the framework's own endpoint and no malicious patterns detected. |
| dist/esm/next-devtools/shared/types.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/shared/version-staleness.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/next-devtools/shared/webpack-module-path.js | safe | No malicious patterns detected; the code only performs regex-based string normalization for webpack internal resource paths. |
| dist/esm/next-devtools/userspace/app/app-dev-overlay-error-boundary.js | safe | No malicious patterns detected; the code is a standard React error boundary for Next.js development overlay with expected dependencies and no exfiltration, credential harvesting, or code execution. |
| dist/esm/next-devtools/userspace/app/app-dev-overlay-setup.js | safe | No malicious patterns detected; the file only initializes error handling and debug log forwarding for a Next.js dev overlay. |
| dist/esm/next-devtools/userspace/app/client-entry.js | safe | This is a simple React component that renders an error boundary for Next.js dev overlay; no malicious patterns detected. |
| dist/esm/next-devtools/userspace/app/errors/index.js | safe | No malicious patterns detected; the file is a simple ES module re-export barrel with no executable logic or external data flow. |
| dist/esm/next-devtools/userspace/app/errors/intercept-console-error.js | safe | No malicious patterns detected; the code is a legitimate Next.js console.error patch for error handling. |
| dist/esm/next-devtools/userspace/app/errors/replay-ssr-only-errors.js | safe | No malicious patterns detected; the code is a legitimate Next.js devtools error replay module that reads SSR error data from the DOM and passes it to an internal error handler. |
| dist/esm/next-devtools/userspace/app/errors/stitched-error.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/userspace/app/errors/use-error-handler.js | safe | No malicious patterns detected; the file contains standard Next.js devtools error handling with no exfiltration, obfuscation, or process execution. |
| dist/esm/next-devtools/userspace/app/forward-logs-utils.js | safe | No malicious patterns detected; the code is a straightforward log serialization utility using safe-stable-stringify with depth/breadth limits and no network, filesystem, process, or dynamic execution behaviors. |
| dist/esm/next-devtools/userspace/app/segment-explorer-node.js | safe | No malicious patterns detected; the file is legitimate Next.js internal devtools code with no exfiltration, credential harvesting, obfuscation, or suspicious execution. |
| dist/esm/next-devtools/userspace/app/terminal-logging-config.js | safe | No malicious patterns detected; the code only reads and parses a framework-specific debug environment variable with a safe fallback. |
| dist/esm/next-devtools/userspace/pages/hydration-error-state.js | safe | No malicious patterns detected |
| dist/esm/next-devtools/userspace/pages/pages-dev-overlay-error-boundary.js | safe | This is a standard React error boundary component for Next.js dev tools with no malicious patterns, network calls, dynamic execution, or filesystem/process access. |
| dist/esm/next-devtools/userspace/use-app-dev-rendering-indicator.js | safe | No malicious patterns detected; the file only uses React hooks and a Next.js devtools dispatcher for rendering indicators. |
| dist/esm/pages/_app.js | safe | No malicious patterns detected |
| dist/esm/pages/_document.js | safe | This is Vercel Next.js's legitimate _document.js runtime file with no malicious patterns; uses of dangerouslySetInnerHTML are for standard Next.js SSR script injection with proper JSON escaping and nonce support. |
| dist/esm/pages/_error.js | safe | This is a standard Next.js built-in error page component with no malicious patterns; the only flagged constructs (server-side dynamic require and static CSS injection) are legitimate framework usage. |
| dist/esm/server/ReactDOMServerPages.js | safe | No malicious patterns detected; the code is a standard React DOM server module loader with legitimate error handling. |
| dist/esm/server/accept-header.js | safe | No malicious patterns detected |
| dist/esm/server/after/after-context.js | safe | No malicious patterns detected in this Next.js after-context module; it implements request lifecycle task queuing and error reporting without any data exfiltration, credential harvesting, obfuscation, or unauthorized process/file operations. |
| dist/esm/server/after/after.js | safe | No malicious patterns detected; the file is a legitimate Next.js after() utility that schedules callbacks using internal async storage, with no exfiltration, credential access, obfuscation, or process execution. |
| dist/esm/server/after/awaiter.js | safe | No malicious patterns detected; the code is a standard promise-gathering utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/server/after/builtin-request-context.js | safe | No malicious patterns detected |
| dist/esm/server/after/index.js | safe | No malicious patterns detected |
| dist/esm/server/after/run-with-after.js | safe | No malicious patterns detected; the file contains a straightforward AfterRunner class for managing lifecycle callbacks with no network, filesystem, or process activity. |
| dist/esm/server/api-utils/index.js | safe | No malicious patterns detected; the code is standard Next.js API route utility code with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| dist/esm/server/api-utils/node/parse-body.js | safe | No malicious patterns detected; the file is a standard Next.js API body parser with no exfiltration, credential harvesting, obfuscation, or suspicious process/network activity. |
| dist/esm/server/api-utils/web.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/action-async-storage-instance.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/action-async-storage.external.js | safe | No malicious patterns detected; the file only re-exports an async storage instance from another internal module. |
| dist/esm/server/app-render/after-task-async-storage-instance.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/after-task-async-storage.external.js | safe | This file only re-exports an AsyncLocalStorage instance from a sibling module with no executable logic, I/O, or malicious patterns. |
| dist/esm/server/app-render/app-render-prerender-utils.js | safe | No malicious patterns detected; the file is legitimate Next.js server-side rendering utility code for handling React Server Component streams with no network, filesystem, process, or credential access. |
| dist/esm/server/app-render/async-local-storage.js | safe | No malicious patterns detected; the code is a legitimate Next.js polyfill for AsyncLocalStorage with no external communication, credential access, dynamic execution, or install-time behavior. |
| dist/esm/server/app-render/blocking-route-messages.js | safe | This file contains only static error message factory functions for Next.js prerendering diagnostics with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/server/app-render/cache-signal.js | safe | No malicious patterns detected; this is a legitimate concurrency utility for tracking pending cache reads in Next.js. |
| dist/esm/server/app-render/collect-segment-data.js | safe | No malicious patterns detected; the code is legitimate Next.js internal segment data collection logic with no exfiltration, credential access, obfuscation, or suspicious execution patterns. |
| dist/esm/server/app-render/console-async-storage-instance.js | safe | The file simply creates and exports an AsyncLocalStorage instance with no malicious patterns or suspicious behavior. |
| dist/esm/server/app-render/console-async-storage.external.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/create-component-styles-and-scripts.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/create-component-tree.js | safe | No malicious patterns detected; the file is legitimate Next.js internal server rendering logic with no data exfiltration, credential harvesting, obfuscation, network abuse, or shell execution. |
| dist/esm/server/app-render/create-error-handler.js | safe | No malicious patterns detected; the code is a legitimate Next.js error-handling module with standard imports, error digesting, and telemetry, and contains no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/server/app-render/create-flight-router-state-from-loader-tree.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal module that recursively builds flight router state from a loader tree without network, filesystem, process, or dynamic code execution concerns. |
| dist/esm/server/app-render/csrf-protection.js | safe | No malicious patterns detected; the code implements CSRF origin validation with wildcard domain matching and contains no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/server/app-render/debug-channel-server.node.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/debug-channel-server.web.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/dev-validation-error-delivery.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal module for serializing validation errors for the dev overlay using an in-process render stream and source-map filtering. |
| dist/esm/server/app-render/dev-validation-events.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/dev-validation-scheduler.js | safe | No malicious patterns detected; the code is a development-time validation scheduler with no network, filesystem, process, or credential access. |
| dist/esm/server/app-render/dev-validation-worker-globals.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/dev-validation-worker-snapshot.js | safe | No malicious patterns detected; the code only builds a serializable snapshot for a dev validation worker using standard async data collection and object serialization. |
| dist/esm/server/app-render/dynamic-access-async-storage-instance.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/dynamic-access-async-storage.external.js | safe | No malicious patterns detected; the file only re-exports an AsyncLocalStorage instance with a Turbopack transition annotation. |
| dist/esm/server/app-render/dynamic-rendering.js | safe | The file is a legitimate portion of Next.js's server-side dynamic rendering module with no evidence of data exfiltration, credential harvesting, obfuscated payloads, shell execution, or malicious lifecycle behavior. |
| dist/esm/server/app-render/encryption-utils.js | safe | No malicious patterns detected; the file is a legitimate Next.js encryption utility for Server Actions. |
| dist/esm/server/app-render/encryption.js | safe | This is legitimate Next.js Server Actions encryption code with no malicious patterns; encryption/decryption uses standard Web Crypto APIs, no external network calls, no credential harvesting, no obfuscation, and no shell/process execution. |
| dist/esm/server/app-render/flight-render-result.js | safe | No malicious patterns detected; the file is a simple class extending RenderResult to set the RSC content-type header. |
| dist/esm/server/app-render/get-asset-query-string.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/get-css-inlined-link-tags.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/get-layer-assets.js | safe | No malicious patterns detected; the code appears to be legitimate Next.js server-rendering logic for managing CSS, JavaScript, and font assets. |
| dist/esm/server/app-render/get-preloadable-fonts.js | safe | No malicious patterns detected; the code is a pure font preloading utility with no I/O, network, or dynamic execution. |
| dist/esm/server/app-render/get-script-nonce-from-header.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/get-short-dynamic-param-type.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/has-loading-component-in-tree.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/instant-validation/boundary-constants.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/instant-validation/boundary-impl.js | safe | No malicious patterns detected; this is a legitimate Next.js internal instant validation boundary module with no data exfiltration, credential harvesting, dynamic code execution, or network/file system abuse. |
| dist/esm/server/app-render/instant-validation/boundary-tracking.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/instant-validation/instant-config.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal module that traverses a route loader tree to evaluate 'instant' validation configuration. |
| dist/esm/server/app-render/instant-validation/instant-samples.js | safe | No malicious patterns detected; the code implements framework-internal validation sample tracking with proxies and error handling, with no network exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/esm/server/app-render/instant-validation/instant-validation-error.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/instant-validation/instant-validation.js | safe | No malicious patterns detected; the file is legitimate Next.js internal instant validation logic with only development-gated conditional requires. |
| dist/esm/server/app-render/instant-validation/stream-utils.js | safe | No malicious patterns detected; the code only creates Node.js Readable streams for internal React rendering with no external network, filesystem, or process manipulation. |
| dist/esm/server/app-render/interop-default.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/make-get-server-inserted-html.js | safe | No malicious patterns detected; the file appears to be legitimate Next.js internal server-side rendering code with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/server/app-render/manifests-singleton.js | safe | This is legitimate Next.js framework code for managing server/client reference manifests and server actions, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/esm/server/app-render/metadata-insertion/create-server-inserted-metadata.js | safe | This file safely constructs a nonce-protected inline script to reinsert icon links into <head>; no malicious patterns were detected. |
| dist/esm/server/app-render/module-loading/instrument-module-getter.js | safe | No malicious patterns detected; the code is a legitimate Next.js instrumentation wrapper for tracking pending module imports, with no data exfiltration, credential harvesting, obfuscation, dynamic code execution, or suspicious network/process activity. |
| dist/esm/server/app-render/module-loading/track-dynamic-import.js | safe | No malicious patterns detected; the file implements legitimate dynamic import tracking for Next.js caching. |
| dist/esm/server/app-render/module-loading/track-module-loading.external.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/module-loading/track-module-loading.instance.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/parse-and-validate-flight-router-state.js | safe | The code parses and validates a router state header with size limits and schema validation, containing no malicious patterns such as data exfiltration, obfuscated execution, or unauthorized system access. |
| dist/esm/server/app-render/postponed-state.js | safe | The file is a standard Next.js server rendering module for serializing and parsing postponed render state; it contains no network, filesystem, process, credential, obfuscation, or dynamic execution patterns. |
| dist/esm/server/app-render/prospective-render-utils.js | safe | No malicious patterns detected; the code only performs error logging and message formatting for Next.js prospective render debugging. |
| dist/esm/server/app-render/react-large-shell-error.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/react-server.node.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/render-css-resource.js | safe | No malicious patterns detected; the code is a legitimate Next.js internal utility for rendering CSS resources. |
| dist/esm/server/app-render/required-scripts.js | safe | No malicious patterns detected; the code only constructs script URLs and integrity attributes for Next.js asset loading. |
| dist/esm/server/app-render/rsc/postpone.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/rsc/preloads.js | safe | No malicious patterns detected; the code only wraps ReactDOM preload/preconnect APIs for RSC rendering helpers. |
| dist/esm/server/app-render/rsc/taint.js | safe | No malicious patterns detected; the file only exports React's experimental taint APIs gated by an environment flag. |
| dist/esm/server/app-render/segment-explorer-path.js | safe | No malicious patterns detected; the file only performs local path normalization and string manipulation for Next.js segment explorer functionality. |
| dist/esm/server/app-render/server-inserted-html.js | safe | No malicious patterns detected; the code is a standard React server-side HTML insertion utility with no exfiltration, obfuscation, or dynamic execution. |
| dist/esm/server/app-render/staged-rendering.js | safe | No malicious patterns detected; the code implements a staged rendering controller with no network, filesystem, process execution, obfuscation, or credential access. |
| dist/esm/server/app-render/stale-time.js | safe | No malicious patterns detected; the code is a benign internal utility for tracking stale-time values in React Server Components, with no network, filesystem, process, or dynamic-execution activity. |
| dist/esm/server/app-render/stream-ops.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/stream-ops.node.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/stream-ops.web.js | safe | No malicious patterns detected; this is legitimate Next.js internal web stream handling code for React server rendering. |
| dist/esm/server/app-render/strip-flight-headers.js | safe | No malicious patterns detected |
| dist/esm/server/app-render/sync-io-messages.js | safe | No malicious patterns detected; the file only constructs Next.js prerender error messages with hardcoded documentation URLs and performs no network, filesystem, process, or dynamic code operations. |
| dist/esm/server/app-render/types.js | safe | This file only defines schema validation structures using the superstruct library and contains no malicious patterns or security concerns. |
| dist/esm/server/app-render/use-flight-response.js | safe | The code is part of a React Server Component rendering utility and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized process execution. |
| dist/esm/server/app-render/vary-params.js | safe | No malicious patterns detected; the code implements vary-params tracking for React Server Components using standard language features (classes, Proxy, AsyncIterator, AsyncLocalStorage) without network, filesystem, process, credential, or eval activity. |
| dist/esm/server/app-render/wait-for-response.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/server/app-render/walk-tree-with-flight-router-state.js | safe | No malicious patterns detected; this is standard Next.js internal server-side routing code with no exfiltration, credential harvesting, obfuscation, or process/network abuse. |
| dist/esm/server/app-render/work-async-storage-instance.js | safe | No malicious patterns detected |
Scanned versions of next
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 16.3.8 | Needs review | 3305 | Oct 6, 2026 |
Frequently asked questions
Is next safe to use?
No confirmed malware was found in next@16.3.8, but the review flagged 6 high, 245 medium, 685 low severity findings for risky patterns worth checking before you rely on it.
Does next contain malware?
No malware was identified in next@16.3.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was next checked?
Togoder Security downloaded the published npm package and had an AI model read its 3305 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan next together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in next@16.3.8, cost nothing.