Togoder security

npm package security report

next npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 16.3.8 Files reviewed 3305 Size 56.5 MB Scanned

Summary

Togoder Security scanned the npm package next@16.3.8 on Oct 6, 2026. An AI review of 3305 source files produced 6 high, 245 medium, 685 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
6
high
245
medium
685
low

Findings 936

high

Remote binary download without integrity verification

NPS-140248425475

The code downloads an executable binary (mkcert) from GitHub releases and writes it to disk without verifying a checksum or signature. If the download is compromised via MITM or a compromised release, arbitrary code could be executed.

dist/esm/lib/mkcert.js:32
high

Suspicious process execution

NPS-64407DC0225B

The code uses execSync to run the downloaded binary with shell interpolation of dynamically constructed paths and hostnames. This could allow command injection if host or certDir contain malicious values.

dist/esm/lib/mkcert.js:92
high

Node.js Inspector Exposure

NPS-C0307DEC67A1

The middleware endpoint /__nextjs_attach-nodejs-inspector opens the Node.js inspector on the process debug port (process.debugPort) if not already listening, then fetches and returns the DevTools frontend URL from the inspector's HTTP endpoint. This grants anyone who can reach this route full debugging access to the Node.js process, including the ability to execute arbitrary code in the runtime via the inspector protocol. While this is intended for Next.js development mode, exposing it in a production or non-loopback context is a serious security risk.

dist/esm/next-devtools/server/attach-nodejs-debugger-middleware.js:12
high

Remote Code Execution Surface via Debugger

NPS-C2E62E9493B8

By exposing the Node.js inspector endpoint, an attacker with network access to this route could connect to the inspector WebSocket, evaluate arbitrary JavaScript, read environment variables, files, and credentials, and spawn processes. This effectively provides a backdoor-like capability if the endpoint is reachable outside trusted development environments.

dist/esm/next-devtools/server/attach-nodejs-debugger-middleware.js:12
high

Local debugger/DevTools middleware exposure

NPS-E847F970F741

Middleware getAttachNodejsDebuggerMiddleware and devToolsConfigMiddleware expose Node.js debugger attach functionality and devtools configuration over the dev server. This is a powerful capability that, if the dev server is reachable by untrusted parties, could allow attaching a Node debugger or otherwise inspecting/interfering with the process.

dist/esm/server/dev/hot-reloader-webpack.js:1148
high

Path traversal / arbitrary file read

NPS-2858B1421EE5

The asset name is taken directly from the 'blob:' input and resolved against options.distDir without validating that the final path stays inside distDir. A crafted blob URL such as 'blob:../../../../etc/passwd' (when options.assets is not provided) would resolve outside the intended distribution directory, allowing arbitrary readable files to be served via the Response stream.

dist/server/web/sandbox/fetch-inline-assets.js:24
medium

Dynamic code execution

NPS-EA1E608CBEBA

The requireFromString function compiles and executes arbitrary JavaScript code provided as a string using module._compile. This is a dynamic code execution capability that could be abused if the input is attacker-controlled.

dist/build/next-config-ts/require-hook.js:87
medium

Dynamic code execution via require hook

NPS-B95BD7F20964

The code compiles TypeScript config using SWC and then dynamically loads the resulting CommonJS code via requireFromString, which executes the transpiled module in the current process. While this is intentional behavior for loading Next.js config, it represents dynamic code execution where arbitrary code from next.config.ts is run at build time.

dist/build/next-config-ts/transpile-config.js:124
medium

Dynamic require of manifest file

NPS-7E0B6A9A45A5

The readEntryJSFiles function constructs a file path from pagePath and requires it at runtime. While this is intended to load Next.js RSC manifests, the pattern of requiring a file whose path is derived from route/manifest data could be exploited if an attacker can influence pagePath to load arbitrary JavaScript files, leading to code execution. The save/restore of global.__RSC_MANIFEST is also a fragile global mutation pattern.

dist/build/route-bundle-stats.js:82
medium

Environment variable input parsing

NPS-1F042C2DCC6B

The code reads process.env.NEXT_PRIVATE_PAGE_PATHS and process.env.NEXT_PRIVATE_APP_PATHS and parses them with JSON.parse. These environment variables can override route path discovery. While this appears to be a legitimate testing hook in Next.js, it represents an environment-controlled code path that can influence build output. If an attacker can set these environment variables, they can inject arbitrary paths into the build configuration.

dist/build/route-discovery.js
medium

Dynamic module loading with external/environment-controlled paths

NPS-649BA217809B

The code resolves and requires modules based on environment variables such as __INTERNAL_CUSTOM_TURBOPACK_BINDINGS, NEXT_TEST_NATIVE_DIR, NEXT_TEST_WASM_DIR, and NEXT_TEST_NATIVE_IGNORE_LOCAL_INSTALL. If an attacker can control these env vars, they could load arbitrary native binaries or JS modules into the process.

dist/build/swc/index.js
medium

Native binary download fallback

NPS-B015E9E68C04

loadBindings/tryLoadNativeWithFallback download native SWC binaries at runtime via download-swc when local bindings are missing. This introduces a network-dependent, runtime-fetched executable code path which, if the download source or integrity is compromised, could execute untrusted native code.

dist/build/swc/index.js
medium

Runtime execution of native .node binaries

NPS-07642AF15C7B

The module loads and executes platform-specific native Node addons (@next/swc-* / next-swc.*.node). Native binaries can contain arbitrary code; trust depends entirely on the upstream package integrity from the registry.

dist/build/swc/index.js
medium

Dynamic worker thread creation from external input

NPS-044DEF1263C8

The code spawns Node.js Worker threads using a filename provided via the creation.options.filename parameter. This filename is passed directly to new Worker(...) without validation. While this is a legitimate pattern for Turbopack's loader worker pool (executing loader files), the filename could originate from build configuration or external input, allowing arbitrary JavaScript files to be executed in a worker thread context if an attacker can control the filename. This constitutes dynamic module loading/execution.

dist/build/swc/loaderWorkerPool.js:22
medium

Dynamic import with placeholder

NPS-94BCE2D43004

The code uses import('MODULE') with a placeholder 'MODULE' that is later replaced during build. This dynamic import could load arbitrary external modules depending on the build configuration, potentially fetching malicious code from untrusted sources if the placeholder is not properly controlled.

dist/build/templates/edge-wrapper.js:9
medium

Global prototype patching / network interception

NPS-AC9E8E26261E

The code permanently monkey-patches net.Socket.prototype.connect to intercept all outgoing TCP connections and record host/port into an external array. While it restores the original method when the returned cleanup function is invoked, until then it silently observes all socket connections made anywhere in the process. This is a legitimate access-trace mechanism for Turborepo, but the same pattern is commonly used to intercept and harvest connection targets (potentially including internal service addresses, databases, or credential-bearing endpoints).

dist/build/turborepo-access-trace/tcp.js:17
medium

Data collection at runtime

NPS-2166B5ACCC74

Every TCP connect call is inspected and the destination host and port are pushed into the caller-supplied 'addresses' array. The destination of that array is controlled by the caller; if used maliciously, this could accumulate internal network topology information. In this package it appears intended for tracing/telemetry of accessed network resources.

dist/build/turborepo-access-trace/tcp.js:24
medium

Dynamic module loading based on external configuration

NPS-D7D918118B4B

The loadPlugin function resolves and requires PostCSS plugin modules using require.resolve and require() with plugin names provided from external PostCSS configuration files found in the project directory. While this is the intended behavior of PostCSS plugin loading, it means that a malicious or compromised PostCSS configuration file can cause arbitrary modules installed in the project to be loaded and executed at build time. This is a supply-chain/config-trust concern rather than a direct malicious pattern in this file.

dist/build/webpack/config/blocks/css/plugins.js
medium

Improper output encoding

NPS-F0A2CB05D9EC

resolveRobots and resolveSitemap build output (robots.txt, sitemap XML, manifest JSON) by directly interpolating user/route-supplied values (userAgent, allow, disallow, crawlDelay, host, sitemap URLs, item.url, alternates languages/hrefs, image locs, and all video fields such as title, description, content_loc, player_loc, restriction, platform, uploader info, etc.) without XML/HTML escaping or newline sanitization. If route metadata is attacker-influenced, this can lead to injection into generated robots.txt (e.g. injecting additional 'Disallow'/'Sitemap' directives via newlines) and malformed or injected XML in sitemap.xml (e.g. breaking out of element content or attributes such as the uploader info attribute or restriction relationship attribute). While this is not a remote code execution or data exfiltration flaw, it is a genuine output-encoding/security issue in a build-time metadata generator.

dist/build/webpack/loaders/metadata/resolve-route-data.js:35
medium

Dynamic module import with computed path

NPS-B98A657918EB

The generated code includes a dynamic import statement for an incremental cache handler: import incrementalCacheHandler from ${stringifiedCacheHandlerPath}. The path is derived from the cacheHandler loader option. If an attacker can control this option, they could cause the build to import an arbitrary module, potentially executing malicious code.

dist/build/webpack/loaders/next-edge-function-loader.js:24
medium

Dynamic code execution via generated string

NPS-5E0CA5010645

The loader returns a JavaScript source string that is compiled/executed by webpack. The string is built using dynamic values such as page, absolutePagePath, cacheHandler, middlewareConfig, and rootDir derived from loader options and the build context. While this is typical for webpack loaders, if these values are attacker-controlled (e.g., via a malicious config or compromised dependency), it could lead to arbitrary code execution in the build process.

dist/build/webpack/loaders/next-edge-function-loader.js:27
medium

Dynamic module loading with computed path

NPS-6127AD860964

The code performs require(fontLoaderPath).default where fontLoaderPath is obtained from loader options via this.getOptions(). If the webpack configuration or any upstream source can influence fontLoaderPath, this allows arbitrary module loading and potential code execution during the build process. While this is a legitimate Next.js feature, it represents a dynamic require that should be validated/restricted.

dist/build/webpack/loaders/next-font-loader/index.js:117
medium

Build-time code execution

NPS-9FF00E02A6BC

This is a webpack loader that executes at build time and dynamically loads/executes a font loader module specified by fontLoaderPath. Build-time loaders are a known supply-chain risk vector as they run with developer privileges. The dynamic require is the primary concern, though it appears to be an intentional part of Next.js's font system.

dist/build/webpack/loaders/next-font-loader/index.js:117
medium

Dynamic module loading with computed specifiers

NPS-9FDB7BB34D92

The loader reads a 'modules' array from webpack options (potentially attacker-controlled if the build config is compromised or if a dependency injects options) and generates require() calls with dynamically constructed paths. Module specifiers are passed through webpack's resolver against rootContext and then embedded into generated code via JSON.stringify. While JSON.stringify mitigates direct code injection, a malicious config or compromised build chain could force loading of arbitrary modules, including sensitive files if a path resolutions allows it. This is expected behavior for a Next.js internal instrumentation loader, but the dynamic require generation is a notable pattern worth flagging in third-party contexts.

dist/build/webpack/loaders/next-instrumentation-client-loader.js:23
medium

Unvalidated request body JSON parsing

NPS-372C642EEA69

The HTTP handler reads the request body into a string and passes it through JSON.parse(body) before handing it to the MCP transport. There is no length limit on the body, no Content-Type validation, and no streaming limit, so a client can send an arbitrarily large payload to cause memory exhaustion (DoS). The parsed JSON is also accepted without checking the Content-Type or method restrictions expected by the MCP spec.

dist/cli/internal/turbo-trace-server.js:232
medium

HTTP server bound to loopback without authentication

NPS-1E8FA9BD5A97

The MCP HTTP server listens on 127.0.0.1 (loopback only), which is good, but it exposes an unauthenticated tool (query_spans) that returns trace data. Any local process or a DNS-rebinding attack from a browser page can reach 127.0.0.1 and invoke the MCP endpoint. No Origin/Host header validation or authentication is performed, allowing cross-site requests to interact with the local trace server.

dist/cli/internal/turbo-trace-server.js:260
medium

Data exfiltration / file upload to external server

NPS-7F2F7A10C2F7

The code reads local CPU profile (.cpuprofile) and Turbopack trace files and uploads their contents to an external endpoint (nextjs.org/api/upload-trace, overridable via __NEXT_UPLOAD_TRACE_URL_OVERRIDE). While this appears to be legitimate telemetry for the Next.js team, it constitutes uploading potentially sensitive local build data to a remote server.

dist/cli/internal/upload-trace.js
medium

Process spawning and dynamic dependency installation

NPS-E1473ABDEB9D

The code dynamically installs missing dependencies via installDependencies and then spawns the Playwright CLI binary using cross-spawn with shell: false. While this is part of the legitimate Next.js experimental test workflow, the dynamic installation and execution of package binaries could be abused if an attacker controls package resolution or the project environment.

dist/cli/next-test.js:108
medium

Spawning processes or shell commands

NPS-23306D2E8EAF

The code uses child_process.spawn to execute a command derived from getNpxCommand(baseDir).split(' '). If getNpxCommand returns a string influenced by untrusted input (e.g., project directory path or environment), it could allow command injection or execution of arbitrary binaries. The spawn call also passes options.revision directly as an argument, which, while not shell-interpreted, could be manipulated if revision is attacker-controlled.

dist/cli/next-upgrade.js:21
medium

dangerouslySetInnerHTML usage

NPS-616CB4986FA9

The component uses dangerouslySetInnerHTML to inject document.documentElement.innerHTML directly into the DOM. While it caches the page's own HTML on mount, this pattern can be exploited if the cached HTML contains attacker-controlled content (e.g., injected via XSS or a compromised dependency), effectively re-rendering arbitrary scripts/markup without sanitization.

dist/client/components/errors/graceful-degrade-boundary.js:86
medium

Global fetch override

NPS-9419F3356D1F

The module installs a global window.fetch override during lock scopes. While intended for a testing API and gated by environment checks, monkey-patching fetch could interfere with other scripts or be abused if the lock state is manipulated. It blocks user-initiated fetches until lock release, which is a behavior change outside normal app code.

dist/client/components/segment-cache/navigation-testing-lock.js
medium

Cookie manipulation

NPS-73819C03677D

The code reads and writes the NEXT_INSTANT_TEST_COOKIE via both document.cookie and cookieStore, including a defensive clear that modifies cookies outside the component's immediate scope. This could affect cookie state for the whole origin and potentially leak lock state or resurrect stale cookies if race conditions are exploited.

dist/client/components/segment-cache/navigation-testing-lock.js
medium

Suspicious network request

NPS-3EE231CEEC6F

The code creates a WebSocket connection using a URL derived from options.assetPrefix and options.path. While this is expected behavior for a Next.js hot module replacement (HMR) client, it could be exploited if the assetPrefix is controlled by an attacker, leading to connection to a malicious server.

dist/client/dev/hot-reloader/pages/websocket.js:88
medium

Dynamic URL construction

NPS-8D3654B1ED37

The WebSocket URL is constructed using getSocketUrl(options.assetPrefix) and options.path. If these values are not properly sanitized, an attacker could potentially redirect the WebSocket connection to an arbitrary server.

dist/client/dev/hot-reloader/pages/websocket.js:88
medium

Dynamic HTML injection

NPS-07F24DFDD949

The function reactElementToDOM uses dangerouslySetInnerHTML to assign raw HTML to el.innerHTML. If untrusted input reaches this path, it could lead to DOM-based XSS. This is a known React/Next.js head manager pattern, but it is still a dangerous capability if the data source is compromised.

dist/client/head-manager.js:22
medium

Use of innerHTML

NPS-4B19CCAB978A

Direct assignment to innerHTML can execute inline scripts and event handlers when combined with attacker-controlled props. This is a common vector for client-side code injection.

dist/client/head-manager.js:22
medium

Third-party registry verification needed

NPS-CE3801CE01BE

File uses '@swc/helpers', 'react', 'react-dom' and Next.js internal shared modules. Confirm the package name, publisher, and integrity hash match the official Next.js distribution; typosquatted republishes of this file would be highly dangerous due to arbitrary script injection capability.

dist/client/script.js
medium

dangerouslySetInnerHTML usage

NPS-FB5058EE0A6C

The component supports a 'dangerouslySetInnerHTML' prop that directly assigns HTML content to script element innerHTML without sanitization, enabling arbitrary inline script execution if untrusted input reaches this prop.

dist/client/script.js:96
medium

Dynamic script injection

NPS-1AA8077C572F

The loadScript function dynamically creates <script> elements and sets their src from the 'src' prop, then appends them to document.body. While this is the intended behavior of Next.js's Script component, it allows arbitrary remote script loading if a malicious prop value is passed, which could enable supply-chain or XSS attacks in consuming applications.

dist/client/script.js:105
medium

Dynamic code execution via self.__next_s

NPS-25B36155EF89

In the appDir path, the component emits inline scripts invoking '(self.__next_s=self.__next_s||[]).push(...)' with JSON-encoded props. This pattern is internal to Next.js but executes dynamic payloads at runtime and should be treated as elevated risk surface if the module is not the official Next.js package.

dist/client/script.js:318
medium

Global runtime patching

NPS-038C9C80E848

The module patches core Node.js globals including globalThis.Request, globalThis.Response, globalThis.Headers, net.Socket.prototype.connect, https.Agent.prototype.addRequest, and node:http ClientRequest/get/request. This modifies core HTTP behavior process-wide at import time via the applyPatch mechanism, which is a powerful interception mechanism that could be used for man-in-the-middle modification of all outgoing requests.

dist/compiled/@mswjs/interceptors/ClientRequest/index.js:1
medium

Dynamic module loading with environment variable

NPS-A4586B4E2731

The function uses require(process.env.NEXT_FONT_GOOGLE_MOCKED_RESPONSES) to load a module based on an environment variable. While this is intended for testing (mocked responses), if an attacker can control this environment variable, they could load arbitrary code. This is a potential security risk in environments where environment variables are not fully trusted or can be influenced by external input.

dist/compiled/@next/font/dist/google/fetch-css-from-google-fonts.js:17
medium

Filesystem read based on user-controlled path

NPS-AE2C2DFBA76B

When the NEXT_FONT_GOOGLE_MOCKED_RESPONSES environment variable is set, the function reads arbitrary files from disk via fs.readFileSync(url) when url starts with '/'. If an attacker can influence the 'url' value (e.g., through a compromised font manifest or build configuration) and the environment variable is set, this could allow reading sensitive files. However, this path is a documented mocking/testing feature and requires environmental precondition, so severity is moderate.

dist/compiled/@next/font/dist/google/fetch-font-file.js:15
medium

Dynamic module loading

NPS-AC71EFA81CA2

The file dynamically loads './bundle' and calls the function coreLibPluginPass(). While this pattern is common in Babel's build output, the loaded module could contain obfuscated or malicious code. The actual security risk cannot be assessed without inspecting the 'bundle' module it requires.

dist/compiled/babel/core-lib-plugin-pass.js:1
medium

Dynamic module loading

NPS-9E61358ABB29

The file uses require('./bundle') with a relative path and invokes .core() on the imported module. While the path is static and relative, the actual behavior depends entirely on the contents of './bundle', which is not provided for analysis. This pattern is common in Babel but could hide malicious code if the bundle is compromised.

dist/compiled/babel/core.js:1
medium

Dynamic code execution (eval)

NPS-93E39316FFB2

The loadQueries function uses eval('require')(eval('require').resolve(name, {paths:['.', ctx.path]})) to dynamically resolve and load modules from user-controlled config names. While guarded by checkExtend() and dangerousExtend checks, this is still dynamic module loading based on config input and can lead to arbitrary code execution if a malicious package name passes the prefix check (e.g., a malicious 'browserslist-config-*' package installed in node_modules).

dist/compiled/browserslist/index.js
medium

process spawning

NPS-E0AD7E70610F

The module wraps child_process.spawn and spawnSync to execute external commands. While this is the intended purpose of the cross-spawn library, it is a capability that could be misused if the module is compromised or if inputs are attacker-controlled.

dist/compiled/cross-spawn/index.js:1
medium

HTTP header injection risk

NPS-F5E94C24F7E7

The _createHttpHeader function builds raw HTTP header strings from response headers without sanitizing CRLF characters. If an upstream server returns a header value containing \r\n, this could enable HTTP response splitting/header injection in the websocket upgrade path.

dist/compiled/httpxy/index.js
medium

Potential Server-Side Request Forgery (SSRF)

NPS-34AD04B6286C

The proxy implementation forwards requests to arbitrary targets provided via options (target/forward/URL). If target URLs are derived from untrusted input, this can be abused for SSRF against internal services. This is inherent to proxy libraries but requires callers to validate targets.

dist/compiled/httpxy/index.js
medium

Redirect handling strips credentials on cross-host only

NPS-4E3CF1EF19E0

In followRedirects logic, authorization and cookie headers are stripped only when the redirect host differs from the original request's URL object host, but the comparison uses new URL(location, forwardTarget) and compares against 'forwardTarget' host rather than the actual current hop. Under certain redirect chains this comparison may not correctly detect cross-host hops, potentially leaking Authorization/Cookie headers to a different origin.

dist/compiled/httpxy/index.js
medium

Dynamic code execution

NPS-5FE199429AA9

The code uses eval("require")(file) to dynamically load modules. While this is a known pattern in jest-worker for resolving module paths at runtime, eval-based module loading can be exploited if the file variable is attacker-controlled. In this context, file is received from the parent process via IPC, which is normally trusted, but it represents a dynamic code execution path that could be abused if the IPC channel is compromised.

dist/compiled/jest-worker/processChild.js
medium

IPC message handling / dynamic invocation

NPS-E7CAA92EA5CD

The child process listens for messages from the parent and executes functions from dynamically required modules based on message content (execMethod). Method names and arguments are controlled by the parent process. If a malicious or compromised parent process sends crafted messages, arbitrary exported functions from the loaded module could be invoked with arbitrary arguments.

dist/compiled/jest-worker/processChild.js
medium

Dynamic code execution

NPS-0B976F2D2D32

The file uses eval('require')(file) to dynamically load modules specified in messages from the parent process. While this is legitimate jest-worker functionality, the use of eval to obtain require bypasses normal module resolution and could be exploited if the parent process is compromised or if the file path is attacker-controlled.

dist/compiled/jest-worker/threadChild.js
medium

Arbitrary function execution

NPS-F034F7EAF8AD

execFunction applies a function (from the dynamically required module) with user-supplied arguments. The method and args come from parent process messages. If the parent process is malicious or compromised, it could invoke arbitrary exported functions with arbitrary arguments.

dist/compiled/jest-worker/threadChild.js
medium

Dynamic code execution

NPS-FD6FFEA0CDA4

The loader uses eval() to dynamically import ES modules based on a computed URL from loader.path. While this is standard webpack loader-runner behavior for ESM loaders, eval with computed input is a code execution risk if loader.path can be influenced by untrusted input.

dist/compiled/loader-runner/LoaderRunner.js
medium

Dynamic module loading

NPS-803DCE97A301

Uses require(loader.path) to load arbitrary modules from computed paths. This is core functionality for a loader runner, but allows loading any module specified by the loader configuration.

dist/compiled/loader-runner/LoaderRunner.js
medium

Dynamic code execution

NPS-C23E95915FBE

The evalModuleCode function uses Node's Module._compile to evaluate and execute arbitrary JavaScript module code (provided as the 'code' argument) at runtime. While this is an expected part of mini-css-extract-plugin's child compiler behavior, it represents a dynamic code execution primitive that could be abused if the extracted CSS content or module code is attacker-controlled.

dist/compiled/mini-css-extract-plugin/loader.js
medium

module loading hijacking

NPS-8BEA123798FF

The code monkey-patches Module.prototype._compile, intercepting the compilation of every CommonJS module loaded after this package is imported. While the modification is gated on 'use client'/'use server' directives and delegates to the original compile, this is an invasive runtime behavior that hooks into Node's core module system and could affect unexpected files.

dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-node-register.js:15
medium

dynamic code parsing and directive-based branching

NPS-AE7B31C67EC6

Uses acorn-loose to parse arbitrary file contents at require time and makes security-relevant decisions based on string directives in the source. This creates a mechanism where the behavior of any required module can be altered based on its content, which expands the attack surface if the package is ever compromised or if attacker-controlled files are loaded.

dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-node-register.js:19
medium

module loading hijacking

NPS-8BEA123798FF

The code monkey-patches Module.prototype._compile, intercepting the compilation of every CommonJS module loaded after this package is imported. While the modification is gated on 'use client'/'use server' directives and delegates to the original compile, this is an invasive runtime behavior that hooks into Node's core module system and could affect unexpected files.

dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-node-register.js:15
medium

dynamic code parsing and directive-based branching

NPS-AE7B31C67EC6

Uses acorn-loose to parse arbitrary file contents at require time and makes security-relevant decisions based on string directives in the source. This creates a mechanism where the behavior of any required module can be altered based on its content, which expands the attack surface if the package is ever compromised or if attacker-controlled files are loaded.

dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-node-register.js:19
medium

Dynamic code execution

NPS-C1A4D784974A

Uses eval("require").resolve(...) to dynamically load optional Sass implementations. While this is a known pattern in sass-loader, dynamic require resolution can be abused by malicious packages if module resolution is influenced by attacker-controlled paths or environment.

dist/compiled/sass-loader/cjs.js
medium

Unsafe dynamic module loading

NPS-E612BF01462D

The loader accepts a user-provided 'implementation' option and calls require(s) on it if it is a string. This allows loading arbitrary modules based on build configuration, which could be exploited if untrusted configuration is used.

dist/compiled/sass-loader/cjs.js
medium

Dynamic code execution

NPS-3C836CB4C77B

The code uses new Function(""+e) to convert a non-function argument into a function, which can execute arbitrary code if the input is controlled by an attacker.

dist/compiled/setimmediate/setImmediate.js:5
medium

Dynamic code execution

NPS-535773125CD1

The code uses eval() and execScript() to execute arbitrary JavaScript code within iframe contexts. This is inherent to the vm-browserify package's purpose of providing a browser-based VM implementation, but it represents a significant security concern if untrusted code is ever passed to these functions.

dist/compiled/vm-browserify/index.js
medium

Dynamic module loading from external input

NPS-83AF5C23A606

The function resolves and dynamically imports adapterPath from a file URL via pathToFileURL(require.resolve(adapterPath)).href, then invokes adapterMod.onBuildComplete(...). This allows arbitrary code from an adapter module to execute with full build-time privileges. While this is an intentional Next.js adapter mechanism, the adapter path is an external input and the invoked callback receives sensitive build outputs, file paths, environment config, middleware matchers, and prerender tokens.

dist/esm/build/adapter/build-complete.js:70
medium

Sensitive data exposure to third-party adapter

NPS-66953A9A573A

The onBuildComplete callback is passed prerenderManifest.preview.previewModeId as config.bypassToken on prerender outputs (lines ~684 and ~832), and numerous absolute filesystem paths, project directory, repo root, distDir, and full routing/middleware matcher details. A malicious adapter could exfiltrate secrets or use the preview bypass token to access preview-authenticated routes.

dist/esm/build/adapter/build-complete.js:684
medium

Execution of user-provided code

NPS-3FE8E88F8473

The function executes config.compiler.runAfterProductionCompile (a user-provided function from next.config.js) during the production build. This is by design for Next.js, but in a third-party package context it represents arbitrary code execution at build time from configuration, which could be abused if an attacker can influence the configuration.

dist/esm/build/after-production-compile.js:15
medium

Dynamic module loading / require hook

NPS-17EC4BB40AEC

The code overrides Node.js require.extensions for multiple file extensions (.js, .ts, .cts, .mts, .cjs, .mjs) and dynamically transforms and executes code using swc transformSync. This is a powerful hook that can intercept and modify module loading behavior, potentially allowing arbitrary code execution or code injection if swcOptions are attacker-controlled or if the hook is used to load untrusted modules.

dist/esm/build/next-config-ts/require-hook.js:10
medium

Dynamic code execution via _compile

NPS-F8888C959312

The require hook uses mod._compile to execute transformed code. This is a low-level Node.js API that compiles and runs code. Combined with the fallback to readFileSync and transformSync, it can execute arbitrary JavaScript from files on disk. While this is the intended function of a require hook, it represents a risk if the package is compromised or if the hook is misused.

dist/esm/build/next-config-ts/require-hook.js:26
medium

Dynamic code execution / module loading

NPS-14FBDA24F906

The transpileConfig function reads a Next.js config file from disk, transpiles it with SWC, and then executes the resulting code via requireFromString. If an attacker can control or modify nextConfigPath (e.g., via a malicious project configuration or path traversal), this could lead to arbitrary code execution. Additionally, the code dynamically imports the config path using import(pathToFileURL(nextConfigPath).href) when the Node.js native TypeScript loader is enabled, which also executes the file. This is expected behavior for loading user config, but the path is derived from input and not validated to be within a trusted scope.

dist/esm/build/next-config-ts/transpile-config.js
medium

Dynamic import with computed path

NPS-27F1F22E49A8

The use of import(pathToFileURL(nextConfigPath).href) dynamically imports a file based on the nextConfigPath parameter. If this path is influenced by external input, it could load malicious modules. However, in the context of Next.js, this is intended for loading the user's own configuration.

dist/esm/build/next-config-ts/transpile-config.js
medium

Predictable Cryptographic Keys

NPS-920A63D3A8EF

The preview signing and encryption keys are generated using crypto.randomBytes, which is cryptographically secure. However, the keys are stored in a plaintext JSON file (.previewinfo) in the cache directory, which could be accessible to other users or processes on the system, potentially leading to key compromise.

dist/esm/build/preview-key-utils.js:46
medium

Dynamic module loading with computed path

NPS-40085624A8B4

The readEntryJSFiles function constructs a file path from user-influenced inputs (pagePath, appRoute) and calls require() on it. While this is intended to load Next.js RSC manifest files from the dist directory, the dynamic require with a path derived from external data could potentially load unintended modules if pagePath or appRoute contain path traversal sequences. The code does not sanitize or validate these inputs before constructing the path.

dist/esm/build/route-bundle-stats.js:48
medium

Dynamic worker thread creation with computed filename

NPS-0B266DD8B1FD

The code creates a Node.js Worker thread using a filename derived from the creation.options.filename value, which is passed from an external bindings callback. If an attacker can influence this filename (e.g., through a crafted project configuration or module resolution), it could lead to arbitrary code execution in a worker thread. The workerData also includes bindingPath and cwd, potentially exposing environment context to the worker.

dist/esm/build/swc/loaderWorkerPool.js:9
medium

Dynamic import with placeholder

NPS-833349D71E4E

The code uses a dynamic import('MODULE') where MODULE appears to be a build-time placeholder that will be replaced with the actual module path. If not properly controlled, this could allow loading arbitrary modules from untrusted sources. This is a common pattern in bundlers/frameworks (like Next.js edge runtime) but could be exploited if the placeholder is user-controllable.

dist/esm/build/templates/edge-wrapper.js:10
medium

Proxy with dynamic property access

NPS-4BA89598AA9D

The Proxy get trap dynamically accesses mod[name] and returns a function that calls it. If name is attacker-controlled, this could allow invoking arbitrary exports from the imported module. This is inherent to the design but could be a security concern if the imported module exposes dangerous functions.

dist/esm/build/templates/edge-wrapper.js:13
medium

Environment variable access tracking

NPS-021ED7585A75

The code wraps process.env in a Proxy and records every accessed environment variable key into the provided envVars set. While this appears to be for build-time instrumentation (turborepo-access-trace), it globally replaces process.env for the entire process. Any consumer of this function can capture all environment variable names accessed by subsequent code, which could aid reconnaissance for credential harvesting if the tracked set is exfiltrated or misused. No exfiltration or credential file reads are present in this file itself.

dist/esm/build/turborepo-access-trace/env.js:8
medium

Global prototype modification / monkey-patching

NPS-DD283D04DE08

The code permanently overrides net.Socket.prototype.connect, a core Node.js networking primitive. While it only records the destination address/port and then calls the original implementation, this technique can be abused in a supply-chain context to intercept or redirect arbitrary network connections, and it affects all code running in the process. It is a legitimate pattern used by Turborepo for build-time network access tracing, but it is a high-impact behavior that warrants review.

dist/esm/build/turborepo-access-trace/tcp.js:9
medium

Use of require with dynamic path

NPS-F2FFA54981D0

createLazyPostCssPlugin wraps require(pluginPath) and require(pluginPath)(options). The pluginPath is resolved at runtime from external configuration, enabling execution of arbitrary npm packages specified in the PostCSS config. Although this is a legitimate feature of the build system, it represents a code execution vector tied to build-time configuration.

dist/esm/build/webpack/config/blocks/css/plugins.js:47
medium

Dynamic module loading with computed input

NPS-D23531AA3147

The loadPlugin function calls require.resolve(pluginName, { paths: [dir] }) and then require(pluginPath) or require(pluginPath)(options) where pluginName and pluginPath are derived from user-controlled PostCSS configuration. While this is expected behavior for a PostCSS plugin loader, it means arbitrary modules can be loaded and executed based on config file contents. This is a potential supply-chain risk if a malicious postcss.config.js is present in a project.

dist/esm/build/webpack/config/blocks/css/plugins.js:63
medium

Potential SSRF via URL resolution

NPS-55FE3E7D74B0

The plugin resolves URLs found in CSS declarations (via url() and image-set()). It uses options.resolver and options.context to resolve requests, which can lead to network requests if not properly sandboxed. An attacker controlling CSS input could potentially cause the loader to fetch arbitrary URLs, leading to server-side request forgery (SSRF) or information disclosure. However, this is standard behavior for CSS URL handling and not inherently malicious, but it is a security-sensitive operation.

dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-url-parser.js:260
medium

String interpolation into generated code

NPS-FA3096F30A65

The createMetadataExportsCode function interpolates metadata file paths and module import source strings directly into generated JavaScript code using template literals. This is a code generation pattern, and if any interpolated value contained malicious content, it could result in code injection into the generated output. In practice the values are derived from controlled file system enumeration and stringify output, but it represents an injection surface worth noting.

dist/esm/build/webpack/loaders/metadata/discover.js:82
medium

XML Injection / Improper Output Encoding

NPS-AEB737245A53

The resolveSitemap function builds XML output by directly interpolating untrusted input values (item.url, language keys/values, image URLs, video fields such as title, thumbnail_loc, description, content_loc, player_loc, restriction relationship/content, uploader info/content, etc.) without XML-escaping them. If an attacker can control any of these metadata fields (e.g. via route metadata derived from request data), they could inject arbitrary XML elements/attributes into the sitemap, potentially leading to XSS when the sitemap is served/parsed, or to content spoofing and structure corruption of the generated sitemap. Similarly, resolveRobots interpolates rule values directly into robots.txt without sanitization, which could allow header/line injection if values contain newlines.

dist/esm/build/webpack/loaders/metadata/resolve-route-data.js
medium

Dynamic require with computed path

NPS-97509A17E1B6

The loader performs require(fontLoaderPath) where fontLoaderPath is obtained from this.getOptions(). While this is part of Next.js's internal font loading mechanism, dynamically requiring a module based on loader options can be exploited if an attacker can control the loader options. If a malicious webpack configuration or dependency injection occurs, this could allow arbitrary module loading and code execution at build time.

dist/esm/build/webpack/loaders/next-font-loader/index.js:85
medium

Dynamic module resolution and generation

NPS-4CA8E0ED19E0

The loader dynamically resolves module specifiers using this.getResolve() and rootContext, then generates require() calls with the resolved paths. While this is a legitimate webpack loader pattern, it allows arbitrary module inclusion based on the 'modules' option, which could be exploited if the option is attacker-controlled to load malicious modules.

dist/esm/build/webpack/loaders/next-instrumentation-client-loader.js
medium

build-time plugin hook execution

NPS-AD090A258B3B

The plugin uses compiler.hooks.compilation.tap, hooks.renderModuleContent.tap, hooks.render.tap, and hooks.chunkHash.tap to inject code into every rendered module during compilation. Hooks that rewrite module content are a legitimate webpack pattern but represent a powerful mutation point: any consumer of this package grants it the ability to inject arbitrary code into the output bundle. Reviewers should ensure the package is pinned and trusted.

dist/esm/build/webpack/plugins/eval-source-map-dev-tool-plugin.js:62
medium

dynamic code execution via eval()

NPS-8D983FA7B4F4

The plugin intentionally emits eval(...) calls into the generated bundle to support webpack's eval-source-map devtool. While this is standard behavior for the devtool and not malicious per se, it creates a code-execution sink: any untrusted content interpolated into content + footer is executed in the browser context. The content originates from webpack's own module sources, and footer is JSON-stringified, so injection is bounded, but the pattern still constitutes dynamic code execution and should be flagged when auditing a third-party package.

dist/esm/build/webpack/plugins/eval-source-map-dev-tool-plugin.js:181
medium

dangerouslySetInnerHTML usage

NPS-C67346563039

The component uses React's dangerouslySetInnerHTML to inject previously captured document.documentElement.innerHTML. This bypasses React's XSS protections and could enable HTML/script injection if the captured markup is ever influenced by attacker-controlled content or if the cached snapshot is tampered with in the browser. While intended for error-boundary graceful degradation, it is a notable unsafe rendering pattern.

dist/esm/client/components/errors/graceful-degrade-boundary.js:52
medium

Unvalidated attribute propagation

NPS-F091332A301B

setAttributesFromProps(el, props) forwards props directly as DOM attributes without visible validation in this file. Combined with the head element injection, untrusted props could set arbitrary attributes (e.g., onerror, nonce, href) enabling script execution or CSP bypass via nonce handling in isEqualNode.

dist/esm/client/head-manager.js:3
medium

DOM-based XSS via dangerouslySetInnerHTML

NPS-3DCB51CB9712

reactElementToDOM() directly assigns props.dangerouslySetInnerHTML.__html to element.innerHTML. If any component props are influenced by untrusted input (e.g., URL parameters, user content), this can insert arbitrary HTML/scripts into <head> elements such as meta, link, style, or script tags, leading to DOM-based XSS. This is standard React behavior but worth noting for a head manager operating on user-influenced data.

dist/esm/client/head-manager.js:6
medium

Dynamic script/style element injection into document head

NPS-EDF8534A95DC

updateElements() creates and appends arbitrary 'meta', 'base', 'link', 'style', and 'script' elements to document.head from input components. If callers pass attacker-controlled props (href, src, innerHTML, charset, etc.), this could be abused to load external resources, exfiltrate data via link preloads, or inject scripts.

dist/esm/client/head-manager.js:63
medium

dynamic module loading

NPS-F854A932780C

The function __turbopack_load_page_chunks__ dynamically loads chunks via __turbopack_load__ using data provided at runtime (chunksData). If an attacker can control the chunksData input (e.g., via server-side rendering or injection), this could lead to loading arbitrary modules. While typical for bundlers, it represents a dynamic code loading surface.

dist/esm/client/next-turbopack.js:20
medium

Dynamic script creation and injection into DOM

NPS-225495BE760E

The code creates <script> elements from caller-supplied src/children/dangerouslySetInnerHTML values and appends them to document.body. This is the intended behavior of next/script, but it is a code-execution primitive. If a consumer of this package passes untrusted values, it can load and execute arbitrary remote scripts or inline code.

dist/esm/client/script.js:65
medium

Dynamic script injection via innerHTML

NPS-4C783C8942B3

The loadScript function assigns el.innerHTML = dangerouslySetInnerHTML.__html directly to a dynamically created script element. If the dangerouslySetInnerHTML prop originates from untrusted input, this enables arbitrary JavaScript execution (XSS). While Next.js documents this prop as dangerous, it is still a code-execution sink that warrants review.

dist/esm/client/script.js:84
medium

Runtime string interpolation into an inline script tag

NPS-FDC812A2AC3B

For appDir beforeInteractive strategy, the component emits an inline <script> whose content is built with template literals embedding JSON.stringify'd props. htmlEscapeJsonString is applied for escaping, which mitigates XSS, but the pattern of constructing executable script content from runtime props is a high-risk sink that should be treated carefully.

dist/esm/client/script.js:262
medium

Trusted Types policy bypass

NPS-7ED31E928262

The Trusted Types policy 'nextjs' is created with identity functions for createHTML, createScript, and createScriptURL, effectively disabling the browser's Trusted Types XSS mitigation. Any string passed through this policy will be treated as trusted, which can reintroduce XSS vulnerabilities if untrusted input reaches these sinks.

dist/esm/client/trusted-types.js:9
medium

Security-sensitive exported function

NPS-B61AB5DF867E

__unsafeCreateTrustedScriptURL is exported and explicitly documented as security-sensitive. It promotes arbitrary strings to TrustedScriptURL, and if callers pass attacker-controlled URLs, it can lead to script loading and execution. The fallback to raw strings when Trusted Types are unavailable means the function does not actually enforce any safety.

dist/esm/client/trusted-types.js:18
medium

Dynamic imports with computed paths

NPS-56527C28AE6D

The code uses dynamic import() with paths computed from runtime variables (dir, cacheHandler, and handler values from cacheHandlers). This allows loading of arbitrary modules based on user-controlled configuration. While this is typical Next.js cache handler configuration, it constitutes dynamic module loading with external input and could be exploited if the configuration source is untrusted.

dist/esm/export/helpers/create-incremental-cache.js:12
medium

File system manipulation

NPS-B890EDE3A586

The code extracts tar archives to directories outside the package scope (cache directory and node_modules). This is necessary for the package's functionality but could overwrite files if the tar contains malicious paths (zip slip). The tar library used is from next/dist/compiled/tar, presumably safe, but still a risk.

dist/esm/lib/download-swc.js:12

Files reviewed

FileVerdictWhat the reviewer saw
dist/build/collect-build-traces.js medium This appears to be a legitimate Next.js build tracing module with no malicious patterns; the identified concerns are typical of build tooling that manipulates files and reads environment variables but pose only low risk in this context.
dist/build/next-config-ts/require-hook.js medium This module provides TypeScript require hook support with dynamic code compilation; it is not inherently malicious but introduces dynamic code execution and global module loading modifications that could be risky in untrusted contexts.
dist/build/next-config-ts/transpile-config.js medium The file is part of Next.js build tooling and intentionally transpiles and executes the project's own next.config.ts; no exfiltration, credential harvesting, obfuscation, or malicious process spawning was detected, though dynamic code execution is inherent to its function.
dist/build/route-bundle-stats.js medium This is a legitimate Next.js internal bundle-stats module, but it uses dynamic require() of filesystem paths derived from route data and mutates globals, which are patterns that warrant caution though no malicious behavior is evident.
dist/build/route-discovery.js medium This appears to be legitimate Next.js route discovery code with no clear malicious patterns, though it contains environment-variable-driven build overrides (NEXT_PRIVATE_PAGE_PATHS/NEXT_PRIVATE_APP_PATHS) that warrant monitoring as potential build-injection vectors.
dist/build/swc/index.js medium This is legitimate Next.js SWC binding loader code, but it exhibits several risky patterns — environment-variable-controlled dynamic requires/imports and runtime download of native binaries — that could be abused if those inputs are attacker-controlled.
dist/build/swc/loaderWorkerPool.js medium No clear malicious intent, but the file dynamically spawns worker threads using filenames supplied via bindings and mutates global scheduler state, warranting caution if inputs are not validated upstream.
dist/build/templates/edge-wrapper.js medium The code is a build template for Edge Runtime module wrapping with dynamic import and global state modification, but no direct malicious patterns are evident; the use of placeholders and global pollution presents minor risks if the build process is compromised.
dist/build/turborepo-access-trace/env.js medium The file implements an environment-variable access-tracking Proxy for Turborepo and contains no exfiltration, code execution, network, or process-spawning logic; the only notable concern is its global mutation of process.env and credential-harvesting potential if the tracked Set were misused by other code.
dist/build/turborepo-access-trace/helpers.js medium This is Turborepo's legitimate build access tracing helper that proxies environment variables, TCP connections, and filesystem paths for dependency tracking; no malicious patterns detected.
dist/build/turborepo-access-trace/tcp.js medium The file monkey-patches net.Socket.prototype.connect to record TCP connection destinations into an external array, which is a network-interception pattern that is benign in Turborepo's tracing context but carries inherent risk of connection-target harvesting if misused.
dist/build/webpack-build/index.js medium This file is Next.js's legitimate webpack build orchestrator; it contains no exfiltration, credential harvesting, obfuscation, or backdoor logic, but it does spawn worker processes with inherited environment variables and dynamically loads a sibling module, which are expected build-tool patterns rather than malicious behavior.
dist/build/webpack/alias/react-dom-server.js medium The code is a legitimate Next.js shim that conditionally loads React DOM server builds and intentionally disables legacy APIs; no malicious patterns were detected, though environment-dependent module loading is noted as a low-risk observation.
dist/build/webpack/config/blocks/css/plugins.js medium This is legitimate Next.js PostCSS plugin loading code; it dynamically resolves and requires plugins from user configuration, which is expected but represents a config-driven code execution surface rather than an inherent malicious pattern.
dist/build/webpack/loaders/metadata/resolve-route-data.js medium No malicious patterns (exfiltration, credential harvesting, eval, process spawning, network access, or install-time execution) were detected; the only security concern is missing XML/HTML/text escaping when interpolating metadata into generated robots.txt and sitemap.xml output, which can permit content injection.
dist/build/webpack/loaders/next-edge-function-loader.js medium This is a legitimate Next.js webpack loader, but it generates and evaluates code using dynamic build-time inputs (page paths, cache handler paths, base64 config), which could pose a risk if those inputs are compromised.
dist/build/webpack/loaders/next-font-loader/index.js medium Legitimate Next.js font loader with a dynamic require of a configurable font loader path, which poses a moderate supply-chain risk if the path can be externally controlled.
dist/build/webpack/loaders/next-instrumentation-client-loader.js medium This appears to be a legitimate Next.js instrumentation loader that dynamically resolves and requires user-configured modules; no exfiltration, credential harvesting, obfuscation, or process spawning is present, but the dynamic require generation based on build options warrants a warning-level note.
dist/build/webpack/loaders/next-middleware-loader.js medium This is a Next.js webpack middleware loader that decodes base64 configuration and resolves module paths; no clear malicious patterns like exfiltration, credential harvesting, or shell execution are present, but it relies on attacker-controllable build options and dynamic module resolution which warrant low-severity caution.
dist/cli/internal/turbo-trace-server.js medium The file is a local Turbopack trace/MCP server: it starts a loopback HTTP endpoint and a native trace server handle, with no data exfiltration, credential harvesting, obfuscation, mining, shells, or install-time execution detected, but it has unauthenticated local HTTP exposure and unbounded JSON body parsing that could enable local DoS or DNS-rebinding-style abuse.
dist/cli/internal/upload-trace.js medium Code intentionally uploads local build trace/profile files to an external Next.js endpoint; appears to be legitimate telemetry but does send user files off-machine.
dist/cli/next-dev.js medium This appears to be a legitimate Next.js dev server CLI file with expected telemetry, process forking, and trace upload behaviors; no malicious patterns such as credential theft, obfuscation, backdoors, or unauthorized external exfiltration were identified, though telemetry and trace upload to a configurable URL warrant awareness.
dist/cli/next-info.js medium This file is a legitimate Next.js diagnostic utility that collects system and package information, performs network requests to the npm registry, and spawns version-check commands; no clear malicious patterns such as credential harvesting, exfiltration, or backdoors were found.
dist/cli/next-start.js medium The code appears to be a legitimate Next.js CLI start script with no malicious patterns, but includes dynamic import of inspector and environment variable manipulation, which are low-risk security considerations.
dist/cli/next-test.js medium No clear malicious intent detected; findings relate to legitimate but potentially risky operations (dependency installation, process spawning, config file generation) that are standard for the Next.js test CLI.
Show 1975 more files
FileVerdictWhat the reviewer saw
dist/cli/next-upgrade.js medium The file spawns an external process to run '@next/codemod@canary upgrade', which is expected functionality, but the command construction from getNpxCommand and user-supplied options.revision introduces a potential command injection risk if those inputs are not properly validated.
dist/client/components/app-router.js medium This is a legitimate Next.js App Router client component with expected framework behaviors (history API patching, dynamic conditional requires, dev-mode globals); no data exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns were found, though some patterns warrant low-severity attention.
dist/client/components/errors/graceful-degrade-boundary.js medium The component relies on dangerouslySetInnerHTML with cached document HTML and reflects DOM attributes, which introduces a moderate XSS/tampering risk despite no direct exfiltration, credential harvesting, or code execution patterns.
dist/client/components/layout-router.js medium The code is part of Next.js's client-side router and contains no obvious malicious patterns; the findings are low-risk architectural concerns typical of framework internals.
dist/client/components/segment-cache/navigation-testing-lock.js medium Code implements a testing-only navigation lock with global fetch override and cookie manipulation; no direct exfiltration or malicious payloads, but the global side effects and race conditions merit a warning.
dist/client/dev/hot-reloader/app/web-socket.js medium This is legitimate Next.js Hot Module Replacement (HMR) client code with standard development-time WebSocket communication, dynamic imports for Turbopack, and no malicious patterns detected; minor warnings are due to dev-only patterns that are normal for HMR infrastructure.
dist/client/dev/hot-reloader/pages/hot-reloader-pages.js medium This is a legitimate Next.js development hot-reloader client file with standard HMR functionality; the WebSocket communication and dynamic module replacement patterns are expected development tooling behaviors, though they represent inherent development-time attack surface.
dist/client/dev/hot-reloader/pages/websocket.js medium The code appears to be a legitimate Next.js HMR client, but it constructs WebSocket URLs from configurable options and automatically reloads the page, which could be exploited under certain conditions.
dist/client/head-manager.js medium The code is part of a legitimate Next.js head manager but contains dangerous DOM injection capabilities (innerHTML, dangerouslySetInnerHTML) and direct head manipulation that could be exploited if untrusted input is passed to it.
dist/client/normalize-locale-path.js medium The code appears to be a legitimate Next.js internal helper for locale path normalization, with no clear malicious intent, though it uses conditional dynamic require and environment variable checks that warrant low-severity caution.
dist/client/request/search-params.browser.js medium This appears to be standard transpiled Next.js code that conditionally loads development or production search-params modules based on NODE_ENV, with no evidence of data exfiltration, credential harvesting, obfuscation, or process spawning, though the environment-based dynamic require warrants low-level attention.
dist/client/script.js medium This appears to be Next.js's legitimate client-side Script loader, but it contains dynamic script injection and dangerouslySetInnerHTML patterns inherent to its design, so verify provenance and treat as elevated-risk supply-chain surface.
dist/compiled/@babel/runtime/regenerator/index.js medium This is a standard Babel regenerator runtime compatibility shim; it only uses Function() for a deliberate global assignment fallback and shows no signs of exfiltration, credential theft, backdoors, or other malicious behavior.
dist/compiled/@edge-runtime/primitives/index.js medium The code appears to be a legitimate Edge Runtime primitive loader for WeakRef, but dynamically loads a companion module at import time which cannot be fully verified from this snippet alone.
dist/compiled/@edge-runtime/primitives/timers.js.text.js medium The module re-exports modified global setTimeout/setInterval via Proxies that coerce the returned Timeout to a primitive, which is suspicious monkey-patching but no clear exfiltration, credential harvesting, or code execution was found.
dist/compiled/@mswjs/interceptors/ClientRequest/index.js medium This is the genuine @mswjs/interceptors ClientRequest interceptor package; it performs extensive runtime monkey-patching of Node.js HTTP/net/TLS globals for legitimate request interception, with no evidence of data exfiltration, credential harvesting, backdoors, or malicious code execution.
dist/compiled/@next/font/dist/google/fetch-css-from-google-fonts.js medium The code dynamically loads a module from a path specified by an environment variable, which could allow arbitrary code execution if that variable is attacker-controlled.
dist/compiled/@next/font/dist/google/fetch-font-file.js medium The code is a legitimate Next.js font fetching utility with a documented mocking feature; no clear malicious patterns, but the env-var-triggered arbitrary file read warrants caution.
dist/compiled/@next/font/local/loader.js medium The file only performs a static relative require of an internal module; no malicious indicators such as exfiltration, credential harvesting, obfuscation, or process execution were found, though the out-of-directory module load is noted as a minor concern.
dist/compiled/@next/react-refresh-utils/dist/loader.js medium The loader injects React refresh runtime code into source files, which is expected behavior for a development tool; no malicious patterns were detected.
dist/compiled/babel/core-lib-config.js medium Wrapper file with no directly observable malicious patterns, but it defers all behavior to a bundled module that cannot be reviewed from this file alone.
dist/compiled/babel/core-lib-plugin-pass.js medium The file is a simple module re-export that dynamically loads a bundle, which requires further inspection of that bundle to determine safety.
dist/compiled/babel/core.js medium The file itself is a simple re-export, but its security depends on the unanalyzed './bundle' module, which could contain malicious code.
dist/compiled/babel/plugin-syntax-dynamic-import.js medium The file is a thin one-line re-export shim with no direct malicious patterns, but it defers all behavior to an unprovided bundle, giving low-confidence risk pending review of that dependency.
dist/compiled/babel/types.js medium This is a trivial re-export shim that delegates to './bundle' with no direct malicious indicators, but its behavior depends entirely on the unreviewed bundle file.
dist/compiled/browserslist/index.js medium This is a webpack-bundled copy of the legitimate 'browserslist' library; no exfiltration, backdoors, or malicious payloads were found, but it does contain dynamic eval/require patterns and reads environment variables and config files as part of its normal operation.
dist/compiled/cross-spawn/index.js medium This is the legitimate cross-spawn npm package (bundled with ncc) that provides cross-platform child process spawning; it contains standard process spawning, environment variable, and filesystem access expected of such a utility, but no malicious exfiltration, obfuscation, or backdoor patterns were detected.
dist/compiled/httpxy/index.js medium This is a legitimate httpxy/http-proxy-style library with no malicious code, but it exhibits typical proxy-library risks (SSRF, header injection, credential forwarding on redirects) that require careful caller-side validation.
dist/compiled/image-detector/detector.js medium This is a benign image-dimension detection library with no network, credential, obfuscation, or process-spawning behavior; the only notable concerns are caller-controlled fs access in the TIFF handler and parser robustness against malformed input.
dist/compiled/jest-worker/processChild.js medium This appears to be a legitimate jest-worker child process implementation that uses eval-based require and IPC message-driven dynamic function execution; no clear malicious intent (no exfiltration, credential harvesting, network calls, or backdoors), but the dynamic code execution patterns warrant a warning.
dist/compiled/jest-worker/threadChild.js medium This appears to be legitimate jest-worker threadChild code (webpack bundled), but it uses eval('require') for dynamic module loading and executes functions based on parent process messages, which are inherent risks in worker architectures.
dist/compiled/loader-runner/LoaderRunner.js medium This is the standard webpack loader-runner compiled bundle; it uses eval for dynamic ESM imports and require for loading arbitrary loaders, which are expected behaviors but carry inherent dynamic code execution risk if inputs are untrusted.
dist/compiled/mini-css-extract-plugin/loader.js medium This appears to be the legitimate mini-css-extract-plugin loader bundle; it contains dynamic module compilation (expected for its function), a stray debug console.log, and computed require paths, but no clear exfiltration, credential harvesting, backdoor, or process-spawning behavior was detected.
dist/compiled/react-experimental/cjs/react.development.js medium This appears to be the legitimate React development build with expected dev-mode behaviors; no clear exfiltration, credential harvesting, obfuscated payloads, or backdoors were identified, though a few dynamic loading patterns and global error reporting paths are noted as low-risk observations.
dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-node-register.js medium This is the official Meta React Server DOM Webpack Node register hook; it contains no exfiltration, credential harvesting, obfuscation, or shell execution, but its monkey-patching of Module.prototype._compile and directive-based runtime branching are invasive patterns worth noting as medium-risk behavior rather than outright malicious code.
dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-node-register.js medium This is the official Meta React Server DOM Webpack Node register hook; it contains no exfiltration, credential harvesting, obfuscation, or shell execution, but its monkey-patching of Module.prototype._compile and directive-based runtime branching are invasive patterns worth noting as medium-risk behavior rather than outright malicious code.
dist/compiled/regenerator-runtime/runtime.js medium This is the legitimate Facebook regenerator-runtime polyfill; it contains no malicious patterns, though its use of the Function constructor as a strict-mode escape hatch and its global assignment are minor security-relevant observations.
dist/compiled/sass-loader/cjs.js medium The file appears to be the legitimate sass-loader compiled output, but it uses dynamic require/eval patterns and environment variables that could pose limited risk if untrusted configuration or module resolution is involved.
dist/compiled/setimmediate/setImmediate.js medium The file is a standard setImmediate polyfill but contains a dynamic code execution pattern (new Function) that could be exploited if user-controlled input is passed.
dist/compiled/timers-browserify/main.js medium This appears to be a standard browserify timer polyfill with no obvious malicious patterns, but uses Function constructor and dynamic require which warrant low-severity review.
dist/compiled/vm-browserify/index.js medium This is a legitimate vm-browserify shim that implements a browser-based VM with eval-based code execution; no malicious exfiltration, credential harvesting, or backdoor patterns were found, but its inherent use of dynamic code execution warrants caution.
dist/compiled/webpack/lazy-compilation-node.js medium This is legitimate webpack lazy-compilation runtime code making a dynamic HTTP request for HMR; no malicious patterns, credential theft, shell execution, or obfuscation were found.
dist/esm/build/adapter/build-complete.js medium This file is legitimate Next.js build orchestration code, but it dynamically imports an external adapter module and hands it extensive build artifacts, paths, and preview tokens; the risk is inherent to the adapter mechanism rather than malicious code.
dist/esm/build/after-production-compile.js medium This Next.js build utility executes user-configured code after production builds and emits telemetry; it contains no evident malicious patterns but does perform dynamic code execution driven by configuration.
dist/esm/build/load-jsconfig.js medium No malicious patterns detected; the code is a legitimate Next.js build utility that loads TypeScript/JavaScript configuration files, with dynamic require patterns that are expected for this functionality.
dist/esm/build/next-config-ts/require-hook.js medium The code is a legitimate require hook for transpiling TypeScript and ESM files using swc, but it modifies global Node.js module loading behavior and executes dynamically transformed code, which could be exploited if the package or its configuration is compromised.
dist/esm/build/next-config-ts/transpile-config.js medium The code performs dynamic code execution and module loading based on a config file path, which is a potential security risk if the path is attacker-controlled, but no clear malicious patterns like data exfiltration or backdoors were found.
dist/esm/build/preview-key-utils.js medium The code generates and stores cryptographic keys in plaintext files without apparent malicious intent, but the storage mechanism poses a moderate security risk.
dist/esm/build/route-bundle-stats.js medium The code appears to be a legitimate build-time utility for collecting route bundle statistics in a Next.js project, with minor security concerns around dynamic require of constructed paths and global variable manipulation.
dist/esm/build/route-discovery.js medium This appears to be legitimate Next.js internal route-discovery code, but uses environment-variable-controlled path overrides and hardcoded dynamic require.resolve calls that warrant minor scrutiny.
dist/esm/build/swc/loaderWorkerPool.js medium No direct exfiltration, credential theft, obfuscation, or shell execution, but dynamic worker creation from external input and global worker pool management introduce potential risk if inputs are not trusted.
dist/esm/build/templates/edge-wrapper.js medium The code is a standard edge runtime wrapper that dynamically imports a module and exposes its exports through a thenable Proxy; while it uses dynamic import and top-level side effects, no malicious patterns like data exfiltration or backdoors are present.
dist/esm/build/turborepo-access-trace/env.js medium The file implements an environment variable access-tracking Proxy for build instrumentation; it contains no exfiltration, credential file access, dynamic execution, or network activity, but it globally intercepts process.env which is a moderate information-gathering concern if misused.
dist/esm/build/turborepo-access-trace/tcp.js medium This is a legitimate-looking TCP connect tracer used by Turborepo to detect network access during builds; it monkey-patches net.Socket.prototype.connect to log destinations but does not exfiltrate data, harvest credentials, execute dynamic code, or spawn processes.
dist/esm/build/webpack/config/blocks/css/index.js medium This is a legitimate Next.js webpack CSS configuration module; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected, though dynamic module resolution and environment variable usage are present as expected build-time behaviors.
dist/esm/build/webpack/config/blocks/css/plugins.js medium This file is a legitimate Next.js PostCSS plugin loader with dynamic require() calls driven by user configuration, which is expected but carries inherent supply-chain risks typical of build tooling.
dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-url-parser.js medium The code appears to be a legitimate PostCSS plugin for parsing URLs in CSS, but it includes dynamic module resolution and URL fetching capabilities that could be security-sensitive if misused, though no direct malicious patterns were found.
dist/esm/build/webpack/loaders/metadata/discover.js medium The code is a legitimate Next.js build-time metadata discovery module; it uses dynamic imports and string interpolation of file paths into generated code, which are typical for a webpack loader but represent low-to-medium injection surface if upstream inputs are untrusted.
dist/esm/build/webpack/loaders/metadata/resolve-route-data.js medium No malicious behavior (exfiltration, code execution, backdoors, credential harvesting, process spawning, or install-time hooks) was found; the code is a straightforward metadata-to-text/XML serializer, though it lacks output encoding that could enable XML/robots.txt injection if inputs are attacker-controlled.
dist/esm/build/webpack/loaders/next-font-loader/index.js medium This is a legitimate Next.js internal webpack loader for font processing; the dynamic require and path resolution are part of its normal operation, but could be abused if an attacker controls loader options or the resource query.
dist/esm/build/webpack/loaders/next-instrumentation-client-loader.js medium This is a legitimate Next.js webpack loader for client instrumentation; no malicious patterns like data exfiltration, credential harvesting, or code execution were found, but dynamic module resolution warrants caution if options are untrusted.
dist/esm/build/webpack/plugins/eval-source-map-dev-tool-plugin.js medium This is a forked webpack EvalSourceMapDevToolPlugin that legitimately uses eval/createScript and base64 source-map data URIs as part of the eval-source-map devtool; no exfiltration, credential harvesting, process spawning, or backdoor behavior is present.
dist/esm/build/worker.js medium This appears to be a legitimate Next.js worker build file with benign top-level imports and environment variable usage; no malicious patterns such as exfiltration, obfuscation, process spawning, or backdoor installation were detected.
dist/esm/client/app-dir/link.js medium This is legitimate Next.js Link component code with only minor patterns (dynamic require, location.replace with local-URL guard) that are not indicative of malicious activity.
dist/esm/client/app-globals.js medium This is legitimate Next.js client bootstrap code with environment-gated dynamic requires and import-time side effects, but no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious patterns.
dist/esm/client/components/app-router.js medium This is a legitimate Next.js App Router client component that patches browser history APIs, installs global event handlers, and dynamically requires internal modules, but contains no clear data exfiltration, credential harvesting, obfuscation, shell execution, or other malicious patterns.
dist/esm/client/components/errors/graceful-degrade-boundary.js medium The code is a legitimate-looking React error boundary for graceful degradation, but it uses dangerouslySetInnerHTML and captures/reapplies full document HTML attributes, which are unsafe rendering patterns worth flagging.
dist/esm/client/components/links.js medium This is a legitimate Next.js client-side link prefetching module with no malicious patterns; minor warnings are due to dynamic require() calls and browser API usage that are expected for this functionality.
dist/esm/client/detect-domain-locale.js medium The file contains a benign Next.js feature-flag pattern using environment variable gating and a hardcoded relative dynamic require; no malicious behavior detected, but dynamic require and env-based execution warrant low-severity notice.
dist/esm/client/dev/hot-reloader/app/web-socket.js medium The file contains standard Hot Module Replacement (HMR) WebSocket client logic for Next.js development; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning were detected.
dist/esm/client/head-manager.js medium The file is part of Next.js head manager and contains no clear malicious intent, but it performs DOM operations (innerHTML, script/style/meta/link injection into document.head) that could enable XSS if untrusted data reaches component props.
dist/esm/client/next-turbopack.js medium The code appears to be a legitimate Next.js Turbopack client entry point with dynamic chunk loading, but no clear malicious patterns such as exfiltration, credential harvesting, or backdoors were detected.
dist/esm/client/react-client-callbacks/error-boundary-callbacks.js medium This appears to be a legitimate Next.js internal error-boundary callback module; no clear malicious behavior (no exfiltration, credential harvesting, obfuscation, or process spawning) was detected, though it uses dynamic dev-only require and error reporting hooks that merit routine scrutiny.
dist/esm/client/request/params.browser.js medium The code uses environment-based conditional require to load one of two static modules, which is a benign pattern but carries minor risk due to dynamic loading and ESM/CJS mixing.
dist/esm/client/request/search-params.browser.js medium Code conditionally loads modules based on NODE_ENV; this is a typical pattern but relies on environment variable control, posing a low risk if the environment is compromised.
dist/esm/client/script.js medium This is the legitimate Next.js next/script client runtime; it contains expected dynamic script-injection primitives (innerHTML, DOM script appending, inline script emission) that are code-execution sinks but are consistent with the component's documented purpose and contain no exfiltration, credential harvesting, obfuscation, or process-spawning malicious patterns.
dist/esm/client/trusted-types.js medium This Next.js Trusted Types helper intentionally implements a no-op Trusted Types policy and exports a documented unsafe string-to-TrustedScriptURL promotion function, weakening XSS protections rather than containing classic malicious code.
dist/esm/client/webpack.js medium The code monkey-patches webpack internals to append a deployment ID query string to chunk filenames; while it modifies module/asset loading behavior and exposes a global public-path setter without validation, no exfiltration, credential harvesting, or obfuscated payloads were found.
dist/esm/export/helpers/create-incremental-cache.js medium This appears to be legitimate Next.js incremental cache setup code, but it uses dynamic imports with computed paths from configuration which could load arbitrary modules if the configuration is attacker-controlled.
dist/esm/lib/download-swc.js medium The code downloads and extracts SWC binaries from a registry, which is expected for Next.js, but it involves network requests and file system operations outside the package scope, posing moderate risk if the registry or tar contents are compromised.
dist/esm/lib/find-config.js medium The code dynamically discovers and executes local configuration files, which is a legitimate pattern but introduces a code execution surface if the search path or key is attacker-controlled; no data exfiltration, credential harvesting, obfuscation, or network exfiltration was detected.
dist/esm/lib/helpers/get-npx-command.js medium The file contains a benign use of execSync to probe yarn dlx availability, with no malicious patterns detected, though child process execution warrants low-severity caution.
dist/esm/lib/helpers/get-online.js medium The code performs expected network and proxy checks with minor process spawning, but no malicious patterns are evident.
dist/esm/lib/helpers/get-pkg-manager.js medium The code is a standard package manager detection utility with minor process execution that is not overtly malicious, but execSync calls make it a low-severity concern.
dist/esm/lib/helpers/get-registry.js medium The code executes the detected package manager's config command to read the registry URL, which is a legitimate but potentially risky pattern if the package manager name is attacker-controlled; no clear malicious intent, but medium risk due to shell execution.
dist/esm/lib/helpers/git.js medium Purpose-built git branch/commit helper that uses execSync with hardcoded arguments; no exfiltration, backdoor, or obfuscation found, but the generic args shell interpolation is a latent injection risk if reused.
dist/esm/lib/helpers/install.js medium The code is a legitimate package manager installation helper that spawns npm, pnpm, or yarn with user-provided dependencies; no clear malicious patterns were detected, but it does execute processes with input that should be validated to prevent command injection.
dist/esm/lib/memory/startup.js medium This Next.js memory debugging module is not malicious but enables heap snapshot generation via SIGUSR2 and near memory limits, which could expose sensitive in-memory data to disk if the module is enabled in production.
dist/esm/lib/mkcert.js medium The code downloads and executes a remote binary without integrity checks and uses shell commands with dynamic input, posing security risks.
dist/esm/lib/patch-incorrect-lockfile.js medium The code is a legitimate Next.js lockfile patcher but performs unverified network fetches driven by registry configuration and rewrites package-lock.json with fetched tarball/integrity data, creating a supply-chain tampering risk if the registry or network is compromised.
dist/esm/lib/recursive-copy.js medium The code performs recursive file copying with potential path traversal and symlink following risks, but no clear malicious patterns were detected.
dist/esm/lib/turbopack-warning.js medium The file appears to be legitimate Next.js Turbopack warning/validation code with no exfiltration, obfuscation, shell execution, or credential harvesting; only minor low-severity dynamic loading and process.exit behaviors are present.
dist/esm/lib/verify-partytown-setup.js medium The code performs legitimate Next.js build-time operations for Partytown integration, including dynamic module loading and file system cleanup, but carries low-to-medium risk due to dynamic require and recursive deletion.
dist/esm/lib/verify-typescript-setup.js medium This is legitimate Next.js TypeScript verification code with expected dynamic require, auto-install, and file-writing behaviors; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors detected.
dist/esm/next-devtools/server/attach-nodejs-debugger-middleware.js medium The middleware intentionally exposes the Node.js inspector debugger endpoint, which if reachable outside a trusted local development environment can lead to remote code execution and credential/data theft.
dist/esm/next-devtools/server/devtools-config-middleware.js medium Dev-server middleware exposes an unauthenticated local POST endpoint that buffers unbounded input and writes user-controlled JSON to a cache file, presenting DoS and potential prototype-pollution concerns but no clear exfiltration, credential theft, or code-execution payloads.
dist/esm/next-devtools/server/launch-editor.js medium The code is part of Next.js devtools for launching editors and contains legitimate process spawning and environment variable usage, but lacks robust input sanitization in some paths, posing a moderate security risk if misused.
dist/esm/next-devtools/server/restart-dev-server-middleware.js medium The code implements Next.js dev-server restart and status endpoints; it contains no data exfiltration, credential harvesting, obfuscation, or backdoor patterns, but exposes unauthenticated process termination and cache-invalidation capabilities that could cause denial of service if the dev server were exposed.
dist/esm/next-devtools/userspace/app/forward-logs.js medium Code appears to be legitimate Next.js devtools log forwarding, but it intercepts console/error output and transmits serialized runtime data over a WebSocket, which could leak sensitive information if enabled outside trusted development contexts.
dist/esm/next-devtools/userspace/pages/pages-dev-overlay-setup.js medium This appears to be legitimate Next.js devtools code that installs a pages dev overlay and global error handlers; no clear malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or backdoors were detected.
dist/esm/server/api-utils/get-cookie-parser.js medium No malicious patterns detected; the code performs standard cookie parsing with a benign runtime require of an internal Next.js module.
dist/esm/server/api-utils/node/api-resolver.js medium The file contains legitimate Next.js API resolver logic with some inherent risks around header forwarding and network requests, but no clear malicious patterns or backdoors.
dist/esm/server/api-utils/node/try-get-preview-data.js medium The code is part of Next.js's legitimate preview mode handling, but it contains weak validation (dev-mode fallback), dynamic requires of internal modules, and JSON parsing of decrypted cookie data without strict type checks, which could be exploited in misconfigured deployments.
dist/esm/server/app-render/action-handler.js medium This is legitimate Next.js internal Server Actions handling code that performs intentional internal worker forwarding, with no malicious exfiltration, credential harvesting, obfuscated payloads, or backdoors, but it does include outbound fetch requests driven by request-derived origin/host metadata that warrant defensive scrutiny against SSRF and header/cookie leakage.
dist/esm/server/app-render/app-render-render-utils.js medium The code is part of Next.js's rendering utilities and does not contain malicious patterns, but it calls an explicitly dangerous internal function for flushing immediates, which warrants caution.
dist/esm/server/app-render/app-render-scheduling.js medium The code is a Next.js internal workaround that monkey-patches Node.js timer internals to guarantee atomic timer groups; it contains no exfiltration, credential harvesting, dynamic code execution, network, or process-spawning behavior, though its reliance on private timer fields is a fragile practice worth noting.
dist/esm/server/app-render/debug-channel-server.js medium This file contains no malicious patterns; it is a legitimate debug channel switcher for Next.js that conditionally loads Node or Web implementations based on an environment variable, with production safeguards.
dist/esm/server/app-render/encryption-utils-server.js medium The code is a legitimate Next.js encryption utility that manages encryption keys for server actions; no malicious patterns were detected, but it does handle sensitive encryption keys and environment variables.
dist/esm/server/app-render/entry-base.js medium No clear malicious behavior was identified; the file contains standard Next.js internal re-exports and environment-conditional requires that are low-risk but warrant review.
dist/esm/server/app-render/instant-test-bootstrap.js medium The file contains no data exfiltration, credential harvesting, obfuscation, miner, or process-spawning behavior; it generates a cookie-gated same-origin RSC prefetch inline script, which is a minor concern due to inline script generation and automatic fetch but consistent with its documented purpose.
dist/esm/server/dev/dev-validation-worker-pool.js medium Legitimate Next.js dev-server validation worker code with expected dynamic module loading, worker spawning, and env propagation; no malicious patterns, exfiltration, or credential harvesting detected.
dist/esm/server/dev/get-source-map-from-file.js medium This is legitimate Next.js internals for reading source maps, but it resolves user/file-controlled sourceMappingURL paths without sanitization, allowing potential out-of-scope file reads.
dist/esm/server/dev/hot-reloader-shared-utils.js medium The code is a benign Next.js hot-reloader utility that checks version information via a fixed public npm registry endpoint; no malicious patterns were detected.
dist/esm/server/dev/hot-reloader-webpack.js medium This is legitimate Next.js dev-server hot-reloader code with no evident malware, but it includes powerful dev-only features (inspector fetch, CORS reflection, debugger attach middleware, unauthenticated WebSocket HMR) that could be dangerous if the dev server is exposed beyond localhost.
dist/esm/server/dev/middleware-webpack.js medium This is a Next.js webpack dev-tools middleware file; no overt malicious code (exfiltration, credential theft, obfuscation, backdoors, miners) is present, but it exposes unauthenticated dev-server endpoints that can launch editors with user-controlled paths, which could enable process spawning or path traversal if reachable.
dist/esm/server/dev/on-demand-entry-handler.js medium This is legitimate Next.js development server code with no overt malicious patterns, though it handles unauthenticated HMR WebSocket messages and includes MCP handler dispatch that warrants caution in untrusted dev environments.
dist/esm/server/dev/use-cache-probe-pool.js medium Code is a legitimate Next.js dev-only 'use cache' hang-detection probe pool; no exfiltration, credential harvesting, obfuscation, or shell execution detected, though it spawns workers with inherited env and computes worker paths dynamically.
dist/esm/server/lib/app-info-log.js medium Code appears to be legitimate Next.js startup logging with minor file-write side effects (agent rules generation) and env file path enumeration, no clear malicious behavior detected.
dist/esm/server/lib/cpu-profile.js medium The code is a legitimate CPU profiling utility for Next.js, but it reads environment variables to determine file write paths without sanitization or containment, presenting a low-to-medium arbitrary file write risk if those environment variables are attacker-controlled.
dist/esm/server/lib/module-loader/node-module-loader.js medium This appears to be a legitimate Next.js runtime module loader, but it performs dynamic module loading with require()/__non_webpack_require__() and conditionally branches on environment variables, which warrants monitoring if the loaded module id can be influenced externally.
dist/esm/server/lib/module-loader/route-module-loader.js medium No overtly malicious behavior, but the loader dynamically imports a caller-controlled module id through an injectable loader, a potential arbitrary module loading/execution risk that warrants review of the underlying NodeModuleLoader and callers.
dist/esm/server/lib/render-server.js medium The code is part of Next.js internals and contains a potential dynamic import from an environment variable in test mode, but no overtly malicious patterns were found.
dist/esm/server/lib/router-utils/resolve-routes.js medium This is a standard Next.js internal router utility file; it contains no malicious patterns such as exfiltration, credential theft, obfuscation, or backdoor behavior, though it includes minor trust-boundary considerations around proxy headers and test-gated file reads.
dist/esm/server/lib/router-utils/setup-dev-bundler.js medium This appears to be legitimate Next.js development bundler code with no evidence of malicious intent; findings are limited to normal framework behaviors like dynamic requires, env var reads, and telemetry.
dist/esm/server/lib/start-server.js medium This appears to be legitimate Next.js server startup code with a minor medium-risk shell command interpolation concern in getProcessIdUsingPort and several low-risk patterns typical of a development server.
dist/esm/server/load-components.js medium The file is part of Next.js internal server-side code that loads manifests and page modules dynamically; while it uses eval-like manifest evaluation and computed path module loading, these are expected patterns for this framework and no clear malicious intent (exfiltration, backdoors, credential harvesting) is present.
dist/esm/server/load-manifest.external.js medium The code executes manifest files as JavaScript via vm.runInNewContext, which is a potential sandbox escape vector if manifest contents are attacker-controlled, but no immediate malicious patterns are present.
dist/esm/server/mcp/get-or-create-mcp-server.js medium The file itself contains no overt malicious patterns such as exfiltration, shell execution, or obfuscation, but it exposes a privileged MCP server with filesystem path forwarding and dev-server control tools that could pose security risks if exposed or if the underlying tool implementations lack input validation.
dist/esm/server/mcp/mcp-telemetry-tracker.js medium Code is a benign telemetry counter, but it contains a runtime require() for an internal telemetry events module that warrants inspection of the referenced file.
dist/esm/server/mcp/tools/get-project-metadata.js medium No clear malicious patterns found, but the file records telemetry on each tool invocation and returns the local project path, which should be reviewed in context of the telemetry tracker implementation.
dist/esm/server/mcp/tools/get-routes.js medium The code is a legitimate MCP tool for scanning Next.js route files; no malicious exfiltration, credential harvesting, obfuscation, or command execution patterns were detected, though it does perform intentional filesystem scanning and internal telemetry tracking.
dist/esm/server/node-environment-baseline.js medium The code performs top-level global object modifications and lazy module loading via require(), which are not overtly malicious but represent potential attack surfaces for supply chain compromise.
dist/esm/server/node-environment-extensions/console-file.js medium The code patches console methods to mirror output to a file logger during development; while not overtly malicious, it introduces a data persistence mechanism that could leak sensitive console output if the log file is not properly secured.
dist/esm/server/node-environment-extensions/fast-set-immediate.external.js medium Legitimate Next.js internal module that globally monkey-patches Node.js timer/nextTick primitives at import time, which is invasive but not malicious; no exfiltration, credential theft, dynamic code execution, or shell commands were found.
dist/esm/server/node-environment-extensions/node-crypto.js medium The code is a legitimate Next.js instrumentation patch that wraps node:crypto functions to track dynamic IO during prerendering; no malicious exfiltration, backdoor, or process-spawning patterns were found, though the import-time monkey-patching is a notable behavioral concern.
dist/esm/server/node-environment-extensions/process-error-handlers.js medium No data exfiltration, credential harvesting, obfuscation, or backdoor patterns detected, but the code intentionally overrides Node.js process-level error handling by removing all uncaughtException and unhandledRejection listeners, which is a potentially risky global side effect.
dist/esm/server/node-environment-extensions/unhandled-rejection.external.js medium The code is not overtly malicious (no exfiltration, exec, or credential harvesting), but it aggressively monkey-patches Node.js process error-handling methods at import time to selectively suppress unhandled rejections, which is an invasive and potentially fragile practice that warrants scrutiny.
dist/esm/server/node-environment-extensions/web-crypto.js medium The file is framework instrumentation that transparently wraps crypto.getRandomValues and crypto.randomUUID for prerender IO tracking; it contains no exfiltration, credential harvesting, obfuscation, or process spawning, but does monkey-patch global Web Crypto APIs which warrants caution.
dist/esm/server/node-polyfill-crypto.js medium No malicious behavior detected, but the code mutates globalThis.crypto at import time and exposes a settable, configurable global property that could be overwritten by other code, weakening cryptographic trust boundaries on affected Node.js versions.
dist/esm/server/post-process.js medium The code is a legitimate Next.js server utility for HTML post-processing with CSS optimization; it uses standard patterns with no clear malicious intent, though dynamic require and env var usage are noted as minor concerns.
dist/esm/server/render-result.js medium This is legitimate Next.js internal code for handling render results with no malicious patterns; the dynamic require and environment variable access are standard framework patterns.
dist/esm/server/require-hook.js medium This file is a legitimate Next.js require-hook that patches Node module resolution, but its monkey-patching of require and _resolveFilename represents a powerful, high-risk pattern that could be repurposed or abused if the package or its dependencies were compromised.
dist/esm/server/require.js medium The code appears to be standard Next.js server-side page loading logic with dynamic requires and file system access, but no clear malicious patterns like data exfiltration or credential harvesting were found.
dist/esm/server/route-matcher-providers/helpers/manifest-loaders/node-manifest-loader.js medium This Next.js manifest loader dynamically requires files based on a constructed path; while it appears to be a legitimate internal helper, the lack of path validation on the 'name' input poses a potential arbitrary module loading risk if inputs are not strictly controlled upstream.
dist/esm/server/route-modules/app-page/module.render.js medium The file is a benign Next.js internal lazy-render helper; no data exfiltration, credential harvesting, obfuscation, network access, process spawning, or install-time execution was found, though it does use runtime require for an internal compiled module.
dist/esm/server/route-modules/route-module.js medium This file is a legitimate Next.js internal module handling route preparation, manifest loading, and cache setup; no exfiltration, credential theft, backdoors, or obfuscation patterns were found, though it does contain dynamic module loading and eval-based manifest loading that are controlled by configuration.
dist/esm/server/web/adapter.js medium This is a legitimate Next.js middleware adapter file with no evident malicious intent; the only notable concerns are a dynamic require gated by an environment variable and header/rewrite propagation behavior that could theoretically leak information if misconfigured.
dist/esm/server/web/get-edge-preview-props.js medium This file is a benign Next.js edge-runtime helper that reads preview mode environment variables; no exfiltration, obfuscation, process spawning, or other malicious patterns are present in the provided code.
dist/esm/server/web/sandbox/context.js medium The code is part of Next.js edge runtime sandboxing and uses dynamic code execution, environment variable exposure, and file system access, but these are inherent to its sandboxing purpose and not overtly malicious.
dist/esm/server/web/sandbox/fetch-inline-assets.js medium The code lacks proper path validation when resolving file paths from user-controlled 'blob:' URLs, potentially allowing path traversal and unauthorized file reads.
dist/esm/server/web/sandbox/sandbox.js medium The code contains several low-to-medium risk patterns related to sandbox context manipulation and dynamic evaluation, but no clear malicious intent or data exfiltration was detected.
dist/esm/shared/lib/bloom-filter.js medium The file implements a standard Bloom filter with no exfiltration, credential harvesting, obfuscation, or command execution; only minor concerns around conditional dynamic require, environment variable usage, and unvalidated import data.
dist/esm/shared/lib/image-blur-svg.js medium No exfiltration, credential harvesting, obfuscation, network, or process-spawning code is present, but the function builds an SVG string via unescaped string interpolation of caller-controlled values (notably blurDataURL), creating a potential injection vector.
dist/esm/shared/lib/router/utils/middleware-route-matcher.js medium No malicious exfiltration, credential harvesting, or backdoor patterns detected, but the code compiles and executes externally-supplied regex patterns dynamically, which could pose a ReDoS or input-validation risk depending on how matchers are sourced.
dist/esm/shared/lib/router/utils/path-match.js medium The file is a legitimate Next.js path-matching utility with no clear malicious behavior, but it has minor security considerations around dynamic regex construction and object spreading that could be abused by untrusted input.
dist/esm/shared/lib/size-limit.js medium No clearly malicious behavior identified; only a minor concern about dynamic require() usage in an ESM module.
dist/experimental/testmode/fetch.js medium The file is part of Next.js experimental test-mode fetch interception and does not exhibit overt malicious behavior, but it globally monkey-patches fetch and forwards full request details (including credentials and headers) to a local proxy, which could be abused if the proxy endpoint is compromised or misconfigured.
dist/experimental/testmode/playwright/next-fixture.js medium No overt malicious code such as exfiltration, credential harvesting, obfuscation, or process spawning was found; however, the module's wildcard route interception and configurable fetch loopback behavior are test-mode capabilities that should be vetted before inclusion in non-test environments.
dist/experimental/testmode/playwright/next-worker-fixture.js medium The file implements a scoped local proxy server for Next.js testmode with no clear malicious behavior, though the runtime-registered proxy handlers represent a minor attack surface.
dist/experimental/testmode/playwright/page-route.js medium Test-mode Playwright route handler that proxies cross-origin fetch requests and manipulates headers; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution were detected, but the proxying behavior warrants caution.
dist/experimental/testmode/proxy/server.js medium The file implements a test-mode HTTP proxy server that binds to all network interfaces and forwards fetch requests without apparent target restrictions, creating network exposure and potential SSRF/DoS concerns, though no overtly malicious (exfiltration, credential theft, RCE) patterns are present.
dist/export/helpers/create-incremental-cache.js medium The code contains dynamic imports with user-influenced paths and global state modification, which pose moderate security risks if inputs are not properly validated.
dist/lib/download-swc.js medium No overt malicious patterns (no exfiltration, credential harvesting, or shell execution) were found, but the script downloads and extracts remote tarballs without integrity verification, posing a supply-chain risk.
dist/lib/find-config.js medium This is a legitimate configuration file loader from Next.js that dynamically imports config files found via directory traversal, which carries inherent code-execution risk if malicious config files are planted in parent directories, but contains no overtly malicious patterns.
dist/lib/helpers/get-cache-directory.js medium The code appears to be a legitimate cache directory resolver, but it uses environment variables and file system checks that could be exploited if the module is used in a malicious context, though no overt malicious patterns are present.
dist/lib/helpers/get-npx-command.js medium The file contains child_process.execSync usage and returns shell command strings for package manager invocation, which are low-to-medium risk patterns in isolation but could become dangerous if combined with untrusted input downstream.
dist/lib/helpers/get-online.js medium The code appears to be a legitimate helper for checking online status and proxy configuration, with only minor concerns around shell command execution and environment variable access.
dist/lib/helpers/get-pkg-manager.js medium No malicious patterns detected; the code performs standard package manager detection using environment variables, lockfile checks, and version commands, with only minor shell execution concerns.
dist/lib/helpers/get-registry.js medium The code executes a shell command to retrieve the npm registry, using a package manager name derived from project files, which could theoretically enable command injection if that name is attacker-controlled; otherwise it appears to be a legitimate Next.js helper.
dist/lib/helpers/install.js medium The code is a legitimate helper for spawning package manager install commands, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors, though it does spawn processes based on caller-provided dependency names.
dist/lib/inline-static-env.js medium This appears to be a legitimate Next.js build-time utility that inlines static environment variables into client and server bundles; no exfiltration, credential harvesting, dynamic code execution, or backdoor patterns were found, though the broad file rewriting and env inlining behavior should be understood by consumers.
dist/lib/memory/startup.js medium Legitimate memory debugging code for Next.js that modifies V8 flags, registers a SIGUSR2 handler, and generates heap snapshots, with no malicious patterns detected but minor security considerations around heap snapshot data exposure.
dist/lib/mkcert.js medium Legitimate mkcert wrapper, but contains shell-exec of a downloaded binary with unverified integrity and unsanitized host interpolation.
dist/lib/patch-incorrect-lockfile.js medium The file performs legitimate-looking lockfile patching for @next/swc packages, but includes outbound network fetches, external lockfile mutation, and dynamic registry resolution that warrant caution despite no overtly malicious payloads.
dist/lib/require-instrumentation-client.js medium The file is a benign Next.js internal loader that requires an aliased instrumentation module at import time; no exfiltration, credential harvesting, obfuscation, process spawning, or network activity is present, though the resolved module's behavior cannot be audited from this file alone.
dist/lib/turbopack-warning.js medium No malicious patterns (exfiltration, credential theft, obfuscation, shells, mining) found; only benign Next.js Turbopack configuration validation with a forced process.exit(1) and environment-variable-gated behavior typical of the framework.
dist/lib/typescript/runTypeScriptCli.js medium The code spawns the TypeScript CLI via cross-spawn with array arguments and shell disabled, performs signal-based process group termination for cleanup, and reads package metadata; no data exfiltration, credential harvesting, obfuscation, or backdoor patterns were found, but the process spawning and forced termination capabilities warrant a warning-level classification.
dist/lib/typescript/writeAppTypeDeclarations.js medium The code appears to be a legitimate Next.js utility for writing TypeScript declaration files, with no malicious patterns such as data exfiltration, credential harvesting, or code execution; minor warnings relate to expected file system writes and path construction.
dist/lib/verify-partytown-setup.js medium The code appears to be a legitimate Next.js utility for verifying and setting up Partytown, with no clear malicious patterns, though it uses dynamic require and file system operations that carry low inherent risk.
dist/lib/verify-typescript-setup.js medium This is legitimate Next.js TypeScript setup/verification code with no malicious patterns; the flagged items (dynamic require of the TypeScript API, auto-installation of TS dependencies, and writing tsconfig/next-env files) are expected framework behaviors rather than security defects.
dist/lib/worker.js medium This appears to be a legitimate Next.js build worker wrapper around jest-worker with no overt data exfiltration, credential theft, obfuscation, or backdoor code, but it inherits and propagates the full parent environment into child processes and spawns/kills child processes, which are expected build-tool behaviors rather than malicious patterns.
dist/next-devtools/server/attach-nodejs-debugger-middleware.js medium This appears to be a legitimate Next.js development helper that exposes the Node.js inspector via a dev-server middleware, but it creates a debugger exposure risk if the dev server is reachable by untrusted parties.
dist/next-devtools/server/launch-editor.js medium This is legitimate Next.js devtools code for launching editors, but it spawns external processes and consumes EDITOR/VISUAL/REACT_EDITOR environment variables, creating command-execution surface that is a normal but notable risk; no malicious exfiltration or backdoor patterns were found.
dist/next-devtools/server/middleware-response.js medium No malicious patterns detected; however, the code may expose sensitive error details via util.inspect in HTTP 500 responses.
dist/next-devtools/server/restart-dev-server-middleware.js medium This is a legitimate Next.js dev-server restart/status middleware with no signs of exfiltration, credential harvesting, obfuscation, or backdoor code; the only concerns are dev-only process termination and cache invalidation triggered by local HTTP requests.
dist/next-devtools/userspace/app/errors/intercept-console-error.js medium Legitimate Next.js devtools code that intercepts and forwards console errors, but the global console patching and error forwarding behavior warrants medium-severity attention in third-party contexts.
dist/next-devtools/userspace/app/forward-logs.js medium This is Next.js devtools instrumentation that intercepts console output/errors and forwards them over WebSocket, which is intended functionality but creates a data channel that could exfiltrate sensitive logged information if the socket endpoint or activation env variable is misused.
dist/server/api-utils/node/api-resolver.js medium This appears to be legitimate Next.js API route resolver code with expected framework behaviors; the main concerns are the SSRF-prone fetch using the Host header and dynamic require calls, but no clear malicious patterns were found.
dist/server/app-render/app-render-scheduling.js medium No malicious patterns (no exfiltration, credential harvesting, eval, shells, or network activity) were found; the only concerns are benign but invasive monkey-patching of Node.js timer internals for scheduling determinism.
dist/server/app-render/entry-base.js medium This appears to be a legitimate Next.js server-render entry module, but contains several low-severity patterns (environment-gated dynamic require, globalThis mutation, import-time side effects) that warrant attention rather than indicating active malice.
dist/server/app-render/module-loading/instrument-module-getter.js medium Code is a legitimate Next.js internal module-getter instrumentation wrapper; it only reads Next.js-specific environment flags and lazily requires a static relative module, with no exfiltration, credential access, or command execution observed.
dist/server/config-utils.js medium This Next.js config utility installs a global require hook aliasing webpack modules to bundled Next.js copies; while the paths are explicit and appear benign, the pattern of globally mutating module resolution and using dynamic require.resolve warrants a warning for supply-chain review.
dist/server/dev/hot-reloader-shared-utils.js medium No malicious patterns detected; the only outbound network call is a hardcoded, non-exfiltrating version staleness check against the public npm registry.
dist/server/dev/hot-reloader-turbopack.js medium This is a legitimate Next.js Turbopack dev hot-reloader file; it contains dev-time network access to the local inspector, dynamic invocation of global HMR hooks, and environment variable usage, but no clear data exfiltration, credential harvesting, obfuscation, or backdoor patterns were found.
dist/server/dev/hot-reloader-webpack.js medium This is legitimate Next.js dev-server hot-reloader code; the only notable concern is an origin-reflection CORS policy on dev hot-reloader endpoints that could expose source/source-maps to arbitrary origins in a development environment.
dist/server/dev/middleware-webpack.js medium This is a Next.js devtools middleware file with no obvious credential harvesting, exfiltration, obfuscation, or eval/child_process abuse, but it exposes user input to filesystem path resolution, source map reading, and editor process launching, creating a non-trivial attack surface if the dev server is reachable by untrusted parties.
dist/server/dev/use-cache-probe-pool.js medium This appears to be legitimate Next.js dev-server internals (use-cache hang probe worker pool) with no exfiltration, credential harvesting, obfuscation, backdoors, or shell execution; only routine child-process spawning and env propagation warrant low-severity notes.
dist/server/lib/cpu-profile.js medium The code appears to be a legitimate CPU profiling utility for Next.js, but it writes files based on environment variables and executes at import time, posing a low-to-medium risk if environment variables are attacker-controlled.
dist/server/lib/experimental/create-env-definitions.js medium The code is a legitimate Next.js utility for generating TypeScript definitions from environment variables, with only minor concerns about file writing and env variable key processing, but no malicious patterns detected.
dist/server/lib/generate-agent-files.js medium No malicious patterns detected (no exfiltration, credential harvesting, code execution, or network activity), but the module silently creates and rewrites AGENTS.md/CLAUDE.md in the project directory at dev time and injects AI-agent instruction content.
dist/server/lib/module-loader/node-module-loader.js medium This is a Next.js internal node module loader with dynamic require based on an id parameter; it contains no exfiltration, credential harvesting, obfuscation, or process spawning, but the dynamic require pattern warrants a low-to-medium warning.
dist/server/lib/render-server.js medium The code is part of Next.js's server rendering infrastructure and contains legitimate dynamic import and environment-based behavior, but the lack of validation on environment-controlled import paths and server field propagation introduces medium-risk attack surfaces.
dist/server/lib/router-server.js medium This is a legitimate Next.js router-server module from the Next.js package; it contains no clear data exfiltration, credential harvesting, obfuscated payloads, or reverse shells, but uses dynamic requires, global fetch patching, and internal header filtering that warrant routine supply-chain verification since the analyzed file appears to be legitimate Next.js core code.
dist/server/lib/router-utils/instrumentation-globals.external.js medium The code appears to be a legitimate Next.js instrumentation loading utility, but it dynamically loads and executes a module from a computed path, which could be risky if the path or file is attacker-controlled.
dist/server/lib/router-utils/proxy-request.js medium No clear malicious code (exfiltration, credential theft, shells, or mining) was found, but the code implements a generic request-forwarding proxy with limited target validation, which carries SSRF/open-proxy and header-forwarding risks if exposed to untrusted input.
dist/server/lib/start-server.js medium This is a legitimate Next.js start-server module with no data exfiltration or credential harvesting, but it uses child_process.exec with interpolated port values for port lookup, which is a minor command-injection pattern worth noting.
dist/server/load-components.js medium This appears to be legitimate Next.js server-side code for loading page components and manifests, but contains dynamic code execution (evalManifest) and dynamic module loading (requirePage) patterns that warrant caution if page paths or manifest paths are attacker-controllable.
dist/server/load-manifest.external.js medium This appears to be legitimate Next.js manifest-loading code, but the evalManifest function executes file contents via vm.runInNewContext and paths are file-system derived, which are risky if callers pass untrusted paths; no exfiltration, backdoors, or mining patterns were found.
dist/server/node-environment-baseline.js medium The file is a Next.js runtime shim that modifies globalThis at import time and lazily loads a bundled WebSocket implementation, which is not overtly malicious but introduces supply-chain and runtime trust concerns.
dist/server/node-environment-extensions/console-file.js medium The code patches global console methods for development-time file logging; no data exfiltration, credential harvesting, obfuscation, or malicious network/process activity detected, but global console modification is a minor security hygiene concern.
dist/server/node-environment-extensions/fast-set-immediate.external.js medium This is a legitimate Next.js internal timer-shimming module, but it globally monkey-patches setImmediate/clearImmediate/process.nextTick at import time, which is a risky pattern worth flagging despite no evidence of exfiltration, credential theft, or backdoors.
dist/server/node-environment-extensions/process-error-handlers.js medium This is Next.js internal code that intentionally overrides Node.js error handling to prevent crashes, which is a legitimate framework behavior but carries security implications by suppressing uncaught exceptions and unhandled rejections.
dist/server/node-environment-extensions/unhandled-rejection.external.js medium No malicious exfiltration, credential theft, obfuscation, or backdoor patterns were found; the primary risks are aggressive global process monkey-patching and selective suppression of unhandled rejection events, which are legitimate but intrusive Error-handling side effects.
dist/server/node-environment.js medium The file itself contains no direct malicious patterns, but its import-time execution of multiple opaque environment-modifying modules warrants review of the required submodules for potential hidden malicious behavior.
dist/server/node-polyfill-crypto.js medium The file is a legitimate crypto polyfill but mutates the global crypto object at import time with a mutable setter, creating a medium-risk attack surface for crypto-provider substitution by other code in the process; no direct malicious behavior is present.
dist/server/post-process.js medium The code is a legitimate Next.js post-processing utility that conditionally loads the 'critters' package for CSS optimization; no malicious patterns were detected.
dist/server/render-result.js medium The file is part of Next.js's rendering internals and contains no malicious patterns; the only notable items are standard framework-specific dynamic require calls with hardcoded module names and environment variable checks for runtime detection.
dist/server/require-hook.js medium The file monkey-patches Node.js module resolution to alias Next.js internal modules; no direct malicious behavior (exfiltration, shells, crypto) was found, but the module-loading interception warrants caution.
dist/server/require.js medium The code performs dynamic module loading and file reads based on computed paths derived from manifests and user input, which could be exploited for path traversal or arbitrary code execution if inputs are not properly sanitized.
dist/server/route-matcher-providers/helpers/manifest-loaders/node-manifest-loader.js medium This appears to be legitimate Next.js internal manifest-loading code with a dynamic require pattern that could be risky if inputs are not validated, but no overt malicious behavior is present.
dist/server/route-modules/route-module.js medium This appears to be legitimate Next.js framework code with standard dynamic imports and manifest loading, though it uses runtime-computed module paths and environment variables that warrant awareness rather than indicating outright malice.
dist/server/web/adapter.js medium The file contains conditional dynamic require of an experimental internal module based on an environment variable, which poses a moderate risk if that variable is attacker-controlled, but no clear malicious patterns like data exfiltration, credential harvesting, or backdoors were found.
dist/server/web/sandbox/context.js medium The code is part of Next.js Edge Runtime sandboxing and includes legitimate dynamic code execution and environment variable access, but these patterns pose security risks if the sandbox is bypassed or if input paths are attacker-controlled.
dist/server/web/sandbox/fetch-inline-assets.js medium The function reads and streams local files based on an unvalidated blob name that can traverse outside the intended distDir, creating a path traversal / arbitrary file read risk.
dist/server/web/sandbox/sandbox.js medium The file is a legitimate Next.js edge sandbox runner; it contains no data exfiltration, credential harvesting, obfuscation, or backdoor patterns, though it does perform dynamic evaluation and global context injection that are inherent to its sandboxing role.
dist/shared/lib/router/utils/escape-path-delimiters.js medium The code is not malicious but contains a broken regular expression that could cause runtime errors and weaken path escaping.
dist/shared/lib/router/utils/path-match.js medium Path-matching utility with no network, filesystem, process, or exfiltration behavior; only a minor concern that caller-supplied regex modifications could enable ReDoS if fed untrusted input.
dist/telemetry/anonymous-meta.js medium This is a Next.js telemetry metadata collector that fingerprints the host environment (OS, CPU, memory, Docker/WSL/CI status) but does not exfiltrate data, harvest credentials, execute shell commands, or contain obfuscated/backdoor code.
dist/telemetry/detached-flush.js medium The file implements Next.js's detached telemetry flush mechanism, which reads and deletes project-local event files and forwards telemetry data; no credential harvesting, obfuscation, shell spawning, or other clearly malicious patterns were detected, though it does execute filesystem operations and telemetry transmission at import time.
dist/telemetry/events/swc-load-failure.js medium No malicious patterns detected; the file contains expected Next.js telemetry reporting logic with minor dynamic require and data collection concerns.
dist/telemetry/events/swc-plugins.js medium This appears to be legitimate Next.js telemetry code for detecting SWC plugins in package.json dependencies, with minor concerns around dynamic require and filesystem traversal that are consistent with its intended purpose rather than malicious intent.
dist/telemetry/events/version.js medium No malicious patterns such as exfiltration, credential harvesting, obfuscated code execution, backdoors, or process spawning were detected; the file is a benign telemetry event builder with limited privacy implications due to collected configuration and environment metadata.
dist/telemetry/post-telemetry-payload.js medium The code is a legitimate Next.js telemetry sender that exfiltrates data to an external endpoint, which is expected behavior but poses a medium risk due to unvalidated payload transmission.
dist/telemetry/project-id.js medium Code is not clearly malicious but executes a shell command to read git remote URL and accesses environment variables for telemetry project identification, which warrants caution.
dist/telemetry/storage.js medium This is Next.js's official telemetry implementation that intentionally collects and transmits anonymous usage data; it is not malicious but represents a privacy/data-exfiltration concern that should be controlled via NEXT_TELEMETRY_DISABLED.
dist/trace/report/index.js medium The file itself appears to be a benign reporting aggregator, but the included 'to-telemetry' reporter raises data exfiltration concerns that require inspection of its implementation.
dist/trace/shared.js medium The code appears to be a legitimate tracing utility with no clear malicious intent, but it does access environment variables and pollutes the global namespace, which are minor security concerns.
dist/trace/trace-uploader.js medium This is Next.js's trace uploader: it collects build trace data and project metadata and POSTs it to an argv-supplied URL, which is intended telemetry behavior but technically constitutes outbound data transmission of project/git metadata to a caller-controlled endpoint, warranting a warning rather than a clean safe rating.
dist/trace/upload-trace.js medium This module spawns a detached child process to upload trace and telemetry data (including project paths and persistent identifiers) to a caller-supplied remote URL, which is a privacy/data-exfiltration concern despite appearing to be legitimate Next.js telemetry code.
root-params.js medium No malicious patterns detected; the module is a harmless compiler placeholder that throws an error on import.
app.js safe Cleared by Jev triage; no further analysis needed
babel.js safe Cleared by Jev triage; no further analysis needed
cache.js safe This is a legitimate Next.js cache module that conditionally exports server/client caching utilities using standard require() calls, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or shell execution.
client.js safe Cleared by Jev triage; no further analysis needed
compat/router.js safe Cleared by Jev triage; no further analysis needed
constants.js safe Cleared by Jev triage; no further analysis needed
dist/api/app-dynamic.js safe The file is a simple re-export module that only forwards exports from a shared internal library, with no suspicious or malicious code patterns.
dist/api/app.js safe No malicious patterns detected; this is a simple re-export module pointing to a local _app file with no external network, process, filesystem, or dynamic code execution behavior.
dist/api/constants.js safe This file is a simple re-export of constants from a shared library with no malicious patterns detected.
dist/api/document.js safe No malicious patterns detected; the file only re-exports a local _document module.
dist/api/dynamic.js safe No malicious patterns detected
dist/api/error.js safe This file only contains standard re-export statements with no malicious patterns detected
dist/api/error.react-server.js safe No malicious patterns detected
dist/api/form.js safe No malicious patterns detected
dist/api/head.js safe No malicious patterns detected
dist/api/headers.js safe No malicious patterns detected
dist/api/image.js safe This file only re-exports an image library from a shared internal module with no suspicious code patterns.
dist/api/link.js safe No malicious patterns detected
dist/api/navigation.js safe No malicious patterns detected; the file is a simple re-export from a local client component.
dist/api/navigation.react-server.js safe No malicious patterns detected
dist/api/og.js safe No malicious patterns detected
dist/api/router.js safe This is a simple re-export module that only re-exports from a relative client router module, with no malicious patterns detected.
dist/api/script.js safe No malicious patterns detected
dist/api/server.js safe No malicious patterns detected; the file only re-exports from an internal module.
dist/build/adapter/build-complete.js safe This is a legitimate Next.js build adapter module that processes build outputs, traces file dependencies, and invokes adapter callbacks; no malicious patterns, data exfiltration, credential harvesting, or backdoor code detected.
dist/build/adapter/setup-node-env.external.js safe No malicious patterns detected; the file only conditionally imports standard Next.js internal server environment modules.
dist/build/after-production-compile.js safe No malicious patterns detected
dist/build/analysis/extract-const-value.js safe No malicious patterns detected
dist/build/analysis/get-page-static-info.js safe No malicious patterns detected; this is a legitimate Next.js static page analysis module that reads local page files, parses ASTs, and parses route segment configurations.
dist/build/analysis/parse-module.js safe No malicious patterns detected
dist/build/analyze/index.js safe This is legitimate Next.js bundle analyzer source code with no malicious patterns; it only performs local file operations, starts a localhost server, and records telemetry events.
dist/build/babel/loader/get-config.js safe This is legitimate Next.js Babel loader configuration code with no malicious patterns detected.
dist/build/babel/loader/index.js safe This is a legitimate Next.js Babel loader that transforms source code using webpack's loader API and contains no malicious patterns.
dist/build/babel/loader/transform.js safe No malicious patterns detected; the file is a legitimate Babel transformation loader adapted from @babel/core.
dist/build/babel/loader/util.js safe No malicious patterns detected
dist/build/babel/plugins/commonjs.js safe The code is a standard Babel plugin wrapper for CommonJS transformation, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
dist/build/babel/plugins/jsx-pragma.js safe No malicious patterns detected; this is a standard Babel JSX pragma plugin for Next.js with no external network, filesystem, or process manipulation.
dist/build/babel/plugins/next-font-unsupported.js safe No malicious patterns detected; the code is a standard Babel plugin that throws an error when next/font imports are used, with no data exfiltration, credential harvesting, obfuscation, network activity, or process execution.
dist/build/babel/plugins/next-page-config.js safe No malicious patterns detected; the file is a Next.js Babel plugin that validates page config exports at build time and contains no network, filesystem, process, or code execution behavior.
dist/build/babel/plugins/next-page-disallow-re-export-all-exports.js safe This is a standard Next.js Babel plugin that only validates and rejects invalid export * from syntax in page components, with no malicious patterns such as network access, process spawning, credential harvesting, or dynamic code execution.
dist/build/babel/plugins/next-ssg-transform.js safe No malicious patterns detected; the code is a legitimate Next.js Babel plugin for transforming SSG/SSR exports.
dist/build/babel/plugins/optimize-hook-destructuring.js safe No malicious patterns detected
dist/build/babel/plugins/react-loadable-plugin.js safe This is a legitimate Babel plugin for Next.js dynamic imports with no malicious patterns detected.
dist/build/babel/preset.js safe This is a legitimate Next.js Babel preset configuration file with no malicious patterns detected; all require() calls use static strings, no eval/exec, no network requests, no credential harvesting, and no install-time hooks.
dist/build/browser-variant-modules.js safe No malicious patterns detected; the file is a generated static list of module paths with no dynamic code execution, network access, or filesystem manipulation.
dist/build/build-context.js safe No malicious patterns detected; the file contains benign internal state management utilities for Next.js build process.
dist/build/compiler.js safe No malicious patterns detected
dist/build/create-compiler-aliases.js safe This is a legitimate Next.js build configuration file that only defines webpack alias mappings and module path resolutions, with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, network requests, or process spawning.
dist/build/define-env.js safe No malicious patterns detected
dist/build/duration-to-string.js safe No malicious patterns detected; the code only contains pure utility functions for formatting time durations.
dist/build/entries.js safe No malicious patterns detected; the code is a legitimate Next.js build utility for creating webpack entrypoints.
dist/build/file-classifier.js safe No malicious patterns detected; the file only contains pure functions for extracting and combining route slot metadata.
dist/build/generate-build-id.js safe No malicious patterns detected; the code is a benign utility function for generating a build ID with fallback logic and input validation.
dist/build/generate-routes-manifest.js safe No malicious patterns detected; the code is a legitimate Next.js routes manifest generator with no network, filesystem, process, or obfuscated behavior.
dist/build/get-babel-config-file.js safe No malicious patterns detected; the code only searches for Babel configuration files in a given directory using path.join and fs.existsSync.
dist/build/get-babel-loader-config.js safe No malicious patterns detected; the code is a standard Babel loader configuration utility for Next.js with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/build/get-static-info-including-layouts.js safe No malicious patterns detected; the code performs local file system checks and static config inheritance for Next.js pages and layouts.
dist/build/get-supported-browsers.js safe No malicious patterns detected; the file is a standard Next.js utility that resolves supported browsers via browserslist with no network, filesystem, process, or dynamic execution risks.
dist/build/handle-entrypoints.js safe No malicious patterns detected; the file contains standard Next.js internal entrypoint handling logic with no exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
dist/build/handle-externals.js safe No malicious patterns detected; the code is a legitimate Next.js webpack external handling module with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/build/is-writeable.js safe This utility simply checks whether a directory is writeable using fs.access with no malicious behavior, external calls, or suspicious patterns.
dist/build/jest/__mocks__/empty.js safe No malicious patterns detected
dist/build/jest/__mocks__/fileMock.js safe No malicious patterns detected; the file is a standard Jest mock for static file imports.
dist/build/jest/__mocks__/nextFontMock.js safe This is a standard Next.js font mock file for Jest testing that uses a Proxy to return mock font objects with no network, filesystem, process, or dynamic code execution activity.
dist/build/jest/__mocks__/styleMock.js safe No malicious patterns detected
dist/build/jest/jest.js safe No malicious patterns detected; this is a legitimate Next.js Jest configuration helper that loads environment variables and configuration files without exfiltration, obfuscation, or suspicious system calls.
dist/build/jest/object-proxy.js safe The file implements a benign Proxy-based mock object for CSS module imports in Jest tests, with no network, filesystem, process, or credential access patterns.
dist/build/load-entrypoint.js safe No malicious patterns detected; the code is a legitimate Next.js build artifact that reads local template files and expands them using a SWC binding.
dist/build/load-jsconfig.js safe No malicious patterns detected
dist/build/lockfile.js safe No malicious patterns detected
dist/build/manifests/formatter/format-manifest.js safe No malicious patterns detected; the file only performs standard JSON serialization of a manifest object.
dist/build/next-dir-paths.js safe No malicious patterns detected
dist/build/normalize-catchall-routes.js safe No malicious patterns detected
dist/build/output/format.js safe No malicious patterns detected; the code only formats cache-control time values using simple arithmetic and string interpolation.
dist/build/output/index.js safe No malicious patterns detected; the code is a standard Next.js build monitoring module with no network, filesystem, or process manipulation.
dist/build/output/log.js safe No malicious patterns detected
dist/build/output/store.js safe No malicious patterns detected; the file is a standard Next.js dev-build store module with no exfiltration, obfuscation, credential harvesting, or command execution.
dist/build/page-extensions-type.js safe No malicious patterns detected
dist/build/polyfills/fetch/index.js safe No malicious patterns detected
dist/build/polyfills/fetch/whatwg-fetch.js safe This file is a simple polyfill re-exporting fetch API globals from self, with no suspicious or malicious patterns detected.
dist/build/polyfills/object-assign.js safe No malicious patterns detected
dist/build/polyfills/object.assign/auto.js safe No malicious patterns detected
dist/build/polyfills/object.assign/implementation.js safe No malicious patterns detected
dist/build/polyfills/object.assign/index.js safe No malicious patterns detected
dist/build/polyfills/object.assign/polyfill.js safe No malicious patterns detected
dist/build/polyfills/object.assign/shim.js safe No malicious patterns detected
dist/build/polyfills/polyfill-module.js safe No malicious patterns detected; the code only contains standard polyfills for modern JavaScript methods.
dist/build/polyfills/process.js safe No malicious patterns detected; the file is a benign Next.js process polyfill with no exfiltration, obfuscation, or suspicious network/process activity.
dist/build/preview-key-utils.js safe The code is a legitimate Next.js utility for generating and caching preview mode cryptographic keys; no malicious patterns such as exfiltration, obfuscation, network requests, or process spawning were detected.
dist/build/print-build-errors.js safe No malicious patterns detected
dist/build/progress.js safe The code is a benign progress bar utility with no malicious patterns, network requests, credential harvesting, or dynamic code execution.
dist/build/rendering-mode.js safe No malicious patterns detected
dist/build/segment-config/app/app-segment-config.js safe No malicious patterns detected; the file is a standard Zod schema definition for Next.js app segment configuration with no network, filesystem, process, or dynamic execution behavior.
dist/build/segment-config/app/app-segments.js safe No malicious patterns detected; the code is legitimate Next.js internal logic for collecting app segment configurations.
dist/build/segment-config/app/collect-root-param-keys.js safe No malicious patterns detected; the code is a standard Next.js internal utility for collecting route parameter keys.
dist/build/segment-config/middleware/middleware-config.js safe No malicious patterns detected; the code defines Zod validation schemas for Next.js middleware configuration without any exfiltration, code execution, or suspicious behavior.
dist/build/segment-config/pages/pages-segment-config.js safe No malicious patterns detected; the file only defines a Zod schema and a parse function for Next.js page segment configuration.
dist/build/sort-by-page-exts.js safe No malicious patterns detected
dist/build/spinner.js safe No malicious patterns detected; the code is a standard Next.js build artifact implementing a terminal spinner with console log capture.
dist/build/static-paths/app.js safe This is Next.js framework code for static path generation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution detected.
dist/build/static-paths/app/extract-pathname-route-param-segments-from-loader-tree.js safe No malicious patterns detected; the code is a legitimate Next.js utility for extracting route parameters from a loader tree.
dist/build/static-paths/pages.js safe No malicious patterns detected; this is standard Next.js build-time logic for processing getStaticPaths results with input validation and path escaping.
dist/build/static-paths/types.js safe No malicious patterns detected
dist/build/static-paths/utils.js safe No malicious patterns detected; the file contains standard Next.js routing utility functions with no network, filesystem, process, or dynamic code execution concerns.
dist/build/swc/helpers.js safe No malicious patterns detected
dist/build/swc/install-bindings.js safe No malicious patterns detected
dist/build/swc/jest-transformer.js safe No malicious patterns detected
dist/build/swc/options.js safe No malicious patterns detected; the file is a legitimate Next.js SWC options builder that resolves plugin paths from user configuration and constructs compiler options without exfiltration, credential harvesting, obfuscation, or shell execution.
dist/build/swc/types.js safe No malicious patterns detected
dist/build/templates/app-page.js safe No malicious patterns detected; this is a legitimate Next.js app-page template with build-time template placeholders and no suspicious runtime behavior.
dist/build/templates/app-route.js safe This is legitimate Next.js framework code for an App Router route handler; no malicious patterns such as exfiltration, credential harvesting, shell execution, or obfuscated payloads were found.
dist/build/templates/edge-app-route.js safe No malicious patterns detected; this is a legitimate Next.js internal edge route module template with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/build/templates/edge-ssr-app.js safe This is a legitimate Next.js Edge SSR runtime template with no malicious patterns detected; dynamic requires use build-time placeholders (VAR_USERLAND, VAR_PAGE) and there is no exfiltration, credential harvesting, obfuscation, or shell execution.
dist/build/templates/edge-ssr.js safe No malicious patterns detected; the file is a legitimate Next.js Edge SSR template with standard module imports, request handling, and rendering logic.
dist/build/templates/helpers.js safe No malicious patterns detected; the file only contains a benign module hoisting utility with no I/O, network, process, or dynamic execution behavior.
dist/build/templates/middleware.js safe This is a standard Next.js middleware template generated by the framework; it contains no malicious patterns, external data exfiltration, credential harvesting, obfuscation, or dynamic code execution beyond normal module loading.
dist/build/templates/pages-api.js safe This is a legitimate Next.js build template for Pages API routes with no malicious patterns detected.
dist/build/templates/pages-edge-api.js safe No malicious patterns detected; the file is a standard Next.js edge API page template with only placeholder substitutions and internal framework imports.
dist/build/templates/pages.js safe No malicious patterns detected; this is a standard Next.js build artifact for page route modules with no obfuscation, exfiltration, or dangerous dynamic execution.
dist/build/turbopack-analyze/index.js safe No malicious patterns detected; the file is a legitimate Next.js Turbopack analysis module using expected imports, native bindings, and project lifecycle operations.
dist/build/turbopack-build/impl.js safe This is legitimate Next.js Turbopack build orchestration code with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution.
dist/build/turbopack-build/index.js safe No malicious patterns detected; the code is a legitimate Turbopack build orchestration module using workers and environment variables for build configuration.
dist/build/turborepo-access-trace/index.js safe The module is a simple re-export of local helper and result modules with no suspicious behavior, network activity, or credential access.
dist/build/turborepo-access-trace/result.js safe No malicious patterns detected; the file is a straightforward data-container class for tracking environment variables, filesystem paths, and network addresses without any exfiltration, code execution, or filesystem manipulation.
dist/build/turborepo-access-trace/types.js safe The file contains only TypeScript type definitions and module boilerplate with no executable or malicious code.
dist/build/type-check.js safe This is a legitimate Next.js build utility for running TypeScript type checking in a worker; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected.
dist/build/utils.js safe No malicious patterns detected; the file is a legitimate Next.js build utility with expected filesystem, tracing, and static-analysis logic.
dist/build/validate-app-paths.js safe The code is a Next.js internal route validation module that only manipulates strings and throws descriptive errors, with no network, filesystem, process, or dynamic execution activity.
dist/build/warn-about-edge-runtime.js safe No malicious patterns detected
dist/build/webpack-build/impl.js safe No malicious patterns detected; this is legitimate Next.js webpack build orchestration code with no exfiltration, credential harvesting, or dynamic code execution.
dist/build/webpack-config-rules/resolve.js safe No malicious patterns detected; the file only defines module resolution field preferences for a webpack configuration.
dist/build/webpack/alias/react-dom-server-experimental.js safe This is a Next.js internal compatibility shim for react-dom/server APIs with conditional requires based on environment variables; no malicious patterns detected.
dist/build/webpack/cache-invalidation.js safe No malicious patterns detected
dist/build/webpack/config/blocks/base.js safe No malicious patterns detected; the code is a standard Next.js webpack configuration module with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
dist/build/webpack/config/blocks/css/index.js safe No malicious patterns detected; the code is a legitimate Next.js webpack CSS configuration module.
dist/build/webpack/config/blocks/css/loaders/client.js safe No malicious patterns detected; the code is a standard Next.js webpack CSS loader configuration.
dist/build/webpack/config/blocks/css/loaders/file-resolve.js safe No malicious patterns detected; the code is a simple URL resolution utility with no network, filesystem, process, or dynamic execution behavior.
dist/build/webpack/config/blocks/css/loaders/getCssModuleLocalIdent.js safe No malicious patterns detected; this is a legitimate Next.js utility for generating CSS module local class names using safe path, hashing, and string operations.
dist/build/webpack/config/blocks/css/loaders/global.js safe The file is a standard webpack CSS loader configuration from Next.js with no malicious patterns or security concerns detected.
dist/build/webpack/config/blocks/css/loaders/index.js safe No malicious patterns detected; the file only re-exports CSS loader modules from sibling files using standard CommonJS export patterns.
dist/build/webpack/config/blocks/css/loaders/modules.js safe No malicious patterns detected; the file is a standard webpack CSS loader configuration module for Next.js.
dist/build/webpack/config/blocks/css/loaders/next-font.js safe No malicious patterns detected; this is a legitimate Next.js internal webpack loader configuration module with no data exfiltration, dynamic code execution, process spawning, or suspicious file system access.
dist/build/webpack/config/blocks/css/messages.js safe No malicious patterns detected
dist/build/webpack/config/blocks/images/index.js safe No malicious patterns detected; this is a standard Next.js webpack image configuration module with only static loader rules and no network, filesystem, or shell access.
dist/build/webpack/config/blocks/images/messages.js safe No malicious patterns detected; the file only exports a static error message helper using picocolors for terminal formatting.
dist/build/webpack/config/helpers.js safe No malicious patterns detected
dist/build/webpack/config/index.js safe This is a standard Next.js webpack configuration builder with no malicious patterns detected.
dist/build/webpack/config/utils.js safe The file contains only a simple pipe utility function with no malicious patterns, network activity, file system access, or dynamic code execution.
dist/build/webpack/loaders/css-loader/src/CssSyntaxError.js safe No malicious patterns detected; the file only defines a CSS syntax error class for webpack's css-loader.
dist/build/webpack/loaders/css-loader/src/camelcase.js safe No malicious patterns detected
dist/build/webpack/loaders/css-loader/src/index.js safe No malicious patterns detected; this is a legitimate css-loader module that normalizes options and processes CSS with PostCSS without any exfiltration, code execution, or suspicious behavior.
dist/build/webpack/loaders/css-loader/src/plugins/index.js safe This is a standard webpack css-loader plugin index file that only re-exports three PostCSS parser modules with no malicious patterns, network activity, file system access, or dynamic code execution.
dist/build/webpack/loaders/css-loader/src/plugins/postcss-icss-parser.js safe No malicious patterns detected; the code is a legitimate PostCSS plugin for handling ICSS imports/exports in Next.js's bundled CSS loader.
dist/build/webpack/loaders/css-loader/src/plugins/postcss-import-parser.js safe No malicious patterns detected; the file is a standard PostCSS @import parser from Next.js's bundled css-loader with no exfiltration, code execution, or process spawning behavior.
dist/build/webpack/loaders/css-loader/src/plugins/postcss-url-parser.js safe No malicious patterns detected; the code is a standard PostCSS URL parser plugin used for CSS URL resolution.
dist/build/webpack/loaders/css-loader/src/runtime/api.js safe No malicious patterns detected; this is a standard css-loader runtime file that builds CSS strings and source map comments without any exfiltration, code execution, or process spawning.
dist/build/webpack/loaders/css-loader/src/runtime/getUrl.js safe No malicious patterns detected; the file is a legitimate css-loader runtime utility for normalizing CSS url() values.
dist/build/webpack/loaders/css-loader/src/utils.js safe This is a legitimate css-loader utility module from Next.js's bundled webpack loader; no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution were detected.
dist/build/webpack/loaders/devtool/devtool-style-inject.js safe No malicious patterns detected; the code is a legitimate Next.js devtools style injection utility that uses DOM APIs and MutationObserver without any data exfiltration, credential harvesting, dynamic code execution, or network activity.
dist/build/webpack/loaders/empty-loader.js safe No malicious patterns detected
dist/build/webpack/loaders/error-loader.js safe No malicious patterns detected; the file is a standard webpack error loader for emitting build errors.
dist/build/webpack/loaders/get-module-build-info.js safe No malicious patterns detected
dist/build/webpack/loaders/instrumentation-client-stub.js safe No malicious patterns detected
dist/build/webpack/loaders/lightningcss-loader/src/codegen.js safe No malicious patterns detected; this is standard webpack CSS loader code generation logic with no external network, filesystem, or process access.
dist/build/webpack/loaders/lightningcss-loader/src/index.js safe No malicious patterns detected; the file is a standard webpack loader entry point that only re-exports local modules.
dist/build/webpack/loaders/lightningcss-loader/src/interface.js safe No malicious patterns detected
dist/build/webpack/loaders/lightningcss-loader/src/loader.js safe The lightningcss-loader code is a standard Next.js webpack CSS loader with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized network/file/process operations.
dist/build/webpack/loaders/lightningcss-loader/src/minify.js safe No malicious patterns detected; the file is a legitimate webpack CSS minification plugin that uses lightningcss and swc bindings for asset optimization.
dist/build/webpack/loaders/lightningcss-loader/src/utils.js safe No malicious patterns detected; the code performs benign browserslist-to-lightningcss target version conversion with caching.
dist/build/webpack/loaders/metadata/discover.js safe This is legitimate Next.js metadata discovery code with no malicious patterns; it only performs file enumeration and constructs webpack import paths for static metadata images.
dist/build/webpack/loaders/metadata/types.js safe No malicious patterns detected
dist/build/webpack/loaders/modularize-import-loader.js safe No malicious patterns detected; this is a standard Next.js webpack loader that generates re-export statements using locally resolved paths.
dist/build/webpack/loaders/next-app-loader/create-app-route-code.js safe No malicious patterns detected; the code is a legitimate Next.js internal webpack loader helper that resolves app route paths and loads entrypoints without any suspicious behavior.
dist/build/webpack/loaders/next-app-loader/index.js safe This is a legitimate Next.js internal webpack loader that performs file system operations and path resolution only within the app directory, with no malicious patterns detected.
dist/build/webpack/loaders/next-barrel-loader.js safe This is a legitimate Next.js Webpack loader for barrel file import optimization; no malicious patterns such as data exfiltration, credential harvesting, code execution, or process spawning were detected.
dist/build/webpack/loaders/next-client-pages-loader.js safe This is a standard Next.js webpack loader that generates client-side page registration code; no malicious patterns detected.
dist/build/webpack/loaders/next-edge-app-route-loader/index.js safe This is a legitimate Next.js webpack loader that transforms app route modules for edge runtime; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity were detected.
dist/build/webpack/loaders/next-edge-ssr-loader/index.js safe This is a standard Next.js webpack loader that generates edge SSR bundles and contains no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution beyond legitimate build-time operations.
dist/build/webpack/loaders/next-error-browser-binary-loader.js safe No malicious patterns detected
dist/build/webpack/loaders/next-flight-action-entry-loader.js safe No malicious patterns detected; the file is a standard Next.js webpack loader that re-exports server actions.
dist/build/webpack/loaders/next-flight-client-entry-loader.js safe This is a legitimate Next.js webpack loader that transforms module import statements for client entry points without any malicious patterns, data exfiltration, or code execution.
dist/build/webpack/loaders/next-flight-client-module-loader.js safe This is a legitimate Next.js webpack loader for React Server Components that transforms source code and manages build metadata without any malicious patterns.
dist/build/webpack/loaders/next-flight-css-loader.js safe No malicious patterns detected; the file is a standard Next.js Webpack loader that computes a SHA1 checksum for CSS HMR and contains no exfiltration, obfuscation, network, filesystem, or process-spawning behavior.
dist/build/webpack/loaders/next-flight-loader/action-client-wrapper.js safe No malicious patterns detected; the file is a standard Next.js re-export wrapper with only static requires and no dynamic or suspicious behavior.
dist/build/webpack/loaders/next-flight-loader/action-validate.js safe No malicious patterns detected; the file only performs a runtime type check on server action exports.
dist/build/webpack/loaders/next-flight-loader/cache-wrapper.js safe No malicious patterns detected; the file only re-exports the cache binding from an internal Next.js module.
dist/build/webpack/loaders/next-flight-loader/index.js safe No malicious patterns detected; this is a legitimate Next.js webpack loader for React Server Components with no exfiltration, credential harvesting, obfuscation, or suspicious execution.
dist/build/webpack/loaders/next-flight-loader/module-proxy.js safe No malicious patterns detected; the file is a simple re-export of createClientModuleProxy from react-server-dom-webpack/server.
dist/build/webpack/loaders/next-flight-loader/server-reference.js safe No malicious patterns detected; the file is a simple re-export module for a React server reference registration API.
dist/build/webpack/loaders/next-flight-loader/track-dynamic-import.js safe This file is a simple re-export shim for the Next.js trackDynamicImport utility and contains no malicious patterns.
dist/build/webpack/loaders/next-flight-server-reference-proxy-loader.js safe This is a legitimate Next.js Webpack loader that generates proxy modules for React Server Components; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or shell execution.
dist/build/webpack/loaders/next-font-loader/postcss-next-font.js safe No malicious patterns detected; the file is a legitimate PostCSS plugin for next/font that only manipulates CSS AST nodes and exports font metadata.
dist/build/webpack/loaders/next-image-loader/blur.js safe No malicious patterns detected; the code is a legitimate Next.js image blur placeholder generator with no data exfiltration, obfuscation, or suspicious behavior.
dist/build/webpack/loaders/next-image-loader/index.js safe No malicious patterns detected; this is a legitimate Next.js webpack image loader with standard build-time functionality.
dist/build/webpack/loaders/next-invalid-import-error-loader.js safe This is a legitimate Next.js webpack loader that throws an error with a developer-provided message; no malicious patterns detected.
dist/build/webpack/loaders/next-metadata-image-loader.js safe This is the legitimate Next.js metadata image webpack loader; no malicious exfiltration, credential harvesting, obfuscation, process spawning, or backdoor patterns are present.
dist/build/webpack/loaders/next-metadata-route-loader.js safe No malicious patterns detected; this is a legitimate Next.js internal webpack loader that generates metadata route code and reads local resource files for favicon, sitemap, robots, and OpenGraph image handling.
dist/build/webpack/loaders/next-middleware-asset-loader.js safe No malicious patterns detected; the file is a standard Next.js webpack loader for emitting middleware asset files.
dist/build/webpack/loaders/next-middleware-wasm-loader.js safe No malicious patterns detected; this is a standard Webpack loader for Next.js middleware WASM files.
dist/build/webpack/loaders/next-root-params-loader.js safe No malicious patterns detected
dist/build/webpack/loaders/next-route-loader/index.js safe This is a standard Next.js webpack route loader file with no malicious patterns detected.
dist/build/webpack/loaders/next-style-loader/index.js safe No malicious patterns detected; this is a legitimate webpack loader for Next.js style injection with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoLinkTag.js safe No malicious patterns detected; this is a standard Next.js/webpack style loader runtime that injects stylesheets into link tags with no data exfiltration, code execution, or suspicious behavior.
dist/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoStyleTag.js safe No malicious patterns detected; this is a legitimate Next.js/webpack style loader runtime that dynamically injects CSS into the DOM with no network, filesystem, process, or credential access.
dist/build/webpack/loaders/next-style-loader/runtime/isEqualLocals.js safe No malicious patterns detected
dist/build/webpack/loaders/next-swc-loader.js safe No malicious patterns detected; the file is a legitimate Next.js SWC webpack loader that performs source transformation without any exfiltration, credential harvesting, obfuscation, or suspicious system interaction.
dist/build/webpack/loaders/postcss-loader/src/Error.js safe No malicious patterns detected
dist/build/webpack/loaders/postcss-loader/src/Warning.js safe No malicious patterns detected
dist/build/webpack/loaders/postcss-loader/src/index.js safe This is a legitimate PostCSS webpack loader implementation that processes CSS files without any malicious patterns such as data exfiltration, credential harvesting, obfuscated code, cryptocurrency mining, backdoors, or unauthorized file system/network access.
dist/build/webpack/loaders/postcss-loader/src/utils.js safe The code only normalizes source map paths using path utilities and does not contain any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
dist/build/webpack/loaders/resolve-url-loader/index.js safe No malicious patterns detected; this is a legitimate webpack loader for resolving url() paths with standard source-map and postcss usage.
dist/build/webpack/loaders/resolve-url-loader/lib/file-protocol.js safe No malicious patterns detected; the file only provides utility functions for prepending and removing the file:// protocol from source map paths.
dist/build/webpack/loaders/resolve-url-loader/lib/join-function.js safe No malicious patterns detected; the file implements a path-joining utility for webpack's resolve-url-loader with only filesystem existence checks and debug logging.
dist/build/webpack/loaders/resolve-url-loader/lib/postcss.js safe No malicious patterns detected; this is a legitimate PostCSS plugin for resolving url() references in CSS source maps.
dist/build/webpack/loaders/resolve-url-loader/lib/value-processor.js safe No malicious patterns detected; the code is a legitimate webpack loader utility for resolving CSS url() references.
dist/build/webpack/loaders/utils.js safe No malicious patterns detected; the code contains standard webpack utility functions for handling module exports, CSS detection, and base64 encoding/decoding.
dist/build/webpack/plugins/build-manifest-plugin-utils.js safe No malicious patterns detected; the code is a standard Next.js build-manifest utility with no network, credential, obfuscation, or process-spawning behavior.
dist/build/webpack/plugins/build-manifest-plugin.js safe No malicious patterns detected; the code is a standard Next.js webpack plugin for generating build manifests.
dist/build/webpack/plugins/copy-file-plugin.js safe The CopyFilePlugin is a legitimate webpack plugin that reads a file and emits it as an asset during compilation, with no malicious patterns detected.
dist/build/webpack/plugins/css-chunking-plugin.js safe No malicious patterns detected; the code is a legitimate webpack plugin for CSS chunk optimization with no network, filesystem, or process execution activities.
dist/build/webpack/plugins/css-minimizer-plugin.js safe No malicious patterns detected
dist/build/webpack/plugins/deferred-entries-plugin.js safe This is a standard Next.js webpack plugin that registers deferred entry points during the build process; no malicious patterns, network calls, credential access, or dynamic code execution were detected.
dist/build/webpack/plugins/devtools-ignore-list-plugin.js safe No malicious patterns detected
dist/build/webpack/plugins/eval-source-map-dev-tool-plugin.js safe This is a legitimate fork of webpack's EvalSourceMapDevToolPlugin used by Next.js to add ignoreList support for source maps; it contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or suspicious process/network activity.
dist/build/webpack/plugins/flight-client-entry-plugin.js safe No malicious patterns detected; this is a legitimate Next.js webpack plugin for handling client entry points and server actions.
dist/build/webpack/plugins/flight-manifest-plugin.js safe This is a legitimate Next.js webpack plugin that generates client reference manifests for React Server Components; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, dynamic execution, or suspicious network/filesystem activity were detected.
dist/build/webpack/plugins/force-complete-runtime.js safe No malicious patterns detected; the code is a legitimate Next.js webpack plugin that adjusts chunk runtime requirements.
dist/build/webpack/plugins/jsconfig-paths-plugin.js safe No malicious patterns detected; the file implements a standard webpack resolver plugin for TypeScript/JavaScript path aliases without any suspicious behavior.
dist/build/webpack/plugins/memory-with-gc-cache-plugin.js safe No malicious patterns detected; the file implements a legitimate webpack memory cache plugin with TTL-based eviction.
dist/build/webpack/plugins/middleware-plugin.js safe This is a legitimate Next.js webpack plugin for analyzing Edge Runtime middleware code; no malicious patterns such as data exfiltration, credential harvesting, or backdoor installation were detected.
dist/build/webpack/plugins/mini-css-extract-plugin.js safe No malicious patterns detected; the file is a thin, legitimate wrapper around Next.js's bundled mini-css-extract-plugin that only subclasses it and sets a marker property.
dist/build/webpack/plugins/minify-webpack-plugin/src/index.js safe No malicious patterns detected
dist/build/webpack/plugins/next-font-manifest-plugin.js safe No malicious patterns detected; the code is a standard Next.js webpack plugin that builds a font manifest during compilation.
dist/build/webpack/plugins/next-trace-entrypoints-plugin.js safe No malicious patterns detected; this is a legitimate Next.js webpack plugin that performs file tracing and dependency resolution using @vercel/nft.
dist/build/webpack/plugins/next-types-plugin/index.js safe This is a legitimate Next.js internal webpack plugin that generates TypeScript type definitions for app routes; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or unauthorized system access were detected.
dist/build/webpack/plugins/next-types-plugin/shared.js safe No malicious patterns detected; the file only defines a simple exported Set for tracking dev page files.
dist/build/webpack/plugins/nextjs-require-cache-hot-reloader.js safe No malicious patterns detected; this is a legitimate Next.js webpack hot-reload plugin that clears the require cache and sandbox module context for emitted assets.
dist/build/webpack/plugins/optional-peer-dependency-resolve-plugin.js safe No malicious patterns detected
dist/build/webpack/plugins/pages-manifest-plugin.js safe No malicious patterns detected; the file is a standard Next.js webpack plugin that generates pages-manifest.json without network, credential, process, or obfuscated code activity.
dist/build/webpack/plugins/profiling-plugin.js safe No malicious patterns detected
dist/build/webpack/plugins/react-loadable-plugin.js safe No malicious patterns detected; this is a legitimate Next.js webpack plugin for generating react-loadable manifests.
dist/build/webpack/plugins/rspack-flight-client-entry-plugin.js safe No malicious patterns detected; the file is a legitimate Next.js Rspack plugin implementation with only local module imports and standard build tooling logic.
dist/build/webpack/plugins/rspack-profiling-plugin.js safe No malicious patterns detected
dist/build/webpack/plugins/slow-module-detection-plugin.js safe This is a legitimate Next.js webpack plugin that measures module build times and prints a report to the console; it contains no network, filesystem, process, or dynamic code execution behavior.
dist/build/webpack/plugins/subresource-integrity-plugin.js safe No malicious patterns detected
dist/build/webpack/plugins/telemetry-plugin/telemetry-plugin.js safe No malicious patterns detected; the file implements a webpack telemetry plugin that only tracks module usage internally without any external data exfiltration, credential access, or dangerous dynamic execution.
dist/build/webpack/plugins/telemetry-plugin/update-telemetry-loader-context-from-swc.js safe No malicious patterns detected; the code only parses telemetry data and updates in-memory context objects.
dist/build/webpack/plugins/telemetry-plugin/use-cache-tracker-utils.js safe No malicious patterns detected
dist/build/webpack/plugins/wellknown-errors-plugin/getModuleTrace.js safe No malicious patterns detected; the code is a legitimate webpack error-trace formatting utility from Next.js with no network, filesystem, process, or credential-access activity.
dist/build/webpack/plugins/wellknown-errors-plugin/index.js safe The code is a webpack plugin that filters warnings and reformats module build errors; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution were detected.
dist/build/webpack/plugins/wellknown-errors-plugin/parse-dynamic-code-evaluation-error.js safe No malicious patterns detected; this is a benign webpack plugin utility that formats dynamic code evaluation error messages.
dist/build/webpack/plugins/wellknown-errors-plugin/parseBabel.js safe No malicious patterns detected
dist/build/webpack/plugins/wellknown-errors-plugin/parseCss.js safe No malicious patterns detected; the code only parses CSS error messages and formats them for webpack build output.
dist/build/webpack/plugins/wellknown-errors-plugin/parseNextAppLoaderError.js safe The code is a standard Next.js webpack plugin helper that parses loader errors and contains no malicious patterns.
dist/build/webpack/plugins/wellknown-errors-plugin/parseNextFontError.js safe No malicious patterns detected; the code is a standard Next.js webpack plugin that formats font-related build errors without network, filesystem, or process activity.
dist/build/webpack/plugins/wellknown-errors-plugin/parseNextInvalidImportError.js safe No malicious patterns detected; the code is a standard Next.js webpack error parsing utility with no network, filesystem, process, or dynamic execution behavior.
dist/build/webpack/plugins/wellknown-errors-plugin/parseNotFoundError.js safe No malicious patterns detected; the file only formats webpack errors for Next.js builds and contains no data exfiltration, obfuscation, dynamic execution, or suspicious network/file/process operations.
dist/build/webpack/plugins/wellknown-errors-plugin/parseScss.js safe No malicious patterns detected; the file only parses SCSS error messages and formats them for Webpack output.
dist/build/webpack/plugins/wellknown-errors-plugin/simpleWebpackError.js safe No malicious patterns detected
dist/build/webpack/plugins/wellknown-errors-plugin/webpackModuleError.js safe No malicious patterns detected
dist/build/webpack/stringify-request.js safe No malicious patterns detected
dist/build/webpack/utils.js safe No malicious patterns detected
dist/build/worker.js safe No malicious patterns detected; this is standard Next.js build worker code with no obfuscation, network calls, credential access, or suspicious lifecycle behavior.
dist/build/write-build-id.js safe No malicious patterns detected; the code simply writes a build ID file within the distribution directory.
dist/bundle-analyzer/_next/static/WF5Ql9w6rALUjSQk9e-fZ/_buildManifest.js safe No malicious patterns detected
dist/bundle-analyzer/_next/static/WF5Ql9w6rALUjSQk9e-fZ/_clientMiddlewareManifest.js safe No malicious patterns detected in the middleware manifest snippet.
dist/bundle-analyzer/_next/static/WF5Ql9w6rALUjSQk9e-fZ/_ssgManifest.js safe No malicious patterns detected; this is standard Next.js static site generation manifest initialization code.
dist/bundle-analyzer/_next/static/chunks/0.8z-24o~zj6q.js safe This is a standard Next.js/Turbopack bundle containing React and Next.js framework code with no malicious patterns detected.
dist/bundle-analyzer/_next/static/chunks/0nxgmn1p8~ej~.js safe This is a legitimate Next.js/Turbopack client-side bundle chunk containing React routing internals with no malicious patterns detected.
dist/bundle-analyzer/_next/static/chunks/turbopack-0_jd6_0ca14du.js safe This is a legitimate Turbopack runtime chunk loader for Next.js with no malicious patterns detected.
dist/cli/internal/query-trace.js safe The code is a CLI client that queries a local trace server via JSON-RPC over localhost; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution were detected.
dist/cli/internal/static-routes-info.js safe No malicious patterns detected; the code is a legitimate Next.js internal CLI for static route bundle analysis with no network, credential, or process execution behavior.
dist/cli/next-analyze.js safe No malicious patterns detected; the code is a standard Next.js CLI analyze command with expected file system and process signal handling.
dist/cli/next-build.js safe No malicious patterns detected; this is a legitimate Next.js CLI build entry point that only reads environment variables for debugging/tracing flags and does not exfiltrate data or execute untrusted code.
dist/cli/next-export.js safe No malicious patterns detected
dist/cli/next-post-build.js safe No malicious patterns detected; the file is a legitimate Next.js post-build utility that compacts a local Turbopack cache database.
dist/cli/next-request-insights.js safe No malicious patterns detected; the code only queries a local Next.js dev server for request insights and reads a project lockfile.
dist/cli/next-telemetry.js safe No malicious patterns detected; this is a legitimate Next.js telemetry preference management CLI.
dist/cli/next-typegen.js safe This is a legitimate Next.js CLI type generation script that only performs expected build-time tasks (route discovery, TypeScript setup verification, writing .d.ts files) with no malicious patterns, external network calls, credential harvesting, or suspicious process execution.
dist/client/add-base-path.js safe This is a standard Next.js utility module for prepending a base path to URLs, with no malicious patterns or security concerns detected.
dist/client/add-locale.js safe No malicious patterns detected; the code is a benign Next.js i18n helper that conditionally adds locale prefixes to paths.
dist/client/app-bootstrap.js safe The file is a legitimate Next.js client-side bootstrap module with no malicious patterns; dynamic script loading is standard framework behavior scoped to self.__next_s.
dist/client/app-call-server.js safe No malicious patterns detected; this is a legitimate React/Next.js client-side server action dispatcher.
dist/client/app-dir/form.js safe No malicious patterns detected; the code is a standard Next.js client-side Form component with expected navigation and validation logic.
dist/client/app-dir/link.js safe No malicious patterns detected
dist/client/app-dir/link.react-server.js safe No malicious patterns detected; the file is a standard Next.js Link component with only local module imports and console error logging.
dist/client/app-find-source-map-url.js safe This is a legitimate Next.js internal client utility for resolving source map URLs; it performs no network exfiltration, process spawning, credential harvesting, or dynamic code execution.
dist/client/app-globals.js safe This is a standard Next.js internal client globals file with conditional dynamic imports and setup calls that are scoped to the framework's dev/testing features, showing no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning.
dist/client/app-index.js safe No malicious patterns detected; this is standard Next.js App Router client hydration code.
dist/client/app-link-gc.js safe The code only performs client-side DOM cleanup of Next.js development link elements and contains no malicious patterns.
dist/client/app-next-dev.js safe This file is a standard Next.js development client bootstrap module with no malicious patterns detected.
dist/client/app-next-turbopack.js safe This is a standard Next.js Turbopack client bootstrap file; detected patterns are framework-internal dynamic requires and import-time hydration with no malicious indicators.
dist/client/app-next.js safe No malicious patterns detected; the file appears to be a standard Next.js client bootstrap module with legitimate require calls and no external data flows or dangerous operations.
dist/client/app-webpack.js safe No malicious patterns detected; the code only modifies webpack chunk filename handling using a deployment ID for legitimate asset URL construction.
dist/client/asset-prefix.js safe No malicious patterns detected; the code is a benign Next.js utility for computing asset prefix from the current script URL.
dist/client/assign-location.js safe No malicious patterns detected; the file only contains URL manipulation logic for relative path assignment.
dist/client/compat/router.js safe This is a standard Next.js router compatibility shim that only uses React context; no malicious patterns detected.
dist/client/components/app-router-announcer.js safe No malicious patterns detected; code is a legitimate Next.js accessibility component for route announcements.
dist/client/components/app-router-headers.js safe No malicious patterns detected
dist/client/components/app-router-instance.js safe This is a legitimate Next.js App Router client component that implements navigation, prefetching, and action queue management without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
dist/client/components/app-router-utils.js safe No malicious patterns detected in this Next.js utility module; it only provides URL helpers for prefetching and does not perform any suspicious behavior.
dist/client/components/bfcache-state-manager.js safe No malicious patterns detected; the code is a standard React hook for managing a back/forward cache with no security concerns.
dist/client/components/builtin/app-error.js safe No malicious patterns detected; this is the standard Next.js static 500 error page component that only renders HTML/CSS and React markup at build time.
dist/client/components/builtin/default-null.js safe This is a standard Next.js internal module that exports a simple null-returning component with no malicious patterns.
dist/client/components/builtin/default.js safe This is a benign Next.js internal module that exports a parallel route default component which simply calls notFound(); no malicious patterns detected.
dist/client/components/builtin/empty-stub.js safe No malicious patterns detected; the file is a simple empty React/JSX stub that only defines a null-returning component and harmless CommonJS interop boilerplate.
dist/client/components/builtin/error-styles.js safe No malicious patterns detected; the file only defines static error-page styles, a CSS theme string, and an SVG warning icon.
dist/client/components/builtin/forbidden.js safe No malicious patterns detected; the file is a benign React component for a 403 Forbidden error page with no network, filesystem, or dynamic code execution behavior.
dist/client/components/builtin/global-error.js safe No malicious patterns detected
dist/client/components/builtin/global-not-found.js safe No malicious patterns detected
dist/client/components/builtin/layout.js safe No malicious patterns detected; the file is a standard React/Next.js default layout component with no network, filesystem, process, or dynamic code execution behavior.
dist/client/components/builtin/not-found.js safe No malicious patterns detected
dist/client/components/builtin/unauthorized.js safe No malicious patterns detected
dist/client/components/catch-error.js safe No malicious patterns detected; this is a standard Next.js React error boundary component with no data exfiltration, credential harvesting, obfuscation, or process/network abuse.
dist/client/components/client-boundary-params.browser.js safe No malicious patterns detected; the file only re-exports browser-side params/searchParams helpers with no network, filesystem, eval, or process activity.
dist/client/components/client-boundary-params.js safe No malicious patterns detected; this is a standard Next.js internal module that re-exports param/searchParam helpers with no network, filesystem, process, or dynamic code execution behavior.
dist/client/components/client-page.js safe This is a standard Next.js client page component that only imports React context and route parameter utilities, with no malicious patterns detected.
dist/client/components/client-segment.js safe No malicious patterns detected; the file is a legitimate Next.js client component for segment rendering with no external calls, obfuscation, or process execution.
dist/client/components/dev-root-http-access-fallback-boundary.js safe No malicious patterns detected; the file is a standard Next.js development component with no network, filesystem, process, or dynamic code execution activity.
dist/client/components/error-boundary.js safe No malicious patterns detected
dist/client/components/errors/root-error-boundary.js safe No malicious patterns detected; the code is a standard React error boundary that conditionally renders based on bot user-agent detection.
dist/client/components/forbidden.js safe This is a legitimate Next.js internal module implementing the experimental forbidden() function, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning.
dist/client/components/handle-isr-error.js safe No malicious patterns detected; the code appears to be a legitimate error handler for Incremental Static Regeneration in Next.js.
dist/client/components/hooks-server-context.js safe No malicious patterns detected; the file only defines a custom error class and a validator function for Next.js dynamic server usage errors.
dist/client/components/http-access-fallback/error-boundary.js safe No malicious patterns detected; this is a standard Next.js React error boundary component with no data exfiltration, credential harvesting, obfuscation, network requests, or process spawning.
dist/client/components/http-access-fallback/error-fallback.js safe No malicious patterns detected; the file is a standard React error fallback component with a static inline style.
dist/client/components/http-access-fallback/http-access-fallback.js safe No malicious patterns detected; the file contains standard HTTP error fallback utilities for Next.js with no network, filesystem, credential access, or dynamic code execution.
dist/client/components/instant-samples.browser.js safe No malicious patterns detected
dist/client/components/instant-samples.js safe No malicious patterns detected; the code is a legitimate Next.js internal module for instrumenting route params and search params during client-side validation.
dist/client/components/instant-validation/boundary.js safe No malicious patterns detected; this is a standard Next.js client-side re-export module for validation boundary components.
dist/client/components/instant-validation/impl.browser.js safe This is a benign ES module export shim with no network, filesystem, process, or dynamic execution behavior; all exported values are null stubs.
dist/client/components/instant-validation/impl.js safe No malicious patterns detected
dist/client/components/is-next-router-error.js safe No malicious patterns detected
dist/client/components/links.js safe No malicious patterns detected; this is standard Next.js client-side link prefetching code with no data exfiltration, credential harvesting, obfuscation, or shell execution.
dist/client/components/match-segments.js safe No malicious patterns detected; the file contains a simple segment matching utility with no network, filesystem, or dynamic code execution activity.
dist/client/components/nav-failure-handler.js safe No malicious patterns detected; the code is a legitimate navigation failure handler from Next.js that recovers from errors by performing a hard navigation.
dist/client/components/navigation-devtools.js safe Legitimate Next.js dev-only instrumentation code with no malicious patterns, no network calls, no credential harvesting, and no dynamic code execution.
dist/client/components/navigation-dynamic-rendering.browser.js safe This is a benign browser stub module from Next.js that exports undefined placeholder hooks with no malicious patterns, network activity, or code execution.
dist/client/components/navigation-dynamic-rendering.js safe The module is a standard conditional re-export for browser/server code splitting in Next.js; it contains no network, filesystem, process, or code-execution activity.
dist/client/components/navigation-untracked.js safe The file contains standard React/Next.js internal navigation logic with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
dist/client/components/navigation.js safe This is a legitimate Next.js client navigation module that only re-exports React hooks and server navigation utilities without any malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or shell access.
dist/client/components/navigation.react-server.js safe No malicious patterns detected
dist/client/components/noop-head.js safe No malicious patterns detected
dist/client/components/not-found.js safe No malicious patterns detected; the file is a standard Next.js internal implementation of the notFound() function.
dist/client/components/offline.js safe No malicious patterns detected; the code implements legitimate offline detection and connectivity retry logic for a client-side web application.
dist/client/components/promise-queue.js safe No malicious patterns detected; the code is a straightforward promise queue implementation with no network, filesystem, or process manipulation.
dist/client/components/readonly-url-search-params.js safe No malicious patterns detected; the file is a legitimate Next.js ReadonlyURLSearchParams implementation that only disables mutating URLSearchParams methods.
dist/client/components/redirect-boundary.js safe No malicious patterns detected
dist/client/components/redirect-error.js safe No malicious patterns detected; the code is a standard Next.js redirect error handler with no data exfiltration, dynamic execution, or other security concerns.
dist/client/components/redirect-status-code.js safe No malicious patterns detected
dist/client/components/redirect.js safe This is a legitimate Next.js internal module for handling redirect errors; no malicious patterns detected.
dist/client/components/render-from-template-context.js safe This is a benign React server component that reads a template context and renders its children, with no malicious patterns detected.
dist/client/components/router-reducer/compute-changed-path.js safe No malicious patterns detected; the file contains legitimate Next.js router path computation logic with no network, filesystem, process execution, or obfuscated code.
dist/client/components/router-reducer/create-href-from-url.js safe No malicious patterns detected
dist/client/components/router-reducer/create-initial-router-state.js safe This file is part of Next.js's client-side router initialization logic and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or network requests to untrusted endpoints.
dist/client/components/router-reducer/create-router-cache-key.js safe No malicious patterns detected
dist/client/components/router-reducer/fetch-server-response.js safe This is a legitimate Next.js internal client-side RSC fetch/decode module; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were found.
dist/client/components/router-reducer/is-navigating-to-new-root-layout.js safe No malicious patterns detected; the code is a pure recursive comparison function for Next.js router state with no network, filesystem, process, or dynamic code execution activity.
dist/client/components/router-reducer/ppr-navigations.js safe No malicious patterns detected; this is legitimate Next.js PPR navigation internals without exfiltration, credential harvesting, obfuscation, or harmful dynamic execution.
dist/client/components/router-reducer/reducers/committed-state.js safe The file contains only benign module export logic and a simple in-memory state variable with no suspicious network, filesystem, process, or dynamic execution behavior.
dist/client/components/router-reducer/reducers/find-head-in-cache.js safe No malicious patterns detected; the code is a straightforward recursive cache lookup utility without network, filesystem, process, or dynamic execution behavior.
dist/client/components/router-reducer/reducers/has-interception-route-in-current-tree.js safe No malicious patterns detected; the code is a standard Next.js router utility for checking interception routes in the current tree.
dist/client/components/router-reducer/reducers/hmr-refresh-reducer.js safe No malicious patterns detected; the file is a standard Next.js router reducer for HMR refresh handling.
dist/client/components/router-reducer/reducers/navigate-reducer.js safe No malicious patterns detected; this is standard Next.js router reducer code that only reads environment variables for staleness configuration and performs client-side navigation without exfiltration, dynamic execution, or filesystem/process access.
dist/client/components/router-reducer/reducers/refresh-reducer.js safe This is a legitimate Next.js client-side router refresh reducer with no malicious patterns detected; all imports are internal framework modules, no network calls, no filesystem/process access, and no dynamic code execution.
dist/client/components/router-reducer/reducers/restore-reducer.js safe No malicious patterns detected; the code is a legitimate React/Next.js router reducer for restoring navigation state.
dist/client/components/router-reducer/reducers/server-action-reducer.js safe This is a legitimate Next.js internal client router reducer implementing server action handling; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or backdoors were detected.
dist/client/components/router-reducer/reducers/server-patch-reducer.js safe No malicious patterns detected
dist/client/components/router-reducer/router-reducer-types.js safe No malicious patterns detected
dist/client/components/router-reducer/router-reducer.js safe No malicious patterns detected; the file is a standard Next.js router reducer with conditional development-only dynamic require.
dist/client/components/router-reducer/set-cache-busting-search-param.js safe The file is a legitimate Next.js client-side router utility that computes and sets a cache-busting search parameter, with no malicious patterns detected.
dist/client/components/router-transition.js safe No malicious patterns detected; the code is a legitimate Next.js router transition instrumentation module with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/client/components/segment-cache/bfcache.js safe The file is a legitimate Next.js client-side back/forward cache module with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning.
dist/client/components/segment-cache/cache-key.js safe No malicious patterns detected; the code only defines utility functions for cache key creation and pathname splitting.
dist/client/components/segment-cache/cache-map.js safe No malicious patterns detected; the file is a standard LRU cache map implementation using only internal imports and no network, filesystem, process, or dynamic code execution.
dist/client/components/segment-cache/fetch.js safe No malicious patterns detected; the code is a benign internal fetch wrapper with controlled feature-flag gating and no external data flows or dangerous operations.
dist/client/components/segment-cache/lru.js safe The code implements a standard LRU cache for memory management in Next.js and contains no malicious patterns, network activity, credential harvesting, or dynamic code execution.
dist/client/components/segment-cache/navigation-testing-lock.disabled.js safe This is a benign inert stub module for Next.js's navigation testing lock, exporting no-op functions with no network, filesystem, process, or dynamic code execution behavior.
dist/client/components/segment-cache/navigation.js safe No malicious patterns detected; this is legitimate Next.js client-side navigation code with normal framework imports and no exfiltration, dynamic execution, or suspicious behavior.
dist/client/components/segment-cache/optimistic-routes.js safe No malicious patterns detected; the module is a legitimate Next.js client-side route prediction mechanism with no network, filesystem, process, or credential access.
dist/client/components/segment-cache/prefetch.js safe No malicious patterns detected; the code is a standard client-side prefetch utility that only performs internal cache scheduling and URL validation.
dist/client/components/segment-cache/scheduler.js safe This is a legitimate Next.js prefetch scheduler module containing only queue management, cache coordination, and heap logic with no malicious patterns.
dist/client/components/segment-cache/types.js safe This file only defines TypeScript-style enums and CommonJS export boilerplate for the Segment Cache; no malicious patterns, network activity, dynamic execution, or install-time behavior were detected.
dist/client/components/segment-cache/vary-path.js safe No malicious patterns detected; the code is a pure vary-path cache key construction module with no network, filesystem, process, or dynamic execution activity.
dist/client/components/server-async-storage.browser.js safe No malicious patterns detected; the file is a trivial browser stub that exports undefined async-storage singletons with no network, filesystem, process, or dynamic code activity.
dist/client/components/server-async-storage.js safe No malicious patterns detected; the module is a straightforward re-export of server-side AsyncLocalStorage singletons with a documented browser-safe alias mechanism.
dist/client/components/static-generation-bailout.js safe No malicious patterns detected; the file is a benign Next.js error utility with standard module exports and no I/O, network, or execution of untrusted code.
dist/client/components/styles/access-error-styles.js safe No malicious patterns detected
dist/client/components/unauthorized.js safe No malicious patterns detected; this is a standard Next.js experimental error-throwing utility with no data exfiltration, credential harvesting, obfuscation, network calls, or suspicious behavior.
dist/client/components/unrecognized-action-error.js safe No malicious patterns detected; the file only defines a custom error class and a type guard for Next.js internal use.
dist/client/components/unresolved-thenable.js safe No malicious patterns detected
dist/client/components/unstable-rethrow.browser.js safe No malicious patterns detected
dist/client/components/unstable-rethrow.js safe No malicious patterns detected; the file is a standard Next.js internal utility for rethrowing framework-specific errors.
dist/client/components/use-action-queue.js safe No malicious patterns detected; this is a legitimate Next.js internal React hook module for app router action queue management with no exfiltration, obfuscation, process spawning, or suspicious network/filesystem activity.
dist/client/components/use-offline.js safe No malicious patterns detected; the module is a standard React context provider for offline state management using only local React APIs with no network, filesystem, process, or obfuscated code.
dist/client/detect-domain-locale.js safe No malicious patterns detected; the code is a standard Next.js i18n module with conditional dynamic require gated by an environment variable.
dist/client/dev/debug-channel.js safe This Next.js debug-channel module uses IndexedDB and navigation timing APIs for legitimate client-side debug chunk persistence and restoration; no exfiltration, credential harvesting, obfuscation, process spawning, or other malicious patterns are present.
dist/client/dev/error-overlay/websocket.js safe No malicious patterns detected; the file only re-exports addMessageListener from an internal Next.js hot-reloader websocket module.
dist/client/dev/fouc.js safe No malicious patterns detected; the code is a legitimate FOUC removal utility that safely schedules DOM cleanup.
dist/client/dev/hot-middleware-client.js safe This is a legitimate Next.js development hot-reload middleware client that handles HMR events via WebSocket and page reloads without any malicious patterns.
dist/client/dev/hot-reloader/app/hot-reloader-app.js safe This is Next.js's development hot-reload client code; it uses only expected HMR/dev-tooling APIs with no exfiltration, credential harvesting, obfuscation, process spawning, or other malicious patterns.
dist/client/dev/hot-reloader/get-socket-url.js safe No malicious patterns detected; the file only computes a WebSocket URL for Next.js hot reloading using standard browser APIs and a local utility module.
dist/client/dev/hot-reloader/shared.js safe No malicious patterns detected; the file only exports constants and a warning helper for React Fast Refresh HMR messaging.
dist/client/dev/hot-reloader/turbopack-hot-reloader-common.js safe This is a legitimate Next.js Turbopack HMR utility module with no malicious patterns: it only uses console logging, timers, and message parsing for hot-module reloading, with no network, filesystem, process, or dynamic code execution.
dist/client/dev/noop-turbopack-hmr.js safe This is a benign no-op stub for Turbopack HMR used in webpack builds, containing no malicious patterns, network activity, credential access, or dynamic code execution.
dist/client/dev/on-demand-entries-client.js safe No malicious patterns detected; the code is a standard Next.js development client that sends periodic ping messages to the local dev websocket server.
dist/client/dev/report-hmr-latency.js safe No malicious patterns detected; the file only logs HMR latency and sends telemetry to the dev server as documented.
dist/client/dev/runtime-error-handler.js safe No malicious patterns detected; the file only defines a simple runtime error handler object with standard CommonJS export interop.
dist/client/flight-data-helpers.js safe No malicious patterns detected; this is a standard Next.js flight data helper module with no signs of data exfiltration, credential harvesting, obfuscated code, or backdoor behavior.
dist/client/form-shared.js safe The code is a legitimate Next.js client-side form validation utility with no malicious patterns, exfiltration, or suspicious behavior detected.
dist/client/form.js safe No malicious patterns detected; the file is a legitimate Next.js client-side Form component that handles navigation and form submission without any exfiltration, obfuscation, or suspicious behavior.
dist/client/get-domain-locale.js safe No malicious patterns detected; the code is a standard Next.js utility for resolving domain locales with only static require calls and no external I/O.
dist/client/has-base-path.js safe The file contains standard Next.js base path utility logic with no malicious patterns, data exfiltration, or dynamic code execution.
dist/client/image-component.js safe This is the legitimate Next.js Image component with no malicious patterns or security concerns detected.
dist/client/index.js safe This is a legitimate Next.js client runtime bundle; no malicious patterns such as exfiltration, credential harvesting, obfuscated payloads, or shell execution were detected.
dist/client/legacy/image.js safe No malicious patterns detected; this is a legitimate Next.js legacy image component with only standard image optimization, URL handling, and deprecation warnings.
dist/client/lib/console.js safe No malicious patterns detected; the code is a benign console argument formatter and parser for a Next.js-like client library.
dist/client/lib/javascript-url.js safe The code is a defensive utility for detecting javascript: URL schemes, adapted from React's sanitizeURL, with no malicious patterns detected.
dist/client/lib/promise.js safe No malicious patterns detected
dist/client/link.js safe No malicious patterns detected; this is a standard Next.js Link component implementation with no data exfiltration, credential harvesting, obfuscated code, or suspicious behavior.
dist/client/navigation-build-id.js safe No malicious patterns detected; the module only manages a global build ID string used for client-server synchronization.
dist/client/next-dev-turbopack.js safe This file is a legitimate Next.js development client entry point for Turbopack HMR with no malicious patterns detected.
dist/client/next-dev.js safe No malicious patterns detected; this is standard Next.js development client initialization code.
dist/client/next-turbopack.js safe No malicious patterns detected; the file is a standard Next.js Turbopack client entry point with expected initialization and hydration logic.
dist/client/next.js safe No malicious patterns detected; this is a standard Next.js client entry point with no obfuscation, data exfiltration, or suspicious runtime behavior.
dist/client/normalize-trailing-slash.js safe No malicious patterns detected
dist/client/page-bootstrap.js safe This is Next.js's legitimate development-time HMR page bootstrap module; all network activity and dynamic behavior are expected dev-server features with no malicious patterns detected.
dist/client/page-loader.js safe This is a legitimate Next.js client-side page loader module with no malicious patterns detected.
dist/client/portal/index.js safe This is a standard React Portal component implementation with no malicious patterns detected.
dist/client/react-client-callbacks/error-boundary-callbacks.js safe This is a legitimate Next.js error boundary callback module with no malicious patterns, exfiltration, or suspicious behavior detected.
dist/client/react-client-callbacks/on-recoverable-error.js safe This is a standard Next.js internal error handling module with no malicious patterns, no data exfiltration, no credential harvesting, and no dynamic code execution.
dist/client/react-client-callbacks/report-global-error.js safe No malicious patterns detected; the file only re-exports a global error reporting helper using console.error or reportError with no external calls or dangerous operations.
dist/client/register-deployment-id-global.js safe No malicious patterns detected; the code simply retrieves a deployment ID and assigns it to a global variable.
dist/client/remove-base-path.js safe No malicious patterns detected
dist/client/remove-locale.js safe No malicious patterns detected; the code is a benign utility for removing locale prefixes from URL paths in Next.js.
dist/client/request-idle-callback.js safe No malicious patterns detected
dist/client/request/io.browser.js safe No malicious patterns detected
dist/client/request/params.browser.dev.js safe No malicious patterns detected; this is a Next.js development module that wraps params in a Proxy for synchronous access warnings.
dist/client/request/params.browser.js safe No malicious patterns detected; the file only conditionally requires development or production parameter modules based on NODE_ENV and re-exports a helper function.
dist/client/request/params.browser.prod.js safe No malicious patterns detected
dist/client/request/search-params.browser.dev.js safe No malicious patterns detected; the code is a legitimate Next.js development helper that proxies searchParams to warn about synchronous access, with no exfiltration, obfuscation, or other security red flags.
dist/client/request/search-params.browser.prod.js safe No malicious patterns detected; the code is a straightforward Next.js browser production module for caching search params with no network, filesystem, or code execution behavior.
dist/client/resolve-href.js safe No malicious patterns detected; the file contains standard Next.js URL resolution logic without any security concerns.
dist/client/route-announcer.js safe No malicious patterns detected; the file is a legitimate Next.js RouteAnnouncer accessibility component with no network, filesystem, process, or code execution risks.
dist/client/route-loader.js safe This is a legitimate Next.js client-side route loader module with no malicious patterns detected.
dist/client/route-params.js safe No malicious patterns detected; the file contains legitimate Next.js route parameter handling utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious execution.
dist/client/router-transition-types.js safe No malicious patterns detected; the file contains only standard module export boilerplate and a source map reference.
dist/client/router.js safe No malicious patterns detected; the code is a standard Next.js client router module with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/client/set-attributes-from-props.js safe No malicious patterns detected; the code is a legitimate utility for setting DOM attributes from React props, consistent with Next.js internals.
dist/client/tracing/report-to-socket.js safe The file is a standard Next.js tracing utility that forwards span data to an internal dev websocket; no malicious patterns, credential harvesting, or obfuscation were detected.
dist/client/tracing/tracer.js safe No malicious patterns detected; the code is a legitimate tracing implementation using expected modules.
dist/client/trusted-types.js safe No malicious patterns detected; the code is a standard Next.js Trusted Types polyfill that creates a permissive policy but does not exfiltrate data, execute dynamic code, or perform any suspicious operations.
dist/client/use-client-disallowed.js safe No malicious patterns detected; the code is a Next.js internal guard that throws an error when Client Components are imported in an unsupported environment.
dist/client/use-intersection.js safe No malicious patterns detected
dist/client/use-merged-ref.js safe The file contains a standard React hook utility for merging refs with no suspicious behavior, network access, filesystem operations, or dynamic code execution.
dist/client/web-vitals.js safe No malicious patterns detected; the file is a standard Next.js React hook for reporting Web Vitals metrics to a user-provided callback.
dist/client/webpack.js safe This is a standard Next.js client webpack runtime module that conditionally appends a deployment ID asset token to chunk filenames; it contains no network requests, process spawning, credential access, obfuscation, or other malicious patterns.
dist/client/with-router.js safe No malicious patterns detected; the file is a standard Next.js withRouter HOC helper with no exfiltration, code execution, or suspicious behavior.
dist/compiled/@babel/runtime/helpers/AwaitValue.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/OverloadYield.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/applyDecoratedDescriptor.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/applyDecs.js safe No malicious patterns detected in this Babel decorators helper, which contains only legitimate decorator transformation logic without network, file system, process, or credential access.
dist/compiled/@babel/runtime/helpers/applyDecs2203.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/applyDecs2203R.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/applyDecs2301.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/applyDecs2305.js safe No malicious patterns detected; this is a standard Babel helper for decorator semantics with no network, filesystem, process, or obfuscated code.
dist/compiled/@babel/runtime/helpers/applyDecs2311.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/arrayLikeToArray.js safe This is a benign Babel helper function that converts array-like objects to arrays with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/arrayWithHoles.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/arrayWithoutHoles.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/assertClassBrand.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/assertThisInitialized.js safe No malicious patterns detected; the file is a standard Babel helper that validates this initialization.
dist/compiled/@babel/runtime/helpers/asyncGeneratorDelegate.js safe No malicious patterns detected; this is a standard Babel helper for async generator delegation.
dist/compiled/@babel/runtime/helpers/asyncIterator.js safe No malicious patterns detected; this is a standard Babel helper for async iteration with no network, filesystem, process, or dynamic code execution activity.
dist/compiled/@babel/runtime/helpers/asyncToGenerator.js safe No malicious patterns detected; this is the standard Babel asyncToGenerator helper for converting async functions to generator-based promise chains.
dist/compiled/@babel/runtime/helpers/awaitAsyncGenerator.js safe No malicious patterns detected; the file is a simple Babel helper that wraps a value in an OverloadYield object without any dangerous operations.
dist/compiled/@babel/runtime/helpers/callSuper.js safe This is a standard Babel helper function for calling super constructors, with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/checkInRHS.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/checkPrivateRedeclaration.js safe No malicious patterns detected; the code is a standard Babel helper for private field redeclaration checks with no network, filesystem, process, or dynamic execution behavior.
dist/compiled/@babel/runtime/helpers/classApplyDescriptorDestructureSet.js safe No malicious patterns detected; the file is a standard Babel helper for private field destructuring assignment.
dist/compiled/@babel/runtime/helpers/classApplyDescriptorGet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classApplyDescriptorSet.js safe No malicious patterns detected; the code is a standard Babel helper for setting private class fields with proper validation and no external interactions.
dist/compiled/@babel/runtime/helpers/classCallCheck.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classCheckPrivateStaticAccess.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classCheckPrivateStaticFieldDescriptor.js safe No malicious patterns detected; the file is a benign Babel helper function for checking private static field declarations.
dist/compiled/@babel/runtime/helpers/classExtractFieldDescriptor.js safe No malicious patterns detected; the file is a simple Babel helper that delegates to another local module.
dist/compiled/@babel/runtime/helpers/classNameTDZError.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classPrivateFieldDestructureSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classPrivateFieldGet.js safe No malicious patterns detected; this is a standard Babel helper for accessing private class fields.
dist/compiled/@babel/runtime/helpers/classPrivateFieldGet2.js safe No malicious patterns detected; this is a standard Babel helper for private field access with no external, network, filesystem, or process activity.
dist/compiled/@babel/runtime/helpers/classPrivateFieldInitSpec.js safe This is a standard Babel helper for private field initialization with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/classPrivateFieldLooseBase.js safe No malicious patterns detected; the file is a standard Babel runtime helper for private field access checks.
dist/compiled/@babel/runtime/helpers/classPrivateFieldLooseKey.js safe No malicious patterns detected in this small utility module that generates unique private field key names.
dist/compiled/@babel/runtime/helpers/classPrivateFieldSet.js safe No malicious patterns detected; this is a standard Babel helper for setting private class fields.
dist/compiled/@babel/runtime/helpers/classPrivateFieldSet2.js safe No malicious patterns detected; the helper performs a standard private field set using class brand assertion without any external calls, dynamic execution, or I/O.
dist/compiled/@babel/runtime/helpers/classPrivateGetter.js safe No malicious patterns detected; the file is a standard Babel runtime helper for private getter access.
dist/compiled/@babel/runtime/helpers/classPrivateMethodGet.js safe No malicious patterns detected; this is a standard Babel helper for private method access.
dist/compiled/@babel/runtime/helpers/classPrivateMethodInitSpec.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classPrivateMethodSet.js safe The file contains a standard Babel helper that throws a TypeError when attempting to reassign a private method; no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/classPrivateSetter.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classStaticPrivateFieldDestructureSet.js safe No malicious patterns detected; this is a standard Babel helper for private static field destructuring assignment.
dist/compiled/@babel/runtime/helpers/classStaticPrivateFieldSpecGet.js safe No malicious patterns detected; this is a standard Babel helper for private static field access with no network, filesystem, process, or dynamic code execution behavior.
dist/compiled/@babel/runtime/helpers/classStaticPrivateFieldSpecSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/classStaticPrivateMethodGet.js safe No malicious patterns detected; the file is a standard Babel helper for accessing static private methods.
dist/compiled/@babel/runtime/helpers/classStaticPrivateMethodSet.js safe No malicious patterns detected in this Babel runtime helper that only throws a TypeError for read-only static private field assignments.
dist/compiled/@babel/runtime/helpers/construct.js safe No malicious patterns detected; this is a standard Babel helper for Reflect.construct fallback.
dist/compiled/@babel/runtime/helpers/createClass.js safe No malicious patterns detected; the code is a standard Babel helper for defining class properties.
dist/compiled/@babel/runtime/helpers/createForOfIteratorHelper.js safe No malicious patterns detected; this is a standard Babel transpilation helper for for-of iteration.
dist/compiled/@babel/runtime/helpers/createForOfIteratorHelperLoose.js safe No malicious patterns detected; the file is a standard Babel helper for loose for-of iteration with no network, filesystem, process, or dynamic code execution behavior.
dist/compiled/@babel/runtime/helpers/createSuper.js safe No malicious patterns detected; the file is a standard Babel runtime helper for creating superclass constructors.
dist/compiled/@babel/runtime/helpers/decorate.js safe This is a standard Babel helper for JavaScript decorator transforms with no malicious patterns, network calls, credential access, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/defaults.js safe No malicious patterns detected; the code is a standard utility for copying default properties, with no network, filesystem, or process activity.
dist/compiled/@babel/runtime/helpers/defineAccessor.js safe No malicious patterns detected; the code is a standard Babel helper for defining object properties.
dist/compiled/@babel/runtime/helpers/defineEnumerableProperties.js safe This is a standard Babel helper function that defines enumerable properties; it contains no malicious patterns, network activity, credential access, dynamic code execution, or lifecycle scripts.
dist/compiled/@babel/runtime/helpers/defineProperty.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/dispose.js safe No malicious patterns detected; the code is a standard Babel helper implementing the explicit resource management dispose protocol with SuppressedError support, containing no network, filesystem, process, or dynamic execution behavior.
dist/compiled/@babel/runtime/helpers/esm/AwaitValue.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/OverloadYield.js safe No malicious patterns detected; the file defines a simple constructor function and exports it as default.
dist/compiled/@babel/runtime/helpers/esm/applyDecoratedDescriptor.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/applyDecs.js safe No malicious patterns detected; the code is a standard Babel helper for implementing decorators and metadata, with no network, filesystem, process execution, or obfuscated behavior.
dist/compiled/@babel/runtime/helpers/esm/applyDecs2203.js safe No malicious patterns detected in this Babel decorator helper implementation.
dist/compiled/@babel/runtime/helpers/esm/applyDecs2203R.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/applyDecs2301.js safe No malicious patterns detected; this is a standard Babel runtime decorator helper with no network, filesystem, process, or dynamic code execution concerns.
dist/compiled/@babel/runtime/helpers/esm/applyDecs2305.js safe This is a legitimate Babel helper implementing the ES decorators proposal (applyDecs2305) with no malicious patterns, network access, file system manipulation, or obfuscated code.
dist/compiled/@babel/runtime/helpers/esm/applyDecs2311.js safe Legitimate Babel runtime helper for decorator application, no malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/arrayLikeToArray.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/arrayWithHoles.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/arrayWithoutHoles.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/assertClassBrand.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/assertThisInitialized.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/asyncGeneratorDelegate.js safe No malicious patterns detected; this is a standard Babel helper for async generator delegation.
dist/compiled/@babel/runtime/helpers/esm/asyncIterator.js safe No malicious patterns detected; the file is a standard Babel runtime helper for async iterator support with no network, filesystem, or code execution behavior.
dist/compiled/@babel/runtime/helpers/esm/asyncToGenerator.js safe No malicious patterns detected; the code is a standard Babel async-to-generator helper with no network, filesystem, process, or obfuscation activity.
dist/compiled/@babel/runtime/helpers/esm/awaitAsyncGenerator.js safe The file is a trivial Babel helper that wraps a value in an OverloadYield object with no malicious behavior or side effects.
dist/compiled/@babel/runtime/helpers/esm/callSuper.js safe No malicious patterns detected; this is a standard Babel transpilation helper for calling super constructors with no external network, filesystem, or code execution activity.
dist/compiled/@babel/runtime/helpers/esm/checkInRHS.js safe No malicious patterns detected; the file is a standard Babel helper function for validating the right-hand side of 'in' operators.
dist/compiled/@babel/runtime/helpers/esm/checkPrivateRedeclaration.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classApplyDescriptorDestructureSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classApplyDescriptorGet.js safe No malicious patterns detected; the code only provides a simple helper for accessing class descriptor values via getters or direct values.
dist/compiled/@babel/runtime/helpers/esm/classApplyDescriptorSet.js safe This is a standard Babel helper function for applying values to class private fields with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/esm/classCallCheck.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classCheckPrivateStaticAccess.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/@babel/runtime/helpers/esm/classCheckPrivateStaticFieldDescriptor.js safe No malicious patterns detected; the code is a simple helper function that throws a TypeError when a private static field is accessed before its declaration.
dist/compiled/@babel/runtime/helpers/esm/classExtractFieldDescriptor.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classNameTDZError.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldDestructureSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldGet.js safe No malicious patterns detected; the file is a standard Babel runtime helper for private class field access with no suspicious behavior.
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldGet2.js safe No malicious patterns detected; the code is a legitimate Babel helper for private field access with no suspicious behavior.
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldInitSpec.js safe This is a standard Babel helper for initializing private class fields; it performs no network, filesystem, or process operations and contains no malicious patterns.
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldLooseBase.js safe This is a standard Babel helper function for private field access with no malicious patterns.
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldLooseKey.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateFieldSet2.js safe This is a standard Babel transpilation helper for setting private class fields, with no malicious patterns or security concerns.
dist/compiled/@babel/runtime/helpers/esm/classPrivateGetter.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateMethodGet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateMethodInitSpec.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classPrivateMethodSet.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/@babel/runtime/helpers/esm/classPrivateSetter.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateFieldDestructureSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateFieldSpecGet.js safe No malicious patterns detected; this is a standard Babel helper for accessing private static fields.
dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateFieldSpecSet.js safe No malicious patterns detected in this Babel helper module; it is a straightforward static private field setter with no network, filesystem, or code execution behavior.
dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateMethodGet.js safe No malicious patterns detected; the file is a small helper that asserts a class brand and returns a method reference.
dist/compiled/@babel/runtime/helpers/esm/classStaticPrivateMethodSet.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/@babel/runtime/helpers/esm/construct.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/createClass.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/createForOfIteratorHelper.js safe The file is a standard Babel transpilation helper for iterating over iterables and contains no malicious patterns.
dist/compiled/@babel/runtime/helpers/esm/createForOfIteratorHelperLoose.js safe No malicious patterns detected; this is a standard Babel helper for iterating objects safely.
dist/compiled/@babel/runtime/helpers/esm/createSuper.js safe The code is a standard Babel helper for extending ES6 classes, using only safe reflection and prototype utilities with no malicious patterns.
dist/compiled/@babel/runtime/helpers/esm/decorate.js safe No malicious patterns detected; the code is a standard Babel helper for implementing the JavaScript decorators proposal.
dist/compiled/@babel/runtime/helpers/esm/defaults.js safe No malicious patterns detected; the code is a standard utility function for copying configurable own properties from a source object to a target object.
dist/compiled/@babel/runtime/helpers/esm/defineAccessor.js safe This is a standard Babel helper function for defining object accessors; no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/esm/defineEnumerableProperties.js safe No malicious patterns detected; this is a standard Babel helper function for defining enumerable properties.
dist/compiled/@babel/runtime/helpers/esm/defineProperty.js safe Legitimate Babel helper for defining object properties with no malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/dispose.js safe No malicious patterns detected; the code is a standard polyfill/polyfill-like implementation for resource disposal (using SuppressedError) with no network, filesystem, process, or dynamic code execution behavior.
dist/compiled/@babel/runtime/helpers/esm/extends.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/get.js safe This is a standard Babel helper for Reflect.get with super property fallback, containing no malicious patterns or suspicious behavior.
dist/compiled/@babel/runtime/helpers/esm/getPrototypeOf.js safe No malicious patterns detected; this is a standard Babel helper for getPrototypeOf with no network, filesystem, process, or dynamic execution behavior.
dist/compiled/@babel/runtime/helpers/esm/identity.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/importDeferProxy.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/inherits.js safe No malicious patterns detected; this is a standard Babel helper for prototypal inheritance.
dist/compiled/@babel/runtime/helpers/esm/inheritsLoose.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/initializerDefineProperty.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/initializerWarningHelper.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/instanceof.js safe No malicious patterns detected; the code is a standard Babel helper implementing an instanceof polyfill with no network, filesystem, process, or dynamic execution behavior.
dist/compiled/@babel/runtime/helpers/esm/interopRequireDefault.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/interopRequireWildcard.js safe This is a standard Babel runtime helper for interoperating CommonJS modules with ES modules, containing no malicious patterns.
dist/compiled/@babel/runtime/helpers/esm/isNativeFunction.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/isNativeReflectConstruct.js safe This is a standard Babel helper for detecting native Reflect.construct support with no malicious patterns, network calls, filesystem access, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/esm/iterableToArray.js safe No malicious patterns detected; the code is a standard Babel helper that safely converts iterables to arrays without side effects or external access.
dist/compiled/@babel/runtime/helpers/esm/iterableToArrayLimit.js safe No malicious patterns detected; the code is a standard Babel helper for converting iterables to arrays.
dist/compiled/@babel/runtime/helpers/esm/jsx.js safe No malicious patterns detected; the code is a standard React element creation helper with no network, filesystem, process, or obfuscation concerns.
dist/compiled/@babel/runtime/helpers/esm/maybeArrayLike.js safe No malicious patterns detected; this is a benign Babel helper for array-like handling.
dist/compiled/@babel/runtime/helpers/esm/newArrowCheck.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/nonIterableRest.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/@babel/runtime/helpers/esm/nonIterableSpread.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/@babel/runtime/helpers/esm/nullishReceiverError.js safe No malicious patterns detected; the file only defines a helper that throws a TypeError.
dist/compiled/@babel/runtime/helpers/esm/objectDestructuringEmpty.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/objectSpread.js safe No malicious patterns detected; the file is a standard Babel helper for object spread compatibility.
dist/compiled/@babel/runtime/helpers/esm/objectSpread2.js safe No malicious patterns detected; this is a standard Babel helper for object spread syntax with no network, filesystem, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/esm/objectWithoutProperties.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/objectWithoutPropertiesLoose.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/possibleConstructorReturn.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/readOnlyError.js safe The file contains a trivial Babel-style helper that throws a TypeError for read-only property assignments, with no network, filesystem, process, credential, or obfuscation concerns.
dist/compiled/@babel/runtime/helpers/esm/regeneratorRuntime.js safe This is a legitimate copy of Facebook's regenerator-runtime helper from Babel, containing only generator/async runtime polyfill code with no malicious patterns.
dist/compiled/@babel/runtime/helpers/esm/set.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/setFunctionName.js safe No malicious patterns detected; the code is a straightforward utility for setting function names with safe property definition and error handling.
dist/compiled/@babel/runtime/helpers/esm/setPrototypeOf.js safe No malicious patterns detected; this is a standard Babel helper for setting an object's prototype.
dist/compiled/@babel/runtime/helpers/esm/skipFirstGeneratorNext.js safe No malicious patterns detected; the code is a standard helper for skipping the first yield of a generator function.
dist/compiled/@babel/runtime/helpers/esm/slicedToArray.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/superPropBase.js safe No malicious patterns detected; the file is a standard Babel helper for accessing superclass properties.
dist/compiled/@babel/runtime/helpers/esm/superPropGet.js safe No malicious patterns detected; the file is a benign Babel helper for accessing superclass properties.
dist/compiled/@babel/runtime/helpers/esm/superPropSet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/taggedTemplateLiteral.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/taggedTemplateLiteralLoose.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/tdz.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/temporalRef.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/temporalUndefined.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/toArray.js safe No malicious patterns detected; the file implements a standard Babel helper for converting iterables to arrays with no suspicious behavior.
dist/compiled/@babel/runtime/helpers/esm/toConsumableArray.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/@babel/runtime/helpers/esm/toPrimitive.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/toPropertyKey.js safe No malicious patterns detected; the code is a standard Babel helper for converting values to property keys.
dist/compiled/@babel/runtime/helpers/esm/toSetter.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/tsRewriteRelativeImportExtensions.js safe No malicious patterns detected; the code is a benign utility that rewrites TypeScript import extensions to JavaScript equivalents.
dist/compiled/@babel/runtime/helpers/esm/typeof.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/esm/unsupportedIterableToArray.js safe No malicious patterns detected; the file is a standard Babel helper for converting iterables to arrays.
dist/compiled/@babel/runtime/helpers/esm/using.js safe No malicious patterns detected; this is a standard Babel helper implementing the TC39 'using' declaration disposal mechanism using Symbol.dispose/Symbol.asyncDispose.
dist/compiled/@babel/runtime/helpers/esm/usingCtx.js safe This is a standard Babel/TypeScript helper for transpiling the 'using' declarations proposal (explicit resource management); it contains no malicious patterns such as network access, credential harvesting, obfuscation, or code execution.
dist/compiled/@babel/runtime/helpers/esm/wrapAsyncGenerator.js safe No malicious patterns detected; the file is a standard Babel async generator helper with no network, filesystem, process, or eval activity.
dist/compiled/@babel/runtime/helpers/esm/wrapNativeSuper.js safe No malicious patterns detected; the file is a standard Babel runtime helper implementing _wrapNativeSuper with no network, filesystem, process, or dynamic code execution activity.
dist/compiled/@babel/runtime/helpers/esm/wrapRegExp.js safe No malicious patterns detected; this is a legitimate Babel helper for extending RegExp with named groups.
dist/compiled/@babel/runtime/helpers/esm/writeOnlyError.js safe The file contains a trivial helper function that throws a TypeError for write-only property access, with no malicious patterns or suspicious behavior detected.
dist/compiled/@babel/runtime/helpers/extends.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/get.js safe No malicious patterns detected; this is a standard Babel helper for ES6 Reflect.get/super property access with no network, filesystem, or execution risks.
dist/compiled/@babel/runtime/helpers/getPrototypeOf.js safe No malicious patterns detected; the file is a standard Babel runtime helper for getting an object's prototype.
dist/compiled/@babel/runtime/helpers/identity.js safe The file contains a simple identity function with standard module exports and no malicious patterns.
dist/compiled/@babel/runtime/helpers/importDeferProxy.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/inherits.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/inheritsLoose.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/initializerDefineProperty.js safe This is a standard Babel helper function that safely defines object properties with no malicious patterns.
dist/compiled/@babel/runtime/helpers/initializerWarningHelper.js safe This is a standard Babel runtime helper function that only throws an error when decorators are misconfigured; no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/instanceof.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/interopRequireDefault.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/interopRequireWildcard.js safe No malicious patterns detected; this is a standard Babel runtime helper for ES module interop with no network, filesystem, process, or dynamic execution behavior.
dist/compiled/@babel/runtime/helpers/isNativeFunction.js safe The file contains only a standard utility function to detect native functions via Function.prototype.toString, with no malicious patterns, network activity, file access, or code execution.
dist/compiled/@babel/runtime/helpers/isNativeReflectConstruct.js safe The code is a standard Babel helper for detecting native Reflect.construct support, with no malicious patterns, network activity, or suspicious behavior.
dist/compiled/@babel/runtime/helpers/iterableToArray.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/iterableToArrayLimit.js safe No malicious patterns detected; this is a standard Babel helper for safely converting iterables to arrays with length limits.
dist/compiled/@babel/runtime/helpers/jsx.js safe This is a standard Babel/React JSX runtime helper that creates React elements; no malicious patterns, network calls, file access, or dynamic code execution were found.
dist/compiled/@babel/runtime/helpers/maybeArrayLike.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/newArrowCheck.js safe No malicious patterns detected; this is a standard Babel helper for arrow function instantiation checks.
dist/compiled/@babel/runtime/helpers/nonIterableRest.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/nonIterableSpread.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/nullishReceiverError.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/objectDestructuringEmpty.js safe No malicious patterns detected; the code is a standard Babel helper for throwing a TypeError on null/undefined destructuring.
dist/compiled/@babel/runtime/helpers/objectSpread.js safe This is a standard Babel helper for object spread syntax with no malicious patterns detected
dist/compiled/@babel/runtime/helpers/objectSpread2.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/objectWithoutProperties.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/objectWithoutPropertiesLoose.js safe No malicious patterns detected; the code is a standard Babel helper that safely copies own enumerable properties excluding specified keys.
dist/compiled/@babel/runtime/helpers/possibleConstructorReturn.js safe This is a standard Babel helper function for handling derived constructor return values, containing no malicious patterns, network calls, file system access, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/readOnlyError.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/regeneratorRuntime.js safe No malicious patterns detected; this is the standard @babel/runtime regenerator helper with no exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
dist/compiled/@babel/runtime/helpers/set.js safe No malicious patterns detected; the code is a standard Babel helper for property setting using Reflect.set or a fallback implementation.
dist/compiled/@babel/runtime/helpers/setFunctionName.js safe No malicious patterns detected; the code is a benign utility for setting function names with a safe try/catch and no external operations.
dist/compiled/@babel/runtime/helpers/setPrototypeOf.js safe This is a standard Babel helper function for setting object prototypes with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/skipFirstGeneratorNext.js safe The code is a benign utility function that wraps a generator to skip its first yield, with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/slicedToArray.js safe This is a Babel helper function for array destructuring with no malicious patterns, network activity, environment access, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/superPropBase.js safe This is a standard Babel helper function for accessing super class properties; no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/superPropGet.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/superPropSet.js safe No malicious patterns detected; the file is a Babel-generated helper for super property assignment with only local module requires and no external I/O, dynamic execution, or install-time behavior.
dist/compiled/@babel/runtime/helpers/taggedTemplateLiteral.js safe The file is a standard Babel helper for tagged template literals and contains no malicious patterns.
dist/compiled/@babel/runtime/helpers/taggedTemplateLiteralLoose.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/tdz.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/temporalRef.js safe The code is a standard Babel helper for temporal dead zone (TDZ) references, with no malicious patterns, network activity, file system access, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/temporalUndefined.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/toArray.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/toConsumableArray.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/toPrimitive.js safe No malicious patterns detected; the code is a standard Babel helper for ToPrimitive conversion.
dist/compiled/@babel/runtime/helpers/toPropertyKey.js safe No malicious patterns detected; the code is a standard Babel helper for converting values to property keys.
dist/compiled/@babel/runtime/helpers/toSetter.js safe No malicious patterns detected; the code is a standard Babel helper for creating setter functions via Object.defineProperty.
dist/compiled/@babel/runtime/helpers/tsRewriteRelativeImportExtensions.js safe The code is a benign utility function that rewrites TypeScript import extensions to JavaScript equivalents, with no network, filesystem, process, or dynamic execution activity.
dist/compiled/@babel/runtime/helpers/typeof.js safe No malicious patterns detected
dist/compiled/@babel/runtime/helpers/unsupportedIterableToArray.js safe The file is a standard Babel helper function for iterable conversion with no malicious patterns or security concerns.
dist/compiled/@babel/runtime/helpers/using.js safe This is a legitimate Babel helper function implementing the 'using' declaration spec, with no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/usingCtx.js safe This is a standard Babel helper implementation for the JavaScript 'using' declarations (explicit resource management) proposal; it contains no network, filesystem, process, or obfuscated code patterns.
dist/compiled/@babel/runtime/helpers/wrapAsyncGenerator.js safe No malicious patterns detected; the code is a standard Babel/TypeScript async generator runtime helper with no network, file, process, or dynamic code execution.
dist/compiled/@babel/runtime/helpers/wrapNativeSuper.js safe No malicious patterns detected; the code is a standard Babel helper for wrapping native super classes without any obfuscation, network, filesystem, or process manipulation.
dist/compiled/@babel/runtime/helpers/wrapRegExp.js safe This is a legitimate Babel helper for extending RegExp with named capture groups; no malicious patterns detected.
dist/compiled/@babel/runtime/helpers/writeOnlyError.js safe No malicious patterns detected; the file contains a simple Babel helper that throws a TypeError for write-only property access.
dist/compiled/@edge-runtime/cookies/index.js safe This is a legitimate Edge Runtime cookies library with no malicious patterns, network requests, credential harvesting, or code execution detected.
dist/compiled/@edge-runtime/ponyfill/index.js safe No malicious patterns detected
dist/compiled/@edge-runtime/primitives/abort-controller.js.text.js safe No malicious patterns detected; the code is a legitimate polyfill/implementation of the AbortController and AbortSignal APIs with no network, filesystem, or process activity.
dist/compiled/@edge-runtime/primitives/console.js.text.js safe No malicious patterns detected; the file is a bundled JavaScript implementation of a console formatting utility for the edge-runtime package.
dist/compiled/@edge-runtime/primitives/crypto.js safe No malicious patterns detected; the file is a standard wrapper around Node.js's built-in webcrypto module with no exfiltration, obfuscation, or suspicious behavior.
dist/compiled/@edge-runtime/primitives/events.js.text.js safe The file contains a bundled/transpiled implementation of FetchEvent and PromiseRejectionEvent classes for the @edge-runtime/primitives package with no malicious patterns detected.
dist/compiled/@edge-runtime/primitives/stream.js safe No malicious patterns detected; the code is a simple re-export of Node.js web stream primitives with no data exfiltration, dynamic code execution, process spawning, or suspicious network activity.
dist/compiled/@edge-runtime/primitives/url.js.text.js safe The file is a bundled polyfill for URLPattern and related URL parsing utilities with no malicious behavior, network activity, or dynamic code execution.
dist/compiled/@hapi/accept/index.js safe No malicious patterns detected; the code is a bundled version of the @hapi/accept HTTP content negotiation library with no obfuscation, data exfiltration, credential harvesting, or arbitrary code execution.
dist/compiled/@modelcontextprotocol/sdk/server/streamableHttp.js safe No malicious patterns detected; the code is a legitimate MCP Streamable HTTP server transport implementation with standard request handling, validation, and SSE streaming.
dist/compiled/@napi-rs/triples/index.js safe No malicious patterns detected; the file is a benign platform/architecture triple mapping bundled by ncc with no network, filesystem, process, or dynamic execution activity.
dist/compiled/@next/font/dist/constants.js safe No malicious patterns detected
dist/compiled/@next/font/dist/format-available-values.js safe No malicious patterns detected; the code is a simple utility that formats an array of values into a string for error messages.
dist/compiled/@next/font/dist/google/fetch-resource.js safe The code is a straightforward HTTP/HTTPS resource fetcher for Google Fonts with no malicious patterns detected.
dist/compiled/@next/font/dist/google/find-font-files-in-css.js safe No malicious patterns detected; the code is a pure text-parsing utility for extracting font file URLs from CSS, with no network, filesystem, process, or dynamic execution activity.
dist/compiled/@next/font/dist/google/get-fallback-font-override-metrics.js safe No malicious patterns detected; the file is a standard TypeScript-compiled Next.js font utility that only imports internal modules and logs errors locally.
dist/compiled/@next/font/dist/google/get-font-axes.js safe No malicious patterns detected; the code only validates and formats Google Fonts axis metadata without network, filesystem, or process access.
dist/compiled/@next/font/dist/google/get-google-fonts-url.js safe No malicious patterns detected; the code only generates a Google Fonts URL from provided parameters.
dist/compiled/@next/font/dist/google/get-proxy-agent.js safe No malicious patterns detected; the code simply reads proxy environment variables and returns standard proxy agents.
dist/compiled/@next/font/dist/google/google-fonts-metadata.js safe No malicious patterns detected
dist/compiled/@next/font/dist/google/index.js safe No malicious patterns detected
dist/compiled/@next/font/dist/google/loader.js safe No malicious patterns detected
dist/compiled/@next/font/dist/google/retry.js safe No malicious patterns detected; the code is a simple retry utility wrapping an internal async-retry module with no exfiltration, obfuscation, or unsafe operations.
dist/compiled/@next/font/dist/google/sort-fonts-variant-values.js safe No malicious patterns detected; the file contains a pure sorting utility function with no network, filesystem, process, or dynamic execution activity.
dist/compiled/@next/font/dist/google/validate-google-font-function-call.js safe No malicious patterns detected; the code performs only static validation of Google font arguments with no network, filesystem, process, or dynamic code execution.
dist/compiled/@next/font/dist/local/get-fallback-metrics-from-font-file.js safe No malicious patterns detected
dist/compiled/@next/font/dist/local/index.js safe No malicious patterns detected; the file only defines a stub function that throws an error.
dist/compiled/@next/font/dist/local/loader.js safe No malicious patterns detected; the code is a legitimate Next.js font loader that reads local font files and generates @font-face CSS without any suspicious activity.
dist/compiled/@next/font/dist/local/pick-font-file-for-fallback-generation.js safe No malicious patterns detected; the code is a benign utility for selecting font files based on weight for Next.js font fallback generation.
dist/compiled/@next/font/dist/local/validate-local-font-function-call.js safe The code is a standard validation utility for next/font/local that only performs input validation and error handling, with no malicious patterns, network activity, or dynamic code execution.
dist/compiled/@next/font/dist/next-font-error.js safe No malicious patterns detected
dist/compiled/@next/font/dist/types.js safe No malicious patterns detected
dist/compiled/@next/font/google/index.js safe No malicious patterns detected; the file performs a version check and throws a configuration error message without any suspicious behavior.
dist/compiled/@next/font/google/loader.js safe This file is a simple re-export shim for Next.js's Google Font loader and contains no malicious patterns.
dist/compiled/@next/font/local/index.js safe No malicious patterns detected; the code only performs a version check and throws an error if requirements are not met.
dist/compiled/@next/react-refresh-utils/dist/ReactRefreshRspackPlugin.js safe No malicious patterns detected; the code is a standard webpack/rspack plugin for React Refresh runtime integration.
dist/compiled/@next/react-refresh-utils/dist/ReactRefreshWebpackPlugin.js safe No malicious patterns detected; the code is a legitimate React Fast Refresh webpack plugin that only manipulates webpack runtime hooks and does not perform any exfiltration, credential harvesting, or suspicious activity.
dist/compiled/@next/react-refresh-utils/dist/internal/ReactRefreshModule.runtime.js safe No malicious patterns detected; the code is a standard Next.js React Refresh runtime with no exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/compiled/@next/react-refresh-utils/dist/internal/RspackReactRefresh.js safe No malicious patterns detected; the file is a legitimate React Refresh runtime utility for Next.js/Rspack.
dist/compiled/@next/react-refresh-utils/dist/internal/helpers.js safe No malicious patterns detected; the code is a legitimate React Refresh helper from Next.js with no data exfiltration, dynamic code execution, or other security concerns.
dist/compiled/@next/react-refresh-utils/dist/rspack-runtime.js safe No malicious patterns detected; the code is a standard React Refresh runtime injection for Next.js development.
dist/compiled/@next/react-refresh-utils/dist/runtime.js safe No malicious patterns detected; the code is a standard React Refresh runtime integration for Next.js that registers global hooks and helpers without any data exfiltration, credential harvesting, obfuscation, or process execution.
dist/compiled/@opentelemetry/api/index.js safe No malicious patterns detected; the file is a standard minified build of the @opentelemetry/api package with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/compiled/@vercel/detect-agent/index.js safe The code is a bundled agent-detection utility that reads environment variables and checks for a known Devin installation path, with no exfiltration, dynamic code execution, or other malicious patterns.
dist/compiled/@vercel/routing-utils/superstatic.js safe No malicious patterns detected; the code implements routing utilities and path-to-regexp logic without any data exfiltration, credential access, obfuscated payloads, or suspicious system calls.
dist/compiled/anser/index.js safe No malicious patterns detected; the code is a standard ANSI-to-HTML converter with no network, file system, or process execution activity.
dist/compiled/assert/assert.js safe This is a bundled polyfill for Node.js's assert module and related utility functions; no malicious patterns, obfuscated code, data exfiltration, or dynamic execution were detected.
dist/compiled/async-retry/index.js safe The code is a standard async retry library with no obfuscation, network calls, file system access, or process spawning; it is safe to use.
dist/compiled/async-sema/index.js safe This is a legitimate semaphore and rate-limiting library with no malicious patterns detected.
dist/compiled/babel/core-lib-block-hoist-plugin.js safe No malicious patterns detected
dist/compiled/babel/core-lib-normalize-file.js safe No malicious patterns detected; the file is a simple module re-export from a local bundle.
dist/compiled/babel/core-lib-normalize-opts.js safe No malicious patterns detected
dist/compiled/babel/eslint-parser.js safe No malicious patterns detected; the file simply re-exports a bundled ESLint parser module from a local path.
dist/compiled/babel/generator.js safe No malicious patterns detected
dist/compiled/babel/parser.js safe No malicious patterns detected
dist/compiled/babel/plugin-proposal-class-properties.js safe The file is a simple Babel plugin re-export that requires a local bundle with no malicious patterns detected
dist/compiled/babel/plugin-proposal-export-namespace-from.js safe No malicious patterns detected; the file is a simple Babel plugin re-export that loads a shared bundle module at import time.
dist/compiled/babel/plugin-proposal-numeric-separator.js safe This is a simple re-export shim for Babel's numeric separator plugin with no malicious patterns.
dist/compiled/babel/plugin-proposal-object-rest-spread.js safe No malicious patterns detected
dist/compiled/babel/plugin-syntax-bigint.js safe This is a simple re-export of a Babel plugin from a local bundle, with no malicious patterns detected.
dist/compiled/babel/plugin-syntax-import-attributes.js safe This is a simple Babel plugin wrapper that delegates to a sibling bundle module with no malicious patterns.
dist/compiled/babel/plugin-syntax-jsx.js safe Simple module re-export from a local bundle with no suspicious patterns detected
dist/compiled/babel/plugin-syntax-typescript.js safe No malicious patterns detected
dist/compiled/babel/plugin-transform-define.js safe The file is a simple re-export wrapper that requires a bundled module and invokes a transform function, with no malicious patterns detected.
dist/compiled/babel/plugin-transform-modules-commonjs.js safe No malicious patterns detected; the file merely re-exports a Babel plugin from a local bundle.
dist/compiled/babel/plugin-transform-react-remove-prop-types.js safe The file is a simple Babel plugin loader that requires a local bundle module and calls a factory function, with no suspicious patterns detected.
dist/compiled/babel/plugin-transform-runtime.js safe No malicious patterns detected
dist/compiled/babel/preset-env.js safe The file is a simple Babel preset-env re-export with no malicious patterns, network access, or credential harvesting.
dist/compiled/babel/preset-react.js safe No malicious patterns detected
dist/compiled/babel/preset-typescript.js safe No malicious patterns detected
dist/compiled/babel/traverse.js safe No malicious patterns detected
dist/compiled/browserify-zlib/index.js safe No malicious patterns detected; the file is a standard browserify-bundled zlib implementation with no exfiltration, credential harvesting, obfuscated payloads, or suspicious process/network activity.
dist/compiled/buffer/index.js safe This is the standard browser Buffer polyfill (feross/buffer) with no malicious patterns, network activity, credential access, or dynamic code execution.
dist/compiled/busboy/index.js safe No malicious patterns detected; this is the legitimate busboy multipart/form-data parser with no network, filesystem, or code execution activity.
dist/compiled/bytes/index.js safe No malicious patterns detected
dist/compiled/ci-info/index.js safe No malicious patterns detected; the code is a legitimate CI environment detection library that reads environment variables to identify CI providers.
dist/compiled/cli-select/index.js safe No malicious patterns detected; the code is a legitimate terminal selection menu library with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
dist/compiled/client-only/error.js safe No malicious patterns detected
dist/compiled/client-only/index.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/commander/index.js safe This is the standard Commander.js CLI argument parsing library; no malicious behavior or security concerns were identified.
dist/compiled/content-disposition/index.js safe No malicious patterns detected; this is the standard content-disposition npm package bundled with webpack/ncc, with no data exfiltration, credential harvesting, obfuscation, or process spawning.
dist/compiled/content-type/index.js safe No malicious patterns detected
dist/compiled/cookie/index.js safe No malicious patterns detected; the code is a standard, unmodified implementation of the 'cookie' library for parsing and serializing HTTP cookies.
dist/compiled/css.escape/css.escape.js safe No malicious patterns detected; the code is a benign polyfill for CSS.escape bundled with webpack, containing no network, filesystem, process, obfuscation, or credential harvesting behavior.
dist/compiled/data-uri-to-buffer/index.js safe The code is a standard, bundled implementation of data-uri-to-buffer with no malicious patterns, network calls, file system access, or dynamic code execution.
dist/compiled/debug/index.js safe No malicious patterns detected; this is the standard debug logging library bundled with ncc, performing only local logging and environment variable reads for configuration.
dist/compiled/devalue/devalue.umd.js safe The code is a minified UMD bundle of the devalue serialization library with no malicious patterns detected.
dist/compiled/domain-browser/index.js safe The file is a benign webpack bundle of the domain-browser shim and contains no malicious patterns.
dist/compiled/events/events.js safe No malicious patterns detected; the code is a standard bundled event emitter module.
dist/compiled/find-up/index.js safe The code is a standard bundled implementation of the 'find-up' utility with no malicious patterns, network activity, credential harvesting, or dynamic code execution.
dist/compiled/fresh/index.js safe No malicious patterns detected
dist/compiled/glob/glob.js safe No malicious patterns detected; this is a bundled copy of the standard 'glob' file-matching library.
dist/compiled/gzip-size/index.js safe No malicious patterns detected; the code is a compiled JavaScript library for calculating gzip size with standard Node.js modules and no suspicious behavior.
dist/compiled/hash.js/sha256/256.js safe No malicious patterns detected; this is a standard, minified SHA-256 hash implementation with no network, filesystem, process, or dynamic code execution activity.
dist/compiled/http-proxy-agent/index.js safe This is a legitimate bundled version of the http-proxy-agent library; no malicious patterns were detected.
dist/compiled/https-browserify/index.js safe No malicious patterns detected; the code is a standard browserify shim for Node's https module that enforces HTTPS protocol without any exfiltration, obfuscation, or suspicious behavior.
dist/compiled/https-proxy-agent/index.js safe No malicious patterns detected; the code is a legitimate HTTPS proxy agent implementation bundled with ncc.
dist/compiled/icss-utils/index.js safe No malicious patterns detected
dist/compiled/ignore-loader/index.js safe No malicious patterns detected
dist/compiled/image-size/index.js safe No malicious patterns detected; the code is a legitimate image size detection library with standard file system operations and no data exfiltration, credential harvesting, obfuscated payloads, or other security concerns.
dist/compiled/ipaddr.js/ipaddr.js safe No malicious patterns detected; the code is a standard IPv4/IPv6 address parsing and manipulation library.
dist/compiled/is-animated/index.js safe No malicious patterns detected; the code is a standard Webpack-bundled utility for detecting animated GIF, PNG, and WebP images with no network, filesystem, or code execution activity.
dist/compiled/is-docker/index.js safe No malicious patterns detected
dist/compiled/is-wsl/index.js safe The compiled is-wsl package contains only benign WSL detection logic with no malicious patterns such as exfiltration, backdoors, or dynamic code execution.
dist/compiled/jest-worker/index.js safe No malicious patterns detected; the code is a legitimate Jest worker pool implementation with expected worker process management and no data exfiltration or obfuscation.
dist/compiled/json5/index.js safe The code is a standard JSON5 parser and serializer implementation (bundled with webpack) with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, network activity, shell commands, or dynamic code execution.
dist/compiled/loader-utils2/index.js safe No malicious patterns detected; the code is a legitimate Webpack loader-utils library with standard utility functions and no exfiltration, obfuscation, or suspicious behavior.
dist/compiled/loader-utils3/index.js safe No malicious patterns detected; the code is a legitimate utility library (loader-utils) implementing hash digests, URL handling, and name interpolation without data exfiltration, obfuscation, or process spawning.
dist/compiled/lodash.curry/index.js safe No malicious patterns detected; the code is a standard Lodash curry implementation with no network, filesystem, or process operations.
dist/compiled/lru-cache/index.js safe This is a standard, minified build of the well-known lru-cache npm package with no malicious patterns detected.
dist/compiled/mini-css-extract-plugin/cjs.js safe No malicious patterns detected; the file is a standard webpack/ncc bundle wrapper that re-exports the local index.js module.
dist/compiled/mini-css-extract-plugin/hmr/hotModuleReplacement.js safe No malicious patterns detected; the code implements standard Hot Module Replacement (HMR) for CSS via DOM manipulation with no exfiltration, dynamic code execution, or suspicious network activity.
dist/compiled/mini-css-extract-plugin/index.js safe No malicious patterns detected
dist/compiled/nanoid/index.cjs safe No malicious patterns detected; this is a legitimate bundled version of the nanoid library that only uses crypto.randomFillSync for random ID generation.
dist/compiled/native-url/index.js safe This is a minified URL parsing/polyfill library (native-url) with no malicious patterns, no network calls, no filesystem access, and no dynamic code execution.
dist/compiled/neo-async/async.js safe No malicious patterns detected; the code is a minified bundle of the legitimate neo-async library with no network, filesystem, process execution, credential harvesting, or dynamic code execution.
dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js-experimental.runtime.dev.js safe No malicious patterns detected
dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js-turbo-experimental.runtime.dev.js safe No malicious patterns detected; the file is a benign Next.js dev no-op HMR stub containing an empty connect function and standard module export boilerplate.
dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js-turbo.runtime.dev.js safe This is a benign Next.js development no-op HMR module with no network, filesystem, process execution, or obfuscated code patterns.
dist/compiled/next-server/dist_client_dev_noop-turbopack-hmr_js.runtime.dev.js safe No malicious patterns detected; the file is a benign Next.js no-op Turbopack HMR module with an empty connect function.
dist/compiled/ora/index.js safe The bundled code is the ora spinner package and its dependencies (chalk, cli-spinners, ansi-styles, etc.), containing only terminal styling and spinner logic with no malicious patterns detected.
dist/compiled/os-browserify/browser.js safe This is a standard browser polyfill for Node.js os module with no malicious patterns detected.
dist/compiled/p-limit/index.js safe This is a legitimate, minified/compiled implementation of the p-limit concurrency control library with no malicious patterns, network calls, credential access, dynamic code execution, or install-time hooks.
dist/compiled/p-queue/index.js safe No malicious patterns detected; the code is a standard bundled implementation of the p-queue library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/compiled/path-browserify/index.js safe This is a minified, bundled copy of the well-known path-browserify package containing only pure POSIX path manipulation functions with no malicious patterns detected.
dist/compiled/path-to-regexp/index.js safe This is a standard bundled version of the path-to-regexp library with no malicious patterns; it contains only routing-related logic and no network, filesystem, credential, or code-execution abuse.
dist/compiled/picomatch/index.js safe No malicious patterns detected; the code is a legitimate picomatch glob matching library with no data exfiltration, environment harvesting, obfuscation, or process execution.
dist/compiled/postcss-flexbugs-fixes/index.js safe No malicious patterns detected; the code is a standard PostCSS plugin for flexbugs fixes with no network, filesystem, or process manipulation.
dist/compiled/postcss-modules-extract-imports/index.js safe No malicious patterns detected; the code is a legitimate PostCSS plugin for extracting CSS modules imports and contains no network, credential, execution, or filesystem abuse.
dist/compiled/postcss-modules-local-by-default/index.js safe No malicious patterns detected; the code is a standard bundled PostCSS plugin for handling local-by-default CSS modules.
dist/compiled/postcss-modules-scope/index.js safe The code is a compiled PostCSS plugin for scoping CSS selectors and contains no malicious patterns such as data exfiltration, obfuscated payloads, or network requests.
dist/compiled/postcss-modules-values/index.js safe No malicious patterns detected; the code is a legitimate PostCSS plugin for handling CSS Modules values.
dist/compiled/postcss-plugin-stub-for-cssnano-simple/index.js safe This is a benign webpack/ncc-bundled PostCSS stub plugin containing no malicious patterns.
dist/compiled/postcss-safe-parser/safe-parse.js safe The code is a bundled build of postcss-safe-parser; it parses CSS with an error-tolerant tokenizer and imports postcss as expected, with no data exfiltration, credential harvesting, obfuscated payloads, shell execution, or other malicious patterns.
dist/compiled/postcss-scss/scss-syntax.js safe No malicious patterns detected; the code is a bundled PostCSS SCSS syntax parser/stringifier with no network, filesystem, process, or credential access.
dist/compiled/postcss-value-parser/index.js safe No malicious patterns detected
dist/compiled/process/browser.js safe This is a standard browser polyfill for the Node.js 'process' module (using nextTick, timers, and noop stubs) with no malicious patterns detected.
dist/compiled/punycode/punycode.js safe No malicious patterns detected; the file is a standard punycode implementation with no network, filesystem, process, or dynamic code execution behavior.
dist/compiled/querystring-es3/index.js safe This is a standard querystring parsing/stringifying polyfill with no malicious patterns, network activity, filesystem access, or code execution beyond normal module loading.
dist/compiled/react-dom-experimental/cjs/react-dom-test-utils.production.js safe No malicious patterns detected
dist/compiled/react-dom-experimental/cjs/react-dom.development.js safe This is the official React DOM development build from Meta; no malicious patterns, credential harvesting, obfuscation, network exfiltration, or dynamic code execution were detected.
dist/compiled/react-dom-experimental/cjs/react-dom.production.js safe This is a legitimate React DOM production build shim that only exposes standard React APIs, preloading helpers, and error formatting with no malicious patterns detected.
dist/compiled/react-dom-experimental/cjs/react-dom.react-server.development.js safe This is an official React DOM server build that only performs input validation, emits developer warnings, and delegates resource hint operations to internal React internals; no malicious patterns detected.
dist/compiled/react-dom-experimental/cjs/react-dom.react-server.production.js safe This is a legitimate React DOM server production build with no malicious patterns detected.
dist/compiled/react-dom-experimental/client.js safe No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check.
dist/compiled/react-dom-experimental/client.react-server.js safe No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components.
dist/compiled/react-dom-experimental/index.js safe This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns.
dist/compiled/react-dom-experimental/profiling.js safe No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export.
dist/compiled/react-dom-experimental/profiling.react-server.js safe No malicious patterns detected
dist/compiled/react-dom-experimental/react-dom.react-server.js safe No malicious patterns detected
dist/compiled/react-dom-experimental/server.browser.js safe This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected.
dist/compiled/react-dom-experimental/server.edge.js safe No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV.
dist/compiled/react-dom-experimental/server.js safe No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds.
dist/compiled/react-dom-experimental/server.node.js safe No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV.
dist/compiled/react-dom-experimental/server.react-server.js safe No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components.
dist/compiled/react-dom-experimental/static.edge.js safe This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected.
dist/compiled/react-dom-experimental/static.node.js safe No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs.
dist/compiled/react-dom-experimental/static.react-server.js safe The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected.
dist/compiled/react-dom-experimental/unstable_testing.react-server.js safe No malicious patterns detected
dist/compiled/react-dom/cjs/react-dom-test-utils.production.js safe No malicious patterns detected; this is a legitimate React DOM test-utils shim that warns about deprecation and delegates to React.act.
dist/compiled/react-dom/cjs/react-dom.development.js safe No malicious patterns detected
dist/compiled/react-dom/cjs/react-dom.production.js safe This is a legitimate minified React DOM production build from the official React package with no malicious patterns detected.
dist/compiled/react-dom/cjs/react-dom.react-server.development.js safe This is a legitimate React DOM development build file from Meta's React package; no malicious patterns, data exfiltration, obfuscation, or suspicious behavior detected.
dist/compiled/react-dom/cjs/react-dom.react-server.production.js safe This is a legitimate React DOM server build with no malicious patterns, obfuscation, data exfiltration, or unexpected side effects.
dist/compiled/react-dom/client.js safe No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check.
dist/compiled/react-dom/client.react-server.js safe No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components.
dist/compiled/react-dom/index.js safe This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns.
dist/compiled/react-dom/profiling.js safe No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export.
dist/compiled/react-dom/profiling.react-server.js safe No malicious patterns detected
dist/compiled/react-dom/react-dom.react-server.js safe No malicious patterns detected
dist/compiled/react-dom/server.browser.js safe This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected.
dist/compiled/react-dom/server.edge.js safe No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV.
dist/compiled/react-dom/server.js safe No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds.
dist/compiled/react-dom/server.node.js safe No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV.
dist/compiled/react-dom/server.react-server.js safe No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components.
dist/compiled/react-dom/static.edge.js safe This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected.
dist/compiled/react-dom/static.node.js safe No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs.
dist/compiled/react-dom/static.react-server.js safe The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected.
dist/compiled/react-experimental/cjs/react-compiler-runtime.development.js safe No malicious patterns detected; the code only accesses React internals for hook validation and useMemoCache.
dist/compiled/react-experimental/cjs/react-compiler-runtime.production.js safe No malicious patterns detected; the file only exposes a React internal hook wrapper and contains no obfuscation, network activity, or credential harvesting.
dist/compiled/react-experimental/cjs/react-compiler-runtime.profiling.js safe No malicious patterns detected; the file is a thin React experimental runtime shim that re-exports a memo cache hook from a bundled Next.js dependency.
dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.development.js safe Legitimate React JSX development runtime with only standard developer warnings and debugging helpers; no malicious patterns detected.
dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.production.js safe No malicious patterns detected
dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.profiling.js safe This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export.
dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.react-server.development.js safe This is the standard React JSX development runtime for server components with only debugging and warning logic, no malicious patterns detected.
dist/compiled/react-experimental/cjs/react-jsx-dev-runtime.react-server.production.js safe This is a legitimate React JSX runtime module with no malicious patterns detected.
dist/compiled/react-experimental/cjs/react-jsx-runtime.development.js safe The file is the legitimate, unmodified React experimental JSX runtime development build with no malicious patterns detected.
dist/compiled/react-experimental/cjs/react-jsx-runtime.production.js safe No malicious patterns detected
dist/compiled/react-experimental/cjs/react-jsx-runtime.profiling.js safe This is the official React JSX runtime profiling build containing only element creation logic with no malicious patterns, network activity, or code execution.
dist/compiled/react-experimental/cjs/react-jsx-runtime.react-server.development.js safe No malicious patterns detected; this is a legitimate React JSX runtime development build from Meta with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/compiled/react-experimental/cjs/react-jsx-runtime.react-server.production.js safe No malicious patterns detected; this is a legitimate React JSX runtime compilation artifact from the next/dist/compiled directory.
dist/compiled/react-experimental/cjs/react.production.js safe This is the official React production build and contains no malicious patterns, network requests, credential harvesting, obfuscation, or process spawning beyond expected React internals.
dist/compiled/react-experimental/cjs/react.react-server.development.js safe This is the official React 19.3.0-experimental server-side development build from Meta, containing only expected React internals (element creation, taint tracking, lazy/Memo/forwardRef, Children helpers, and transition handling) with no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or install-time hooks.
dist/compiled/react-experimental/cjs/react.react-server.production.js safe This is the official production build of React's experimental react-server package; it contains no malicious patterns, no network exfiltration, no credential harvesting, no obfuscated code, and no install/build/import-time side effects beyond normal module initialization.
dist/compiled/react-experimental/compiler-runtime.js safe No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV.
dist/compiled/react-experimental/index.js safe This is a standard React environment-based module export switch with no malicious patterns detected.
dist/compiled/react-experimental/jsx-dev-runtime.js safe No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV.
dist/compiled/react-experimental/jsx-dev-runtime.react-server.js safe No malicious patterns detected
dist/compiled/react-experimental/jsx-runtime.js safe This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected.
dist/compiled/react-experimental/jsx-runtime.react-server.js safe This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected.
dist/compiled/react-experimental/react.react-server.js safe No malicious patterns detected
dist/compiled/react-is/cjs/react-is.development.js safe No malicious patterns detected
dist/compiled/react-is/cjs/react-is.production.js safe This is the legitimate React is.production.js module from the official react-is package, containing only type-checking utilities for React elements with no malicious patterns.
dist/compiled/react-is/index.js safe No malicious patterns detected
dist/compiled/react-refresh/babel.js safe No malicious patterns detected; the file is a standard conditional module export that loads the React Refresh Babel plugin's production or development build based on NODE_ENV.
dist/compiled/react-refresh/cjs/react-refresh-babel.development.js safe This is the official React Refresh Babel plugin with no malicious patterns detected; it performs expected AST transformations and uses crypto for hashing signatures only.
dist/compiled/react-refresh/cjs/react-refresh-runtime.development.js safe The code is the official React Refresh runtime for development mode and contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, or unauthorized network/file/process operations.
dist/compiled/react-refresh/runtime.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack-experimental/cjs/react-server-dom-turbopack-client.browser.production.js safe This is the official React Server DOM Turbopack client runtime; no malicious patterns, exfiltration, credential harvesting, obfuscation, or backdoors were detected.
dist/compiled/react-server-dom-turbopack-experimental/cjs/react-server-dom-turbopack-client.edge.production.js safe This is a legitimate React Server Components client runtime file from Meta's official React repository with no malicious patterns detected.
dist/compiled/react-server-dom-turbopack-experimental/cjs/react-server-dom-turbopack-client.node.production.js safe This is an official React production build for server components; no malicious patterns, data exfiltration, credential harvesting, or backdoor mechanisms were detected.
dist/compiled/react-server-dom-turbopack-experimental/client.browser.js safe No malicious patterns detected; the file is a standard environment-based conditional export for React Server DOM Turbopack.
dist/compiled/react-server-dom-turbopack-experimental/client.edge.js safe No malicious patterns detected; the file is a standard conditional re-export shim for React Server DOM Turbopack client edge builds.
dist/compiled/react-server-dom-turbopack-experimental/client.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack-experimental/client.node.js safe This is a standard React Server DOM Turbopack client entry point that conditionally re-exports production or development builds based on NODE_ENV, with no malicious patterns detected.
dist/compiled/react-server-dom-turbopack-experimental/index.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack-experimental/server.browser.js safe No malicious patterns detected; this is a standard React Server DOM Turbopack entry point that conditionally loads production or development builds and re-exports their APIs.
dist/compiled/react-server-dom-turbopack-experimental/server.edge.js safe No malicious patterns detected; the file is a standard conditional re-export shim for the React Server DOM Turbopack package.
dist/compiled/react-server-dom-turbopack-experimental/server.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-turbopack-experimental/server.node.js safe No malicious patterns detected; the file is a standard entry point that conditionally re-exports symbols from a React Server DOM Turbopack implementation.
dist/compiled/react-server-dom-turbopack-experimental/static.browser.js safe No malicious patterns detected; the file is a standard conditional re-export wrapper for React Server DOM Turbopack.
dist/compiled/react-server-dom-turbopack-experimental/static.edge.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack-experimental/static.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-turbopack-experimental/static.node.js safe This is a simple environment-based module loader for React Server DOM Turbopack that contains no malicious patterns.
dist/compiled/react-server-dom-turbopack/cjs/react-server-dom-turbopack-client.browser.production.js safe This is the official React Server DOM Turbopack client runtime; no malicious patterns, exfiltration, credential harvesting, obfuscation, or backdoors were detected.
dist/compiled/react-server-dom-turbopack/cjs/react-server-dom-turbopack-client.edge.production.js safe This is a legitimate React Server Components client runtime file from Meta's official React repository with no malicious patterns detected.
dist/compiled/react-server-dom-turbopack/cjs/react-server-dom-turbopack-client.node.production.js safe This is an official React production build for server components; no malicious patterns, data exfiltration, credential harvesting, or backdoor mechanisms were detected.
dist/compiled/react-server-dom-turbopack/client.browser.js safe No malicious patterns detected; the file is a standard environment-based conditional export for React Server DOM Turbopack.
dist/compiled/react-server-dom-turbopack/client.edge.js safe No malicious patterns detected; the file is a standard conditional re-export shim for React Server DOM Turbopack client edge builds.
dist/compiled/react-server-dom-turbopack/client.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack/client.node.js safe This is a standard React Server DOM Turbopack client entry point that conditionally re-exports production or development builds based on NODE_ENV, with no malicious patterns detected.
dist/compiled/react-server-dom-turbopack/index.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack/server.browser.js safe No malicious patterns detected; this is a standard React Server DOM Turbopack entry point that conditionally loads production or development builds and re-exports their APIs.
dist/compiled/react-server-dom-turbopack/server.edge.js safe No malicious patterns detected; the file is a standard conditional re-export shim for the React Server DOM Turbopack package.
dist/compiled/react-server-dom-turbopack/server.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-turbopack/server.node.js safe No malicious patterns detected; the file is a standard entry point that conditionally re-exports symbols from a React Server DOM Turbopack implementation.
dist/compiled/react-server-dom-turbopack/static.browser.js safe No malicious patterns detected; the file is a standard conditional re-export wrapper for React Server DOM Turbopack.
dist/compiled/react-server-dom-turbopack/static.edge.js safe No malicious patterns detected
dist/compiled/react-server-dom-turbopack/static.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-turbopack/static.node.js safe This is a simple environment-based module loader for React Server DOM Turbopack that contains no malicious patterns.
dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-client.browser.production.js safe No malicious patterns detected; this is the legitimate React Server Components client runtime for webpack with standard serialization, chunk loading, and reference handling logic.
dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-client.edge.production.js safe This is the legitimate production build of React Server DOM Webpack client code containing no malicious patterns, exfiltration, or code execution risks.
dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-client.node.production.js safe This is the official React Server Components client runtime for Webpack; no malicious patterns, obfuscation, exfiltration, or suspicious behavior detected.
dist/compiled/react-server-dom-webpack-experimental/cjs/react-server-dom-webpack-plugin.js safe No malicious patterns detected; the code is a legitimate React Server Components Webpack plugin from Meta with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behaviors.
dist/compiled/react-server-dom-webpack-experimental/client.browser.js safe No malicious patterns detected; the file is a standard React Server DOM Webpack client entry point that conditionally re-exports production or development builds based on NODE_ENV.
dist/compiled/react-server-dom-webpack-experimental/client.edge.js safe No malicious patterns detected; the file is a simple environment-based module re-export with no suspicious behavior.
dist/compiled/react-server-dom-webpack-experimental/client.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack-experimental/client.node.js safe No malicious patterns detected; this is a standard conditional re-export shim for React Server DOM Webpack client Node build.
dist/compiled/react-server-dom-webpack-experimental/index.js safe No malicious patterns detected; the file only throws an error directing users to the correct entry point.
dist/compiled/react-server-dom-webpack-experimental/node-register.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/react-server-dom-webpack-experimental/plugin.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/react-server-dom-webpack-experimental/server.browser.js safe No malicious patterns detected; the file is a standard environment-based re-export shim for React Server DOM Webpack.
dist/compiled/react-server-dom-webpack-experimental/server.edge.js safe No malicious patterns detected; the file is a standard React Server DOM Webpack entry point that conditionally re-exports from React's official CJS bundles based on NODE_ENV.
dist/compiled/react-server-dom-webpack-experimental/server.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-webpack-experimental/server.node.js safe No malicious patterns detected; this is a standard React Server DOM Webpack entry point that conditionally re-exports functions from bundled CJS files based on NODE_ENV.
dist/compiled/react-server-dom-webpack-experimental/static.browser.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack-experimental/static.edge.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack-experimental/static.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-webpack-experimental/static.node.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-client.browser.production.js safe No malicious patterns detected; this is the legitimate React Server Components client runtime for webpack with standard serialization, chunk loading, and reference handling logic.
dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-client.edge.production.js safe This is the legitimate production build of React Server DOM Webpack client code containing no malicious patterns, exfiltration, or code execution risks.
dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-client.node.production.js safe This is the official React Server Components client runtime for Webpack; no malicious patterns, obfuscation, exfiltration, or suspicious behavior detected.
dist/compiled/react-server-dom-webpack/cjs/react-server-dom-webpack-plugin.js safe No malicious patterns detected; the code is a legitimate React Server Components Webpack plugin from Meta with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behaviors.
dist/compiled/react-server-dom-webpack/client.browser.js safe No malicious patterns detected; the file is a standard React Server DOM Webpack client entry point that conditionally re-exports production or development builds based on NODE_ENV.
dist/compiled/react-server-dom-webpack/client.edge.js safe No malicious patterns detected; the file is a simple environment-based module re-export with no suspicious behavior.
dist/compiled/react-server-dom-webpack/client.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack/client.node.js safe No malicious patterns detected; this is a standard conditional re-export shim for React Server DOM Webpack client Node build.
dist/compiled/react-server-dom-webpack/index.js safe No malicious patterns detected; the file only throws an error directing users to the correct entry point.
dist/compiled/react-server-dom-webpack/node-register.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/react-server-dom-webpack/plugin.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/react-server-dom-webpack/server.browser.js safe No malicious patterns detected; the file is a standard environment-based re-export shim for React Server DOM Webpack.
dist/compiled/react-server-dom-webpack/server.edge.js safe No malicious patterns detected; the file is a standard React Server DOM Webpack entry point that conditionally re-exports from React's official CJS bundles based on NODE_ENV.
dist/compiled/react-server-dom-webpack/server.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-webpack/server.node.js safe No malicious patterns detected; this is a standard React Server DOM Webpack entry point that conditionally re-exports functions from bundled CJS files based on NODE_ENV.
dist/compiled/react-server-dom-webpack/static.browser.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack/static.edge.js safe No malicious patterns detected
dist/compiled/react-server-dom-webpack/static.js safe No malicious patterns detected; the file only throws a guard error when loaded outside a react-server environment.
dist/compiled/react-server-dom-webpack/static.node.js safe No malicious patterns detected
dist/compiled/react/cjs/react-compiler-runtime.development.js safe No malicious patterns detected; the code is a standard React compiler runtime shim with only a development-time error check and no external network, file system, or process interactions.
dist/compiled/react/cjs/react-compiler-runtime.production.js safe No malicious patterns detected
dist/compiled/react/cjs/react-compiler-runtime.profiling.js safe No malicious patterns detected; the file is a legitimate React compiler runtime shim that only re-exports a memoization cache hook from React's shared internals.
dist/compiled/react/cjs/react-jsx-dev-runtime.development.js safe This is the standard React 19 development JSX runtime from Meta; it contains only normal React element creation, validation, and warning logic with no malicious patterns.
dist/compiled/react/cjs/react-jsx-dev-runtime.production.js safe No malicious patterns detected
dist/compiled/react/cjs/react-jsx-dev-runtime.profiling.js safe This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export.
dist/compiled/react/cjs/react-jsx-dev-runtime.react-server.development.js safe No malicious patterns detected; this is a legitimate development build of React's JSX dev runtime.
dist/compiled/react/cjs/react-jsx-dev-runtime.react-server.production.js safe No malicious patterns detected; this is a legitimate React JSX runtime production build with no suspicious behavior.
dist/compiled/react/cjs/react-jsx-runtime.development.js safe This is a legitimate development build of React's JSX runtime from Meta Platforms, containing only React's standard JSX element creation, validation, and development warnings with no malicious patterns.
dist/compiled/react/cjs/react-jsx-runtime.production.js safe No malicious patterns detected
dist/compiled/react/cjs/react-jsx-runtime.profiling.js safe No malicious patterns detected; this is a legitimate React JSX runtime profiling build with no network, filesystem, process, or dynamic execution activity.
dist/compiled/react/cjs/react-jsx-runtime.react-server.development.js safe Legitimate React development build with no malicious patterns detected.
dist/compiled/react/cjs/react-jsx-runtime.react-server.production.js safe This is legitimate React JSX runtime production code with no malicious patterns detected.
dist/compiled/react/cjs/react.development.js safe This is the legitimate React 19 development build (react.development.js) from Meta, containing only standard React runtime internals, deprecation warnings, hook dispatchers, and dev-only error messages with no malicious patterns.
dist/compiled/react/cjs/react.production.js safe No malicious patterns detected; this is the standard React production build with no network, filesystem, process-spawning, or obfuscated behavior.
dist/compiled/react/cjs/react.react-server.development.js safe This is the official React 19 server-side development build with no malicious patterns detected.
dist/compiled/react/cjs/react.react-server.production.js safe This is a legitimate, minified production build of React's react-server package from Meta; no malicious patterns, exfiltration, dynamic execution, or lifecycle-script abuse were detected.
dist/compiled/react/compiler-runtime.js safe No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV.
dist/compiled/react/index.js safe This is a standard React environment-based module export switch with no malicious patterns detected.
dist/compiled/react/jsx-dev-runtime.js safe No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV.
dist/compiled/react/jsx-dev-runtime.react-server.js safe No malicious patterns detected
dist/compiled/react/jsx-runtime.js safe This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected.
dist/compiled/react/jsx-runtime.react-server.js safe This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected.
dist/compiled/react/react.react-server.js safe No malicious patterns detected
dist/compiled/regenerator-runtime/path.js safe No malicious patterns detected
dist/compiled/safe-stable-stringify/index.js safe No malicious patterns detected; this is a bundled, minified implementation of the safe-stable-stringify JSON serializer with no network, filesystem, process, or dynamic code execution behavior.
dist/compiled/scheduler-experimental/cjs/scheduler-unstable_mock.development.js safe No malicious patterns detected; this is the legitimate React scheduler mock implementation with no network, filesystem, process, or obfuscated code activity.
dist/compiled/scheduler-experimental/cjs/scheduler-unstable_mock.production.js safe No malicious patterns detected; this is the legitimate React scheduler unstable mock production build with no network, filesystem, process, or dynamic execution activity.
dist/compiled/scheduler-experimental/cjs/scheduler-unstable_post_task.development.js safe This is the legitimate React Scheduler package using the browser postTask API; no malicious patterns detected.
dist/compiled/scheduler-experimental/cjs/scheduler-unstable_post_task.production.js safe No malicious patterns detected; the file is a legitimate React scheduler implementation that uses standard browser APIs and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/compiled/scheduler-experimental/cjs/scheduler.development.js safe This is a legitimate React scheduler development build with no malicious patterns detected.
dist/compiled/scheduler-experimental/cjs/scheduler.native.development.js safe No malicious patterns detected; the file is the standard React scheduler native development build with only benign timer and message-channel scheduling logic.
dist/compiled/scheduler-experimental/cjs/scheduler.native.production.js safe This is the standard React Scheduler production build with no malicious patterns, external network calls, credential harvesting, or suspicious code execution.
dist/compiled/scheduler-experimental/cjs/scheduler.production.js safe This is the standard React Scheduler production build with no malicious patterns detected.
dist/compiled/scheduler-experimental/index.js safe No malicious patterns detected
dist/compiled/scheduler-experimental/index.native.js safe No malicious patterns detected; the file is a standard React Scheduler environment-based module loader.
dist/compiled/scheduler-experimental/unstable_mock.js safe Standard React Scheduler mock entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected.
dist/compiled/scheduler-experimental/unstable_post_task.js safe No malicious patterns detected
dist/compiled/scheduler/cjs/scheduler-unstable_mock.development.js safe No malicious patterns detected; this is the legitimate React scheduler mock implementation with no network, filesystem, process, or obfuscated code activity.
dist/compiled/scheduler/cjs/scheduler-unstable_mock.production.js safe No malicious patterns detected; this is the legitimate React scheduler unstable mock production build with no network, filesystem, process, or dynamic execution activity.
dist/compiled/scheduler/cjs/scheduler-unstable_post_task.development.js safe This is the legitimate React Scheduler package using the browser postTask API; no malicious patterns detected.
dist/compiled/scheduler/cjs/scheduler-unstable_post_task.production.js safe No malicious patterns detected; the file is a legitimate React scheduler implementation that uses standard browser APIs and does not contain exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/compiled/scheduler/cjs/scheduler.development.js safe This is the legitimate React scheduler development build from Meta with no malicious patterns detected; it only contains standard task scheduling logic, timer/heap management, and React DevTools hook integration.
dist/compiled/scheduler/cjs/scheduler.native.development.js safe No malicious patterns detected
dist/compiled/scheduler/cjs/scheduler.native.production.js safe This is the official React scheduler production build for React Native, containing only legitimate task scheduling logic with no malicious patterns.
dist/compiled/scheduler/cjs/scheduler.production.js safe No malicious patterns detected; this is the standard React Scheduler production build with expected internal task scheduling logic and no suspicious behavior.
dist/compiled/scheduler/index.js safe No malicious patterns detected
dist/compiled/scheduler/index.native.js safe No malicious patterns detected; the file is a standard React Scheduler environment-based module loader.
dist/compiled/scheduler/unstable_mock.js safe Standard React Scheduler mock entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected.
dist/compiled/scheduler/unstable_post_task.js safe No malicious patterns detected
dist/compiled/semver/index.js safe This is a standard minified build of the semver library with no malicious patterns detected.
dist/compiled/send/index.js safe No malicious patterns detected
dist/compiled/server-only/empty.js safe Cleared by Jev triage; no further analysis needed
dist/compiled/server-only/index.js safe No malicious patterns detected; the code simply throws an error to enforce server-only usage.
dist/compiled/shell-quote/index.js safe This is the legitimate shell-quote npm package that parses and quotes shell commands; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or process spawning were detected.
dist/compiled/source-map/source-map.js safe The code is a standard source-map library with no malicious patterns, data exfiltration, or dynamic code execution detected.
dist/compiled/source-map08/source-map.js safe This is the standard Mozilla source-map library with no malicious patterns detected.
dist/compiled/stacktrace-parser/stack-trace-parser.cjs.js safe No malicious patterns detected; the file is a standard stack trace parser compiled by ncc with no network, filesystem, or process execution activity.
dist/compiled/stream-browserify/index.js safe No malicious patterns detected
dist/compiled/stream-http/index.js safe No malicious patterns detected; this is a standard polyfill/browser build of the Node.js stream-http package.
dist/compiled/string-hash/index.js safe The code implements a standard djb2 string hash function bundled with ncc, with no malicious patterns, external communications, or system interactions.
dist/compiled/string_decoder/string_decoder.js safe No malicious patterns detected; this is a bundled version of the standard Node.js string_decoder module with only a safe fallback for older Buffer implementations.
dist/compiled/strip-ansi/index.js safe The code is a minified/compiled version of the strip-ansi package that only performs ANSI escape code stripping with no malicious behavior.
dist/compiled/superstruct/index.cjs safe No malicious patterns detected
dist/compiled/text-table/index.js safe No malicious patterns detected; the file is a minified bundle of the text-table npm package containing only table formatting logic with no network, filesystem, or execution risks.
dist/compiled/tty-browserify/index.js safe This is a standard browserify shim for the Node.js tty module that safely stubs out isatty and stream constructors without any malicious patterns.
dist/compiled/ua-parser-js/ua-parser.js safe The code is a legitimate User-Agent parser (ua-parser-js) with no malicious patterns, obfuscation, data exfiltration, or suspicious behavior detected.
dist/compiled/unistore/unistore.js safe No malicious patterns detected; the code is a minified implementation of the 'unistore' state management library with no network, filesystem, or process operations.
dist/compiled/util/util.js safe This is a minified/bundled version of the Node.js built-in 'util' module (polyfills from browserify) with no malicious patterns, network calls, credential harvesting, or dynamic execution beyond standard capability checks.
dist/compiled/watchpack/watchpack.js safe No malicious patterns detected
dist/compiled/web-vitals-attribution/web-vitals.attribution.js safe This is a legitimate minified build of Google's web-vitals attribution library; no malicious patterns detected.
dist/compiled/web-vitals/web-vitals.js safe No malicious patterns detected; this is a standard web-vitals performance monitoring library.
dist/compiled/webpack-sources1/index.js safe This is a legitimate webpack-sources library bundle for source map generation and manipulation, with no malicious patterns detected.
dist/compiled/webpack-sources3/index.js safe No malicious patterns detected; this is a standard Webpack source helper library with no network, filesystem, credential, or subprocess abuse.
dist/compiled/webpack/BasicEvaluatedExpression.js safe No malicious patterns detected
dist/compiled/webpack/ExternalsPlugin.js safe No malicious patterns detected
dist/compiled/webpack/FetchCompileAsyncWasmPlugin.js safe The file is a simple re-export of a webpack plugin with no executable logic or suspicious patterns.
dist/compiled/webpack/FetchCompileWasmPlugin.js safe No malicious patterns detected
dist/compiled/webpack/FetchCompileWasmTemplatePlugin.js safe No malicious patterns detected
dist/compiled/webpack/GraphHelpers.js safe No malicious patterns detected; this is a simple webpack internal module re-export with no dynamic behavior.
dist/compiled/webpack/HotModuleReplacement.runtime.js safe This is a standard Webpack Hot Module Replacement runtime file with no malicious patterns detected.
dist/compiled/webpack/JavascriptHotModuleReplacement.runtime.js safe No malicious patterns detected; this is standard webpack Hot Module Replacement runtime code with no network, credential, obfuscation, or process-spawning behavior.
dist/compiled/webpack/LibraryTemplatePlugin.js safe No malicious patterns detected; the file simply re-exports a webpack internal module.
dist/compiled/webpack/LimitChunkCountPlugin.js safe This file is a simple re-export of the LimitChunkCountPlugin from the webpack main module and contains no malicious patterns.
dist/compiled/webpack/ModuleFilenameHelpers.js safe This file simply re-exports a webpack helper module and contains no malicious patterns, network activity, or dynamic code execution.
dist/compiled/webpack/NodeEnvironmentPlugin.js safe This is a simple re-export shim that imports NodeEnvironmentPlugin from the webpack module with no suspicious behavior.
dist/compiled/webpack/NodeTargetPlugin.js safe No malicious patterns detected
dist/compiled/webpack/NodeTemplatePlugin.js safe No malicious patterns detected; the file is a simple re-export of a webpack plugin from the webpack module.
dist/compiled/webpack/NormalModule.js safe No malicious patterns detected
dist/compiled/webpack/SingleEntryPlugin.js safe No malicious patterns detected
dist/compiled/webpack/SourceMapDevToolModuleOptionsPlugin.js safe No malicious patterns detected
dist/compiled/webpack/WebWorkerTemplatePlugin.js safe No malicious patterns detected
dist/compiled/webpack/lazy-compilation-web.js safe No malicious patterns detected; the code is a standard webpack lazy-compilation helper using EventSource for hot module replacement.
dist/compiled/webpack/package.js safe The file is a one-line re-export of a module from webpack.js with no malicious patterns or suspicious behavior.
dist/compiled/webpack/sources.js safe No malicious patterns detected
dist/compiled/webpack/webpack-lib.js safe No malicious patterns detected
dist/compiled/webpack/webpack.js safe No malicious patterns detected; the code performs conditional module loading for webpack/rspack bundler exports without exfiltration, obfuscation, or execution of untrusted input.
dist/compiled/write-file-atomic/index.js safe This is a legitimate, minified build of the write-file-atomic npm package, implementing atomic file writes with no malicious patterns or suspicious behavior.
dist/compiled/ws/index.js safe No malicious patterns detected
dist/compiled/zod-validation-error/index.js safe No malicious patterns detected; the code is a legitimate Zod validation error formatting library with no network, filesystem, process, or credential access.
dist/compiled/zod/index.cjs safe No malicious patterns detected; this is a standard webpack/ncc-bundled build of the Zod validation library with no data exfiltration, credential harvesting, obfuscated payloads, or suspicious runtime behavior.
dist/diagnostics/build-diagnostics.js safe No malicious patterns detected; this file only writes build diagnostics to local files under the configured distDir.
dist/esm/api/app-dynamic.js safe The file is a simple re-export module that only forwards exports from a shared internal library, with no suspicious or malicious code patterns.
dist/esm/api/app.js safe No malicious patterns detected; this is a simple re-export module pointing to a local _app file with no external network, process, filesystem, or dynamic code execution behavior.
dist/esm/api/constants.js safe This file is a simple re-export of constants from a shared library with no malicious patterns detected.
dist/esm/api/document.js safe No malicious patterns detected; the file only re-exports a local _document module.
dist/esm/api/dynamic.js safe No malicious patterns detected
dist/esm/api/error.js safe This file only contains standard re-export statements with no malicious patterns detected
dist/esm/api/error.react-server.js safe No malicious patterns detected
dist/esm/api/form.js safe No malicious patterns detected
dist/esm/api/head.js safe No malicious patterns detected
dist/esm/api/headers.js safe No malicious patterns detected
dist/esm/api/image.js safe This file only re-exports an image library from a shared internal module with no suspicious code patterns.
dist/esm/api/link.js safe No malicious patterns detected
dist/esm/api/navigation.js safe No malicious patterns detected; the file is a simple re-export from a local client component.
dist/esm/api/navigation.react-server.js safe No malicious patterns detected
dist/esm/api/og.js safe No malicious patterns detected
dist/esm/api/router.js safe This is a simple re-export module that only re-exports from a relative client router module, with no malicious patterns detected.
dist/esm/api/script.js safe No malicious patterns detected
dist/esm/api/server.js safe No malicious patterns detected; the file only re-exports from an internal module.
dist/esm/build/adapter/setup-node-env.external.js safe No malicious patterns detected; the file only conditionally requires trusted Next.js server modules to initialize the Node.js environment.
dist/esm/build/analysis/extract-const-value.js safe No malicious patterns detected; the code is a pure static AST value extraction utility with no network, filesystem, process, or dynamic execution behavior.
dist/esm/build/analysis/get-page-static-info.js safe This is a legitimate Next.js internal module for analyzing page static info; no malicious patterns detected.
dist/esm/build/analysis/parse-module.js safe No malicious patterns detected; the code performs benign cached parsing of module content using SWC with Node's crypto for hashing.
dist/esm/build/analyze/index.js safe No malicious patterns detected; the file is a legitimate Next.js build analyzer entry point that reads config, writes local build artifacts, and serves a local HTTP bundle analyzer.
dist/esm/build/babel/loader/get-config.js safe The file is a legitimate Next.js Babel loader configuration module with only standard dynamic require and readFileSync for loading user-provided Babel configs; no malicious patterns were found.
dist/esm/build/babel/loader/index.js safe No malicious patterns detected; this is a legitimate Babel loader for Next.js that transforms source code without any suspicious behavior.
dist/esm/build/babel/loader/transform.js safe No malicious patterns detected
dist/esm/build/babel/loader/util.js safe No malicious patterns detected
dist/esm/build/babel/plugins/commonjs.js safe The code is a legitimate Babel plugin that conditionally applies the CommonJS transform and contains no malicious patterns.
dist/esm/build/babel/plugins/jsx-pragma.js safe This is a standard Next.js Babel plugin that adds JSX pragma imports/requires for React; no malicious patterns, network calls, process spawning, or obfuscation were detected.
dist/esm/build/babel/plugins/next-font-unsupported.js safe This Babel plugin only throws a descriptive error when specific next/font imports are detected; it performs no network, filesystem, process, or dynamic code execution, and contains no malicious patterns.
dist/esm/build/babel/plugins/next-page-config.js safe This is a legitimate Next.js Babel plugin that validates page config exports and contains no malicious patterns.
dist/esm/build/babel/plugins/next-page-disallow-re-export-all-exports.js safe This is a legitimate Next.js Babel plugin that throws a SyntaxError when export * from '...' is used in a page, and contains no malicious patterns.
dist/esm/build/babel/plugins/next-ssg-transform.js safe No malicious patterns detected
dist/esm/build/babel/plugins/optimize-hook-destructuring.js safe This is a legitimate Babel plugin that optimizes React hook destructuring; no malicious patterns were detected.
dist/esm/build/babel/plugins/react-loadable-plugin.js safe This Babel plugin for Next.js dynamic imports performs static code transformations and does not exhibit any malicious behavior such as data exfiltration, credential harvesting, or dynamic code execution.
dist/esm/build/babel/preset.js safe No malicious patterns detected; the file is a standard Babel preset configuration for Next.js with expected requires and environment variable usage.
dist/esm/build/browser-variant-modules.js safe The file is a static, auto-generated array of module path strings used for browser build aliasing; it contains no executable logic, network activity, credential access, dynamic imports, or other malicious patterns.
dist/esm/build/build-context.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/collect-build-traces.js safe No malicious patterns detected; the code is standard Next.js build tracing logic without exfiltration, credential harvesting, obfuscation, or backdoor behavior.
dist/esm/build/compiler.js safe No malicious patterns detected; the code is a standard webpack compiler wrapper for Next.js with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/build/create-compiler-aliases.js safe This file contains Next.js webpack alias configuration logic with no malicious patterns, no network activity, no credential access, and no dynamic code execution.
dist/esm/build/define-env.js safe This file is part of Next.js build tooling that serializes environment variables into define-env expressions for bundler replacement, with no malicious patterns detected.
dist/esm/build/duration-to-string.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/entries.js safe No malicious patterns detected; the code is a legitimate Next.js build entry configuration module.
dist/esm/build/file-classifier.js safe No malicious patterns detected
dist/esm/build/generate-build-id.js safe No malicious patterns detected
dist/esm/build/generate-routes-manifest.js safe No malicious patterns detected; the file contains legitimate Next.js route manifest generation logic with no network, filesystem, or dynamic code execution concerns.
dist/esm/build/get-babel-config-file.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/get-babel-loader-config.js safe No malicious patterns detected; the code performs legitimate Babel/React Compiler loader configuration using only local module resolution and path operations.
dist/esm/build/get-static-info-including-layouts.js safe No malicious patterns detected
dist/esm/build/get-supported-browsers.js safe No malicious patterns detected; the code safely reads browserslist configuration and returns browser targets without any exfiltration, execution, or filesystem manipulation.
dist/esm/build/handle-entrypoints.js safe This file contains only Next.js/Turbopack entrypoint processing logic with no network, filesystem, process execution, or obfuscated malicious patterns.
dist/esm/build/handle-externals.js safe No malicious patterns detected; the code is legitimate Next.js webpack external-handling logic with no data exfiltration, credential harvesting, obfuscation, or command execution.
dist/esm/build/is-writeable.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/load-entrypoint.js safe No malicious patterns detected; the code performs local template file loading and string replacement using known SWC bindings and standard Node.js APIs.
dist/esm/build/lockfile.js safe No malicious patterns detected; the code implements a legitimate cross-platform advisory lockfile utility for a Next.js dev server.
dist/esm/build/manifests/formatter/format-manifest.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/next-dir-paths.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/normalize-catchall-routes.js safe No malicious patterns detected; the code only normalizes catch-all route paths using local utilities.
dist/esm/build/output/format.js safe No malicious patterns detected; the file only contains pure functions for formatting time durations and cache-control values.
dist/esm/build/output/index.js safe No malicious patterns detected; the file is part of Next.js build-utility code for managing webpack compiler state and reporting errors/warnings.
dist/esm/build/output/log.js safe No malicious patterns detected; the file only provides console logging utilities with no network, filesystem, process, or credential access.
dist/esm/build/output/store.js safe No malicious patterns detected; the code is standard Next.js build store logic with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/esm/build/page-extensions-type.js safe No malicious patterns detected
dist/esm/build/polyfills/fetch/index.js safe No malicious patterns detected
dist/esm/build/polyfills/fetch/whatwg-fetch.js safe The file simply re-exports fetch API primitives from the global self object and contains no malicious patterns.
dist/esm/build/polyfills/object-assign.js safe No malicious patterns detected
dist/esm/build/polyfills/object.assign/auto.js safe The file contains only a no-op comment and a source map reference, with no executable code or malicious patterns.
dist/esm/build/polyfills/object.assign/implementation.js safe No malicious patterns detected
dist/esm/build/polyfills/object.assign/index.js safe The code is a standard polyfill or shim for Object.assign, containing no malicious patterns, network activity, or suspicious behavior.
dist/esm/build/polyfills/object.assign/polyfill.js safe No malicious patterns detected
dist/esm/build/polyfills/object.assign/shim.js safe No malicious patterns detected
dist/esm/build/polyfills/process.js safe No malicious patterns detected; the code is a standard environment-detection polyfill for Next.js process.
dist/esm/build/print-build-errors.js safe No malicious patterns detected; the code is a benign Turbopack build error/warning formatter with no network, filesystem, process, or dynamic execution behavior.
dist/esm/build/progress.js safe No malicious patterns detected; the file implements a benign progress bar utility using only local logging and terminal output.
dist/esm/build/rendering-mode.js safe No malicious patterns detected
dist/esm/build/segment-config/app/app-segment-config.js safe This file is a legitimate Next.js configuration schema validator using Zod with no malicious patterns, network calls, process spawning, or file system manipulation.
dist/esm/build/segment-config/app/app-segments.js safe No malicious patterns detected
dist/esm/build/segment-config/app/collect-root-param-keys.js safe No malicious patterns detected; the code is a standard Next.js utility for collecting route parameter keys with no exfiltration, dynamic execution, or suspicious behavior.
dist/esm/build/segment-config/middleware/middleware-config.js safe This is a legitimate Next.js middleware configuration validation module using zod schemas and picomatch; no malicious patterns, external requests, dynamic code execution, or file system manipulation were detected.
dist/esm/build/segment-config/pages/pages-segment-config.js safe No malicious patterns detected
dist/esm/build/sort-by-page-exts.js safe No malicious patterns detected
dist/esm/build/spinner.js safe No malicious patterns detected; the code is a standard terminal spinner utility with console method interception for UI purposes only.
dist/esm/build/static-paths/app.js safe No malicious patterns detected; the code is a legitimate Next.js internal module for generating static paths and route parameters without any data exfiltration, credential harvesting, obfuscation, or other suspicious behaviors.
dist/esm/build/static-paths/app/extract-pathname-route-param-segments-from-loader-tree.js safe No malicious patterns detected
dist/esm/build/static-paths/pages.js safe No malicious patterns detected; the code implements Next.js static path generation with proper input validation and no external communication or dangerous operations.
dist/esm/build/static-paths/types.js safe No malicious patterns detected
dist/esm/build/static-paths/utils.js safe No malicious patterns detected in the provided JavaScript utility file.
dist/esm/build/swc/helpers.js safe The file contains only a trivial identity helper function with no malicious patterns.
dist/esm/build/swc/index.js safe This is the standard Next.js SWC native bindings loader that conditionally loads platform-specific binaries from expected package locations and environment-configured testing paths, with no malicious patterns detected.
dist/esm/build/swc/install-bindings.js safe The file only contains a lazy, static require of a sibling module to control NODE_ENV-dependent loading order; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution were found.
dist/esm/build/swc/jest-transformer.js safe The file is a legitimate Jest transformer for SWC, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized network/file system access.
dist/esm/build/swc/options.js safe This is legitimate Next.js SWC configuration code with no malicious patterns detected.
dist/esm/build/swc/types.js safe No malicious patterns detected
dist/esm/build/templates/app-page.js safe This is a standard Next.js App Router page entrypoint template with no malicious patterns, external data flows, or dynamic execution.
dist/esm/build/templates/app-route.js safe This is a legitimate Next.js internal App Route module handler template with no malicious patterns detected; the dynamic require('VAR_USERLAND') is a framework placeholder for user route code, not obfuscated or externally controlled execution.
dist/esm/build/templates/edge-app-route.js safe This is a standard Next.js edge route build template with no malicious patterns; the placeholders and env var reads are legitimate framework internals, not exfiltration or backdoors.
dist/esm/build/templates/edge-ssr-app.js safe This is a legitimate Next.js Edge SSR app template file that contains no malicious patterns; it imports local modules, sets up rendering context, and handles requests using standard Next.js server APIs.
dist/esm/build/templates/edge-ssr.js safe No malicious patterns detected; this is a standard Next.js edge SSR runtime template with expected server-side rendering logic and no data exfiltration, credential harvesting, obfuscation, or backdoor indicators.
dist/esm/build/templates/helpers.js safe No malicious patterns detected; the code is a simple utility function for hoisting named exports from modules or promises.
dist/esm/build/templates/middleware.js safe This is legitimate Next.js middleware runtime code with no malicious patterns; dynamic require calls reference internal Next.js modules only and all imports are static and internal.
dist/esm/build/templates/pages-api.js safe No malicious patterns detected; the file is a standard Next.js Pages API route module template with legitimate framework imports and no exfiltration, obfuscation, or suspicious behavior.
dist/esm/build/templates/pages-edge-api.js safe This is a standard Next.js Edge API page template with no malicious patterns; the VAR_* placeholders are build-time substitutions and all imports reference internal server modules.
dist/esm/build/templates/pages.js safe This file is a standard Next.js pages route module template with only static imports, re-exports, and configuration object creation; no malicious patterns detected.
dist/esm/build/turbopack-analyze/index.js safe No malicious patterns detected; the file is a legitimate Next.js/Turbopack analysis module that configures and runs the build analyzer without exfiltration, credential harvesting, obfuscation, or suspicious process/network activity.
dist/esm/build/turbopack-build/impl.js safe This is legitimate Next.js/Turbopack build implementation code with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors detected.
dist/esm/build/turbopack-build/index.js safe No malicious patterns detected; the code is a standard Next.js Turbopack build worker implementation with legitimate dynamic imports and environment variable usage.
dist/esm/build/turborepo-access-trace/helpers.js safe No malicious patterns detected; the code performs legitimate access tracing for Turborepo with no exfiltration, obfuscation, or suspicious behavior.
dist/esm/build/turborepo-access-trace/index.js safe No malicious patterns detected
dist/esm/build/turborepo-access-trace/result.js safe No malicious patterns detected; the file contains a pure data-aggregation class for Turborepo access tracing with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/build/turborepo-access-trace/types.js safe The file contains only TypeScript-style comments and an empty export statement with no executable logic or malicious patterns.
dist/esm/build/type-check.js safe No malicious patterns detected; the code is a standard Next.js TypeScript type-checking orchestration module using a worker, with no data exfiltration, credential harvesting, obfuscation, or suspicious process execution.
dist/esm/build/utils.js safe This is a legitimate Next.js build utility module from the official next package; no malicious patterns, exfiltration, credential harvesting, obfuscation, or unauthorized process execution were detected.
dist/esm/build/validate-app-paths.js safe This is a legitimate Next.js internal route validation module with no malicious patterns, network activity, credential access, or dynamic code execution.
dist/esm/build/warn-about-edge-runtime.js safe No malicious patterns detected
dist/esm/build/webpack-build/impl.js safe No malicious patterns detected; the code is part of Next.js build tooling with standard compilation operations.
dist/esm/build/webpack-build/index.js safe No malicious patterns detected; the code is a legitimate Next.js build orchestration module that spawns internal webpack worker processes and manages build telemetry state without exfiltration or obfuscation.
dist/esm/build/webpack-config-rules/resolve.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/alias/react-dom-server-experimental.js safe No malicious patterns detected; the file is a standard Next.js compatibility shim that conditionally loads official React DOM server builds based on environment and throws errors for legacy APIs.
dist/esm/build/webpack/alias/react-dom-server.js safe This is a legitimate Next.js shim that conditionally requires official React DOM server builds and throws an error for deprecated legacy APIs, with no malicious patterns detected.
dist/esm/build/webpack/cache-invalidation.js safe No malicious patterns detected; the code performs legitimate filesystem cache invalidation and cleanup operations within the provided cache directory.
dist/esm/build/webpack/config/blocks/base.js safe This is a legitimate Next.js webpack configuration module with no malicious patterns detected.
dist/esm/build/webpack/config/blocks/css/loaders/client.js safe This is a standard Next.js webpack CSS loader configuration with no malicious patterns detected.
dist/esm/build/webpack/config/blocks/css/loaders/file-resolve.js safe No malicious patterns detected; the code is a simple URL validation helper for CSS file resolution in a webpack config.
dist/esm/build/webpack/config/blocks/css/loaders/getCssModuleLocalIdent.js safe No malicious patterns detected; the code is a standard CSS module local identifier generator with no network, filesystem, process, or dynamic execution activity.
dist/esm/build/webpack/config/blocks/css/loaders/global.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/config/blocks/css/loaders/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/config/blocks/css/loaders/modules.js safe No malicious patterns detected
dist/esm/build/webpack/config/blocks/css/loaders/next-font.js safe This module is a standard Next.js webpack loader configuration that assembles CSS/font loaders without any malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or file system/process manipulation.
dist/esm/build/webpack/config/blocks/css/messages.js safe No malicious patterns detected; the file only contains static error message helper functions for Next.js CSS import validation.
dist/esm/build/webpack/config/blocks/images/index.js safe No malicious patterns detected; the file is a standard Next.js webpack configuration block for handling images.
dist/esm/build/webpack/config/blocks/images/messages.js safe No malicious patterns detected
dist/esm/build/webpack/config/helpers.js safe No malicious patterns detected; the file contains only standard webpack configuration helper functions with no exfiltration, obfuscation, or dangerous operations.
dist/esm/build/webpack/config/index.js safe No malicious patterns detected; the file is a standard webpack configuration builder for Next.js with no network, filesystem, process execution, or obfuscation red flags.
dist/esm/build/webpack/config/utils.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/css-loader/src/CssSyntaxError.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/css-loader/src/camelcase.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/css-loader/src/index.js safe No malicious patterns detected; this is a legitimate css-loader source file for webpack that performs standard CSS import parsing and module handling.
dist/esm/build/webpack/loaders/css-loader/src/plugins/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-icss-parser.js safe No malicious patterns detected; this is a standard CSS Modules ICSS parser plugin from Next.js with no network, filesystem, process, or obfuscated code concerns.
dist/esm/build/webpack/loaders/css-loader/src/plugins/postcss-import-parser.js safe No malicious patterns detected; the code is a legitimate PostCSS import parser from Next.js CSS loader with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/build/webpack/loaders/css-loader/src/runtime/api.js safe No malicious patterns detected; this is the standard css-loader runtime API for building CSS strings with source maps.
dist/esm/build/webpack/loaders/css-loader/src/runtime/getUrl.js safe This is a legitimate CSS loader utility function for URL handling with no malicious patterns detected
dist/esm/build/webpack/loaders/css-loader/src/utils.js safe No malicious patterns detected; the file contains standard CSS-loader utility functions without data exfiltration, credential harvesting, obfuscation, dynamic code execution, or process spawning.
dist/esm/build/webpack/loaders/devtool/devtool-style-inject.js safe This is a benign Next.js devtools utility that injects styles into a shadow DOM element and observes DOM mutations; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or command execution were found.
dist/esm/build/webpack/loaders/empty-loader.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/error-loader.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/get-module-build-info.js safe No malicious patterns detected; the code is a simple getter function for webpack module build info.
dist/esm/build/webpack/loaders/instrumentation-client-stub.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/loaders/lightningcss-loader/src/codegen.js safe No malicious patterns detected; the code is a legitimate webpack CSS loader code generator that only produces import/export strings and CSS module code without network, filesystem, or process access.
dist/esm/build/webpack/loaders/lightningcss-loader/src/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/loaders/lightningcss-loader/src/interface.js safe The file only defines a simple enum-like object for cache keys and contains no malicious patterns, network calls, credential harvesting, or dynamic code execution.
dist/esm/build/webpack/loaders/lightningcss-loader/src/loader.js safe This is a legitimate Next.js lightningcss-loader module for webpack that handles CSS transformation with no malicious patterns detected.
dist/esm/build/webpack/loaders/lightningcss-loader/src/minify.js safe This webpack plugin for CSS minification using lightningcss contains no malicious patterns; it performs legitimate asset transformation using local bindings and standard webpack APIs.
dist/esm/build/webpack/loaders/lightningcss-loader/src/utils.js safe No malicious patterns detected; the code only converts browserslist targets to Lightning CSS target versions with simple caching.
dist/esm/build/webpack/loaders/metadata/types.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/modularize-import-loader.js safe No malicious patterns detected; the loader performs a straightforward re-export transformation without any security-sensitive operations.
dist/esm/build/webpack/loaders/next-app-loader/create-app-route-code.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-app-loader/index.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-barrel-loader.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-client-pages-loader.js safe No malicious patterns detected; this is a legitimate Next.js webpack loader that generates a client-side page registration snippet using standard module APIs.
dist/esm/build/webpack/loaders/next-edge-app-route-loader/index.js safe This is a standard Next.js webpack loader that processes module options and constructs entrypoints; no malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or shell commands were detected.
dist/esm/build/webpack/loaders/next-edge-function-loader.js safe The loader only reads build options provided by the invoking webpack config, parses trusted base64 middleware config, and generates an ESM wrapper for a Next.js Edge Function; no malicious patterns detected.
dist/esm/build/webpack/loaders/next-edge-ssr-loader/index.js safe No malicious patterns detected; the code is a legitimate Next.js webpack loader for edge SSR bundling.
dist/esm/build/webpack/loaders/next-error-browser-binary-loader.js safe No malicious patterns detected; the loader simply throws an error when a Node.js binary module is imported in the browser.
dist/esm/build/webpack/loaders/next-flight-action-entry-loader.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-flight-client-entry-loader.js safe No malicious patterns detected; the code is a legitimate Next.js webpack loader that generates dynamic import statements for client modules.
dist/esm/build/webpack/loaders/next-flight-client-module-loader.js safe No malicious patterns detected in the webpack loader; it performs expected build-time source transformation and metadata assignment without exfiltration, obfuscation, or process execution.
dist/esm/build/webpack/loaders/next-flight-css-loader.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-flight-loader/action-client-wrapper.js safe The file only re-exports internal Next.js and React server component utilities with no malicious patterns, network calls, or dynamic code execution.
dist/esm/build/webpack/loaders/next-flight-loader/action-validate.js safe No malicious patterns detected; the code is a straightforward runtime validation helper for Next.js server action exports.
dist/esm/build/webpack/loaders/next-flight-loader/cache-wrapper.js safe This file is a simple re-export of a cache function from an internal Next.js module with no malicious patterns.
dist/esm/build/webpack/loaders/next-flight-loader/index.js safe No malicious patterns detected; this is a legitimate Next.js webpack loader for React Server Components.
dist/esm/build/webpack/loaders/next-flight-loader/module-proxy.js safe No malicious patterns detected; the file only re-exports a React Server Components proxy helper without any suspicious behavior.
dist/esm/build/webpack/loaders/next-flight-loader/server-reference.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-flight-loader/track-dynamic-import.js safe This is a simple re-export module from Next.js internal code with no malicious patterns detected.
dist/esm/build/webpack/loaders/next-flight-server-reference-proxy-loader.js safe No malicious patterns detected; the loader only generates a static import and call to a trusted internal helper using validated option values.
dist/esm/build/webpack/loaders/next-font-loader/postcss-next-font.js safe The code is a legitimate Next.js PostCSS plugin for next/font that processes @font-face declarations with no malicious patterns, network requests, or dynamic code execution.
dist/esm/build/webpack/loaders/next-image-loader/blur.js safe No malicious patterns detected in the Next.js image blur loader; it performs legitimate image resizing and base64 encoding with no external data exfiltration, credential harvesting, or command execution.
dist/esm/build/webpack/loaders/next-image-loader/index.js safe Next.js image loader that computes image metadata/hashes and emits files; no malicious patterns detected.
dist/esm/build/webpack/loaders/next-invalid-import-error-loader.js safe No malicious patterns detected; the loader simply throws an error with a custom message and conditionally clears the stack.
dist/esm/build/webpack/loaders/next-metadata-image-loader.js safe The code is a legitimate Next.js webpack loader for metadata images with no malicious patterns detected; minor dynamic code generation and file reads are expected loader behaviors.
dist/esm/build/webpack/loaders/next-metadata-route-loader.js safe No malicious patterns detected; this is Next.js's legitimate metadata route webpack loader that reads local asset files and generates route code for sitemaps, robots, manifest, and social images.
dist/esm/build/webpack/loaders/next-middleware-asset-loader.js safe No malicious patterns detected; the loader performs standard webpack asset emission and path interpolation without any suspicious behavior.
dist/esm/build/webpack/loaders/next-middleware-loader.js safe The file is a standard Next.js webpack loader that decodes base64-encoded matcher and middleware configuration options and loads the middleware entrypoint, with no malicious patterns detected.
dist/esm/build/webpack/loaders/next-middleware-wasm-loader.js safe No malicious patterns detected; the loader only computes a SHA-1 hash of the WASM source for naming and emits the file via the webpack build API.
dist/esm/build/webpack/loaders/next-root-params-loader.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/loaders/next-route-loader/index.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/next-style-loader/index.js safe The file is a legitimate Next.js style loader that generates code for injecting CSS, with no malicious patterns such as data exfiltration, credential harvesting, or arbitrary code execution.
dist/esm/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoLinkTag.js safe This is a legitimate Next.js style-loader runtime that injects <link> tags for stylesheets with no malicious patterns, external calls, or obfuscation.
dist/esm/build/webpack/loaders/next-style-loader/runtime/injectStylesIntoStyleTag.js safe This is a standard Next.js/webpack style-loader runtime for injecting CSS into the DOM; it contains no malicious patterns, network calls, credential harvesting, or dynamic code execution.
dist/esm/build/webpack/loaders/next-style-loader/runtime/isEqualLocals.js safe No malicious patterns detected; the file is a simple utility function for comparing CSS module locals with no network, file system, process, or dynamic execution behavior.
dist/esm/build/webpack/loaders/next-swc-loader.js safe No malicious patterns detected; this is the legitimate Next.js SWC webpack loader that transforms source code via the SWC compiler.
dist/esm/build/webpack/loaders/postcss-loader/src/Error.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/postcss-loader/src/Warning.js safe No malicious patterns detected; the file is a benign PostCSS warning wrapper class with a harmless Next.js error code annotation.
dist/esm/build/webpack/loaders/postcss-loader/src/index.js safe The code is a standard PostCSS loader for webpack that performs legitimate CSS processing and does not contain any malicious patterns.
dist/esm/build/webpack/loaders/postcss-loader/src/utils.js safe No malicious patterns detected; the code only normalizes source map paths without network, filesystem, or execution risks.
dist/esm/build/webpack/loaders/resolve-url-loader/index.js safe No malicious patterns detected; the file is a legitimate webpack loader for resolving url() paths in CSS, with standard use of source maps, PostCSS, and async callbacks.
dist/esm/build/webpack/loaders/resolve-url-loader/lib/file-protocol.js safe No malicious patterns detected
dist/esm/build/webpack/loaders/resolve-url-loader/lib/join-function.js safe No malicious patterns detected; the code is a standard resolve-url-loader utility for resolving file paths with debug logging and contains no exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior.
dist/esm/build/webpack/loaders/resolve-url-loader/lib/postcss.js safe The code is a legitimate PostCSS plugin for resolving URLs in CSS, with no malicious patterns detected.
dist/esm/build/webpack/loaders/resolve-url-loader/lib/value-processor.js safe No malicious patterns detected; the code is a legitimate webpack loader utility for resolving url() statements in CSS values.
dist/esm/build/webpack/loaders/utils.js safe No malicious patterns detected; the code is a legitimate Next.js webpack loader utility with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/build/webpack/plugins/build-manifest-plugin-utils.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/build-manifest-plugin.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/copy-file-plugin.js safe No malicious patterns detected; the code is a standard webpack plugin that reads a local file and emits it as an asset with caching, using only approved Next.js compiled dependencies.
dist/esm/build/webpack/plugins/css-chunking-plugin.js safe No malicious patterns detected; the code is a legitimate webpack CSS chunking plugin that only manipulates compilation chunks and reads a non-sensitive environment variable for optional summary output.
dist/esm/build/webpack/plugins/css-minimizer-plugin.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/deferred-entries-plugin.js safe This is a legitimate Next.js webpack plugin that manages deferred entrypoints without any malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/build/webpack/plugins/devtools-ignore-list-plugin.js safe The webpack plugin only manipulates source map assets to add an ignore list for devtools; no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or shell commands were detected.
dist/esm/build/webpack/plugins/flight-client-entry-plugin.js safe No malicious patterns detected; code is a legitimate Next.js webpack plugin for managing client entries and server action manifests.
dist/esm/build/webpack/plugins/flight-manifest-plugin.js safe No malicious patterns detected; this is a standard Next.js webpack plugin that generates React Server Component client reference manifests.
dist/esm/build/webpack/plugins/force-complete-runtime.js safe No malicious patterns detected; the plugin is a benign Webpack runtime configuration helper with no network, filesystem, process, or credential access.
dist/esm/build/webpack/plugins/jsconfig-paths-plugin.js safe No malicious patterns detected; the code is a legitimate webpack resolver plugin for TypeScript/jsconfig path aliases.
dist/esm/build/webpack/plugins/memory-with-gc-cache-plugin.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/plugins/middleware-plugin.js safe This is a legitimate Next.js webpack plugin implementing Edge Runtime security controls; no malicious patterns such as exfiltration, credential harvesting, backdoors, or unauthorized code execution were detected.
dist/esm/build/webpack/plugins/mini-css-extract-plugin.js safe No malicious patterns detected; the file only extends a bundled webpack plugin with a simple flag, with no external calls, obfuscation, or install-time behavior.
dist/esm/build/webpack/plugins/minify-webpack-plugin/src/index.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/next-font-manifest-plugin.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/next-trace-entrypoints-plugin.js safe No malicious patterns detected; the file is a legitimate Next.js webpack trace entrypoints plugin performing file tracing and asset emission without exfiltration, credential harvesting, obfuscation, or suspicious process execution.
dist/esm/build/webpack/plugins/next-types-plugin/index.js safe No malicious patterns detected; this is a legitimate Next.js webpack plugin that generates TypeScript type definition files for App Router pages, layouts, and routes.
dist/esm/build/webpack/plugins/next-types-plugin/shared.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/nextjs-require-cache-hot-reloader.js safe No malicious patterns detected; this is a standard Webpack plugin for Next.js hot reloading that clears require cache entries.
dist/esm/build/webpack/plugins/optional-peer-dependency-resolve-plugin.js safe This webpack resolver plugin only implements standard optional-peer-dependency resolution logic with no malicious patterns detected.
dist/esm/build/webpack/plugins/pages-manifest-plugin.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/profiling-plugin.js safe No malicious patterns detected; the code is a legitimate webpack profiling plugin that instruments compiler hooks without exfiltration, credential harvesting, or dynamic code execution.
dist/esm/build/webpack/plugins/react-loadable-plugin.js safe This is a legitimate Next.js webpack plugin for React Loadable manifest generation with no malicious patterns detected.
dist/esm/build/webpack/plugins/rspack-flight-client-entry-plugin.js safe No malicious patterns detected; the code is a standard build-time plugin for Rspack that manages client entries and does not perform any suspicious network, filesystem, or process operations.
dist/esm/build/webpack/plugins/rspack-profiling-plugin.js safe No malicious patterns detected; the code is a legitimate Rspack profiling plugin that tracks compilation spans using WeakMaps without network, filesystem, or process manipulation.
dist/esm/build/webpack/plugins/slow-module-detection-plugin.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/plugins/subresource-integrity-plugin.js safe No malicious patterns detected; the code is a legitimate webpack plugin for generating Subresource Integrity (SRI) hashes, with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/esm/build/webpack/plugins/telemetry-plugin/telemetry-plugin.js safe No malicious patterns detected; the code is a standard Webpack telemetry plugin for tracking Next.js feature usage.
dist/esm/build/webpack/plugins/telemetry-plugin/update-telemetry-loader-context-from-swc.js safe No malicious patterns detected; the code only parses telemetry data and updates in-memory tracking objects without network, filesystem, or execution activity.
dist/esm/build/webpack/plugins/telemetry-plugin/use-cache-tracker-utils.js safe No malicious patterns detected; the file contains only simple utility functions for creating and merging use-cache tracker maps.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/getModuleTrace.js safe The code is a legitimate Next.js build-time utility that formats webpack module trace information and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious network activity.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/index.js safe No malicious patterns detected; the code is a standard webpack plugin that filters warnings and processes build errors.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parse-dynamic-code-evaluation-error.js safe No malicious patterns detected; the file is a standard webpack error parsing utility with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseBabel.js safe No malicious patterns detected
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseCss.js safe The code is a benign webpack error parser for CSS syntax errors and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious process/network activity.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNextAppLoaderError.js safe No malicious patterns detected; the code only inspects webpack module loaders and formats error messages without network, filesystem, or process manipulation.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNextFontError.js safe This file is a legitimate Next.js webpack error parser for @next/font errors with no malicious patterns detected.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNextInvalidImportError.js safe No malicious patterns detected; the code only processes Next.js webpack build errors locally without network, filesystem, or dynamic execution concerns.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseNotFoundError.js safe No malicious patterns detected; the file is a standard Next.js webpack error-formatting plugin that only reads source maps and module metadata for developer error messages, with no network, file system, process, or dynamic code execution behavior.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/parseScss.js safe No malicious patterns detected; the file only parses Sass error messages and formats them for Webpack error reporting.
dist/esm/build/webpack/plugins/wellknown-errors-plugin/simpleWebpackError.js safe Cleared by Jev triage; no further analysis needed
dist/esm/build/webpack/plugins/wellknown-errors-plugin/webpackModuleError.js safe No malicious patterns detected; the code is a legitimate webpack error-parsing plugin that only reads files within the build context to enrich error messages.
dist/esm/build/webpack/stringify-request.js safe No malicious patterns detected
dist/esm/build/webpack/utils.js safe No malicious patterns detected; the code is a standard webpack utility module for module traversal and entry processing without data exfiltration, obfuscation, or suspicious behavior.
dist/esm/build/write-build-id.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/add-base-path.js safe No malicious patterns detected; the file only performs base path manipulation using environment variables for Next.js routing.
dist/esm/client/add-locale.js safe No malicious patterns detected; the code is a benign Next.js locale utility using a conditional dynamic require gated by an environment variable.
dist/esm/client/app-bootstrap.js safe No malicious patterns detected in this Next.js app bootstrap module, which only loads polyfills and beforeInteractive scripts and triggers hydration.
dist/esm/client/app-call-server.js safe No malicious patterns detected
dist/esm/client/app-dir/form.js safe No malicious patterns detected; the code is a standard Next.js client-side Form component handling navigation and prefetching without any exfiltration, obfuscation, or dangerous operations.
dist/esm/client/app-dir/link.react-server.js safe This is a standard Next.js React Server Component wrapper for the Link component with no malicious patterns, network calls, dynamic execution, or file system access.
dist/esm/client/app-find-source-map-url.js safe No malicious patterns detected; the code only constructs a local URL for Next.js dev-server source map lookups, guarded by a dev-server environment check with no data exfiltration, credential access, or dynamic execution.
dist/esm/client/app-index.js safe This is a standard Next.js client-side entry point module with no malicious patterns; dynamic requires and global stream handling are legitimate framework internals.
dist/esm/client/app-link-gc.js safe This is a legitimate Next.js development-only link garbage collection utility that manages duplicate stylesheet links; no malicious patterns detected.
dist/esm/client/app-next-dev.js safe No malicious patterns detected; the code is a standard Next.js development entry point that bootstraps the app and renders a dev overlay.
dist/esm/client/app-next-turbopack.js safe This is standard Next.js Turbopack client bootstrap code with no malicious patterns detected.
dist/esm/client/app-next.js safe No malicious patterns detected; the file is a standard Next.js client bootstrap module with legitimate imports and dynamic requires.
dist/esm/client/app-webpack.js safe No malicious patterns detected
dist/esm/client/asset-prefix.js safe No malicious patterns detected
dist/esm/client/assign-location.js safe No malicious patterns detected; the code is a simple URL resolution utility with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/client/compat/router.js safe No malicious patterns detected
dist/esm/client/components/app-router-announcer.js safe No malicious patterns detected; the code is a standard Next.js route announcer for accessibility that manipulates DOM and uses React hooks without any exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/esm/client/components/app-router-headers.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/app-router-instance.js safe This is legitimate Next.js app router client-side code with standard navigation, prefetching, and action queue handling; it includes security checks against javascript: URLs and contains no malicious patterns.
dist/esm/client/components/app-router-utils.js safe No malicious patterns detected
dist/esm/client/components/bfcache-state-manager.js safe No malicious patterns detected
dist/esm/client/components/builtin/app-error.js safe No malicious patterns detected; the file is a static Next.js 500 error page, with only a benign but noteworthy use of dangerouslySetInnerHTML for a bundled stylesheet constant.
dist/esm/client/components/builtin/default-null.js safe No malicious patterns detected
dist/esm/client/components/builtin/default.js safe No malicious patterns detected
dist/esm/client/components/builtin/empty-stub.js safe No malicious patterns detected
dist/esm/client/components/builtin/error-styles.js safe No malicious patterns detected
dist/esm/client/components/builtin/forbidden.js safe No malicious patterns detected
dist/esm/client/components/builtin/global-error.js safe No malicious patterns detected; the file is a legitimate Next.js global error boundary component with no data exfiltration, code execution, or suspicious network/file system activity.
dist/esm/client/components/builtin/global-not-found.js safe No malicious patterns detected
dist/esm/client/components/builtin/layout.js safe This is a simple React layout component with no malicious patterns, network requests, file system access, or dynamic code execution.
dist/esm/client/components/builtin/not-found.js safe No malicious patterns detected
dist/esm/client/components/builtin/unauthorized.js safe No malicious patterns detected
dist/esm/client/components/catch-error.js safe This is a legitimate Next.js client-side error boundary component with no malicious patterns detected.
dist/esm/client/components/client-boundary-params.browser.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/client-boundary-params.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/client-page.js safe This is legitimate Next.js internal client component code with no malicious patterns detected
dist/esm/client/components/client-segment.js safe No malicious patterns detected; the code is a standard Next.js client segment wrapper that passes params to a component.
dist/esm/client/components/dev-root-http-access-fallback-boundary.js safe No malicious patterns detected; the file contains legitimate Next.js client-side error boundary logic with no external calls, credential access, or dynamic code execution.
dist/esm/client/components/error-boundary.js safe The code is a standard Next.js React error boundary for client components with no malicious patterns detected.
dist/esm/client/components/errors/root-error-boundary.js safe No malicious patterns detected; the code is a standard React error boundary with bot detection and no external data handling, dynamic execution, or filesystem/network operations.
dist/esm/client/components/forbidden.js safe No malicious patterns detected; the code is a legitimate Next.js experimental forbidden() helper that only checks an environment variable and throws a structured error.
dist/esm/client/components/handle-isr-error.js safe No malicious patterns detected
dist/esm/client/components/hooks-server-context.js safe No malicious patterns detected
dist/esm/client/components/http-access-fallback/error-boundary.js safe No malicious patterns detected; the file is a legitimate Next.js HTTP access fallback error boundary with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/client/components/http-access-fallback/error-fallback.js safe No malicious patterns detected; the file is a standard React error fallback component with static inline CSS and no network, filesystem, or process operations.
dist/esm/client/components/http-access-fallback/http-access-fallback.js safe No malicious patterns detected; the file only contains pure helper functions for identifying HTTP access fallback errors.
dist/esm/client/components/instant-samples.browser.js safe No malicious patterns detected
dist/esm/client/components/instant-samples.js safe This appears to be legitimate Next.js internal instrumentation code for validating route params and search params in client validation contexts, with no malicious patterns detected.
dist/esm/client/components/instant-validation/boundary.js safe This file only re-exports React context and component symbols for a client-side validation boundary, with no network, filesystem, process, or dynamic execution activity.
dist/esm/client/components/instant-validation/impl.browser.js safe No malicious patterns detected
dist/esm/client/components/instant-validation/impl.js safe No malicious patterns detected; the file only re-exports internal modules and includes a source map reference.
dist/esm/client/components/is-next-router-error.js safe No malicious patterns detected
dist/esm/client/components/layout-router.js safe This is legitimate Next.js App Router internal code handling scroll/focus management, layout rendering, and error boundaries with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor installation.
dist/esm/client/components/match-segments.js safe No malicious patterns detected; the file contains a pure segment-matching utility function with no I/O, network, process, or dynamic execution behavior.
dist/esm/client/components/nav-failure-handler.js safe No malicious patterns detected; the code is a standard Next.js navigation error handler that performs a client-side redirect on uncaught errors, with no data exfiltration, credential access, or suspicious behavior.
dist/esm/client/components/navigation-devtools.js safe No malicious patterns detected; this is legitimate React DevTools instrumentation code with no network, filesystem, process, or dynamic execution activity.
dist/esm/client/components/navigation-dynamic-rendering.browser.js safe No malicious patterns detected
dist/esm/client/components/navigation-dynamic-rendering.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/navigation-untracked.js safe No malicious patterns detected; the file only reads React context and an async storage store for route parameter checks.
dist/esm/client/components/navigation.js safe No malicious patterns detected
dist/esm/client/components/navigation.react-server.js safe No malicious patterns detected; the file only contains safe re-exports and a server-side guard for a client-only error helper.
dist/esm/client/components/noop-head.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/not-found.js safe This is a benign Next.js internal utility for throwing a 404 not-found error; no malicious patterns detected.
dist/esm/client/components/offline.js safe No malicious patterns detected; the code implements legitimate offline detection, connectivity polling, and retry logic with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
dist/esm/client/components/promise-queue.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/readonly-url-search-params.js safe No malicious patterns detected; the code is a standard read-only wrapper around URLSearchParams that only throws errors on mutating methods.
dist/esm/client/components/redirect-boundary.js safe No malicious patterns detected; this is a standard Next.js client-side redirect error boundary implementing navigation on redirect errors.
dist/esm/client/components/redirect-error.js safe No malicious patterns detected; the code is a simple redirect error validation utility with no network, filesystem, process, or dynamic execution behavior.
dist/esm/client/components/redirect-status-code.js safe No malicious patterns detected; this file only defines an enum of HTTP redirect status codes with a source map reference.
dist/esm/client/components/redirect.js safe No malicious patterns detected; this is legitimate Next.js redirect utility code with no exfiltration, obfuscation, process spawning, or filesystem manipulation.
dist/esm/client/components/render-from-template-context.js safe No malicious patterns detected
dist/esm/client/components/router-reducer/compute-changed-path.js safe No malicious patterns detected; the code is a standard Next.js router utility for computing changed paths and extracting params from flight router state.
dist/esm/client/components/router-reducer/create-href-from-url.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/router-reducer/create-initial-router-state.js safe No malicious patterns detected; the code is a legitimate Next.js router state initializer with no network exfiltration, credential harvesting, dynamic execution, or process spawning.
dist/esm/client/components/router-reducer/create-router-cache-key.js safe No malicious patterns detected
dist/esm/client/components/router-reducer/fetch-server-response.js safe This is legitimate Next.js App Router client-side RSC fetch logic with no malicious patterns detected.
dist/esm/client/components/router-reducer/is-navigating-to-new-root-layout.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/router-reducer/ppr-navigations.js safe This is legitimate Next.js App Router client-side navigation code with no malicious patterns detected.
dist/esm/client/components/router-reducer/reducers/committed-state.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/router-reducer/reducers/find-head-in-cache.js safe No malicious patterns detected; the code is a pure recursive cache lookup function with no network, filesystem, process, or dynamic execution activity.
dist/esm/client/components/router-reducer/reducers/has-interception-route-in-current-tree.js safe No malicious patterns detected
dist/esm/client/components/router-reducer/reducers/hmr-refresh-reducer.js safe No malicious patterns detected; the file contains a straightforward HMR refresh reducer with no network, filesystem, process execution, or obfuscated behavior.
dist/esm/client/components/router-reducer/reducers/navigate-reducer.js safe No malicious patterns detected; the code is a standard Next.js client-side navigation reducer.
dist/esm/client/components/router-reducer/reducers/refresh-reducer.js safe This is a standard Next.js client-side router refresh reducer that manipulates internal navigation state and caches, with no malicious patterns detected.
dist/esm/client/components/router-reducer/reducers/restore-reducer.js safe No malicious patterns detected; the file is a legitimate Next.js router reducer with only internal imports and no network, filesystem, process, or dynamic code execution activity.
dist/esm/client/components/router-reducer/reducers/server-action-reducer.js safe This file is standard Next.js App Router internals implementing Server Actions; no malicious patterns, credential harvesting, obfuscation, or external data exfiltration were found.
dist/esm/client/components/router-reducer/reducers/server-patch-reducer.js safe No malicious patterns detected; this is a Next.js internal router reducer that handles server-patch retry navigation without any suspicious network, filesystem, process, or dynamic code execution behavior.
dist/esm/client/components/router-reducer/router-reducer-types.js safe No malicious patterns detected
dist/esm/client/components/router-reducer/router-reducer.js safe No malicious patterns detected; the code is a standard Next.js router reducer with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
dist/esm/client/components/router-reducer/set-cache-busting-search-param.js safe No malicious patterns detected; this is standard Next.js client-side cache-busting utility code using Web Crypto for hashing and URL manipulation.
dist/esm/client/components/router-transition.js safe No malicious patterns detected; the code is a legitimate Next.js router transition instrumentation module with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns.
dist/esm/client/components/segment-cache/bfcache.js safe The bfcache module implements in-memory caching for React Server Component payloads with no network, filesystem, process, or dynamic execution behavior detected.
dist/esm/client/components/segment-cache/cache-key.js safe No malicious patterns detected
dist/esm/client/components/segment-cache/cache-map.js safe This is a standard LRU-based cache map implementation with fallback lookup logic; no malicious patterns, network calls, dynamic code execution, or credential access were detected.
dist/esm/client/components/segment-cache/fetch.js safe No malicious patterns detected; the code is a benign internal fetch wrapper for Next.js router with a testing API bypass mechanism.
dist/esm/client/components/segment-cache/lru.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/segment-cache/navigation-testing-lock.disabled.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/segment-cache/navigation-testing-lock.js safe This is legitimate Next.js internal code for the Instant Navigation Testing API; it contains no malicious patterns, exfiltration, credential harvesting, or command execution.
dist/esm/client/components/segment-cache/navigation.js safe The code is part of Next.js client-side router navigation logic and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or unauthorized process execution.
dist/esm/client/components/segment-cache/optimistic-routes.js safe No malicious patterns detected
dist/esm/client/components/segment-cache/prefetch.js safe The prefetch module only orchestrates internal cache prefetching using validated URL inputs and imported utilities, with no suspicious network, filesystem, code execution, or credential-handling patterns.
dist/esm/client/components/segment-cache/scheduler.js safe This is a legitimate Next.js App Router prefetch scheduler module with no malicious patterns detected.
dist/esm/client/components/segment-cache/types.js safe No malicious patterns detected; the file only defines static TypeScript-style enums and constants for a segment cache with no executable logic, network activity, or file/process access.
dist/esm/client/components/segment-cache/vary-path.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/server-async-storage.browser.js safe No malicious patterns detected
dist/esm/client/components/server-async-storage.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/static-generation-bailout.js safe No malicious patterns detected
dist/esm/client/components/styles/access-error-styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/unauthorized.js safe No malicious patterns detected
dist/esm/client/components/unrecognized-action-error.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/components/unresolved-thenable.js safe No malicious patterns detected; the file only defines an inert thenable used to suspend indefinitely.
dist/esm/client/components/unstable-rethrow.browser.js safe No malicious patterns detected; the file is a standard error rethrow utility with no network, filesystem, process, or obfuscated code.
dist/esm/client/components/unstable-rethrow.js safe No malicious patterns detected; this is legitimate Next.js error-handling utility code with only static imports and error type checks.
dist/esm/client/components/use-action-queue.js safe No malicious patterns detected; the file is legitimate Next.js App Router client internals with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/esm/client/components/use-offline.js safe The file implements a standard React offline-state context with no malicious patterns, network calls, credential access, or dynamic code execution.
dist/esm/client/dev/debug-channel.js safe The file implements local Next.js debug-channel buffering in IndexedDB and request ID handling with no external network calls, credential harvesting, dynamic code execution, or process spawning; no malicious patterns detected.
dist/esm/client/dev/error-overlay/websocket.js safe This file is a simple re-export of a message listener function with no malicious patterns, network activity, or code execution.
dist/esm/client/dev/fouc.js safe No malicious patterns detected; the code is a standard Next.js development utility for removing no-FOUC style workarounds before hydration.
dist/esm/client/dev/hot-middleware-client.js safe No malicious patterns detected; the file is a Next.js development hot-reload client with no exfiltration, obfuscation, or process execution behavior.
dist/esm/client/dev/hot-reloader/app/hot-reloader-app.js safe This is a legitimate Next.js dev hot-reloader client module with no malicious patterns detected; all network activity is via the existing HMR WebSocket, code execution is limited to standard webpack HMR APIs, and no credential harvesting, exfiltration, or obfuscated payloads are present.
dist/esm/client/dev/hot-reloader/get-socket-url.js safe No malicious patterns detected; the code only computes a WebSocket URL for a development hot-reloader using standard browser APIs.
dist/esm/client/dev/hot-reloader/pages/hot-reloader-pages.js safe No malicious patterns detected; the file is legitimate Next.js HMR client code for development builds only.
dist/esm/client/dev/hot-reloader/pages/websocket.js safe No malicious patterns detected; this is a standard Next.js HMR WebSocket client with reconnection logic.
dist/esm/client/dev/hot-reloader/shared.js safe Cleared by Jev triage; no further analysis needed
dist/esm/client/dev/hot-reloader/turbopack-hot-reloader-common.js safe No malicious patterns detected; the code is a legitimate Turbopack HMR client utility that manages HMR update reporting without any network, filesystem, or process-related risks.
dist/esm/client/dev/noop-turbopack-hmr.js safe No malicious patterns detected
dist/esm/client/dev/on-demand-entries-client.js safe No malicious patterns detected; the code is a standard Next.js dev-time on-demand entries client that sends periodic ping messages over the existing dev websocket.
dist/esm/client/dev/report-hmr-latency.js safe No malicious patterns detected
dist/esm/client/dev/runtime-error-handler.js safe No malicious patterns detected
dist/esm/client/flight-data-helpers.js safe This is a Next.js internal Flight data helper module containing only data parsing, URL parameter extraction, and state normalization logic with no network, filesystem, process, or dynamic execution behavior.
dist/esm/client/form-shared.js safe This is a legitimate Next.js form handling utility with proper URL validation and no malicious patterns detected.
dist/esm/client/form.js safe No malicious patterns detected; the code is a standard React form component for Next.js with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/client/get-domain-locale.js safe No malicious patterns detected; the code is a standard Next.js i18n utility for domain/locale resolution with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/client/has-base-path.js safe No malicious patterns detected; the file only exports a simple utility that checks a path prefix against a build-time base path environment variable.
dist/esm/client/image-component.js safe No malicious patterns detected; this is legitimate Next.js Image component code with standard React patterns and no data exfiltration, credential harvesting, or dynamic code execution.
dist/esm/client/index.js safe This is a legitimate Next.js client-side hydration entry point with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution.
dist/esm/client/legacy/image.js safe No malicious patterns detected; this is legitimate Next.js legacy image component code with standard image loading, URL generation, and performance optimization logic.
dist/esm/client/lib/console.js safe The code is a standard console argument formatting utility with no malicious patterns detected.
dist/esm/client/lib/javascript-url.js safe No malicious patterns detected; the code is a standard JavaScript URL protocol sanitization check adapted from React.
dist/esm/client/lib/promise.js safe No malicious patterns detected; the code is a legitimate promise timeout helper using requestIdleCallback.
dist/esm/client/link.js safe No malicious patterns detected; this is a standard Next.js Link component with expected client-side routing and prefetching logic.
dist/esm/client/navigation-build-id.js safe No malicious patterns detected
dist/esm/client/next-dev-turbopack.js safe This is a legitimate Next.js Turbopack development client module with no malicious patterns detected.
dist/esm/client/next-dev.js safe No malicious patterns detected; the file is a standard Next.js development client bootstrap module.
dist/esm/client/next.js safe No malicious patterns detected; the file contains standard Next.js client-side initialization code.
dist/esm/client/normalize-locale-path.js safe No malicious patterns detected; the code is a standard Next.js i18n locale path normalization utility with a conditional dynamic require gated by an environment flag.
dist/esm/client/normalize-trailing-slash.js safe No malicious patterns detected; the code only normalizes URL trailing slashes using standard string and regex operations.
dist/esm/client/page-bootstrap.js safe No malicious patterns detected
dist/esm/client/page-loader.js safe No malicious patterns detected; this is a legitimate Next.js page loader module with standard client-side routing and data fetching logic.
dist/esm/client/portal/index.js safe No malicious patterns detected
dist/esm/client/react-client-callbacks/on-recoverable-error.js safe No malicious patterns detected; the code is standard Next.js client error handling with a development-only static require and environment-gated test suppression.
dist/esm/client/react-client-callbacks/report-global-error.js safe No malicious patterns detected
dist/esm/client/register-deployment-id-global.js safe No malicious patterns detected; the code only reads a deployment ID and assigns it to a global variable at import time.
dist/esm/client/remove-base-path.js safe No malicious patterns detected; the code is a simple, side-effect-free utility for removing a base path from URLs.
dist/esm/client/remove-locale.js safe No malicious patterns detected; the file contains a benign locale-removal utility from Next.js with no network, filesystem, process, or dynamic execution behavior.
dist/esm/client/request-idle-callback.js safe No malicious patterns detected
dist/esm/client/request/io.browser.js safe No malicious patterns detected; the file only defines a pre-resolved Promise for React's use() hook.
dist/esm/client/request/params.browser.dev.js safe No malicious patterns detected
dist/esm/client/request/params.browser.prod.js safe No malicious patterns detected; the code only caches Promises in a WeakMap and exports a simple wrapper function.
dist/esm/client/request/search-params.browser.dev.js safe No malicious patterns detected; the code is a development-only Next.js proxy for searchParams that logs warnings on synchronous access.
dist/esm/client/request/search-params.browser.prod.js safe No malicious patterns detected
dist/esm/client/resolve-href.js safe No malicious patterns detected; the code is a standard Next.js URL resolution utility with no exfiltration, credential access, dynamic execution, or process spawning.
dist/esm/client/route-announcer.js safe No malicious patterns detected; the file is a legitimate Next.js route announcer component that uses only React and local router context without network, filesystem, or process access.
dist/esm/client/route-loader.js safe This is a legitimate Next.js client-side route loader with no malicious patterns; it only performs expected script/style loading and prefetching using same-origin assets and standard browser APIs.
dist/esm/client/route-params.js safe No malicious patterns detected
dist/esm/client/router-transition-types.js safe No malicious patterns detected
dist/esm/client/router.js safe No malicious patterns detected; this is legitimate Next.js Pages Router client code with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/esm/client/set-attributes-from-props.js safe The code is a benign utility for setting DOM attributes from React props, with no network, filesystem, process, or dynamic execution patterns.
dist/esm/client/tracing/report-to-socket.js safe No malicious patterns detected; the code only sends local dev spans to an internal websocket for telemetry.
dist/esm/client/tracing/tracer.js safe No malicious patterns detected
dist/esm/client/use-client-disallowed.js safe This file is a legitimate Next.js internal module that intentionally throws an error when Client Components are used in disallowed environments, with no malicious patterns detected.
dist/esm/client/use-intersection.js safe No malicious patterns detected
dist/esm/client/use-merged-ref.js safe No malicious patterns detected; the code is a legitimate React ref-merging utility with no network, filesystem, process, or dynamic execution activity.
dist/esm/client/web-vitals.js safe No malicious patterns detected; the file only wires up Next.js' bundled web-vitals reporting to a user-supplied callback inside a React effect.
dist/esm/client/with-router.js safe No malicious patterns detected; this is a standard React higher-order component for injecting a router.
dist/esm/export/helpers/get-params.js safe No malicious patterns detected; the code is a standard Next.js utility for matching route parameters.
dist/esm/export/helpers/is-dynamic-usage-error.js safe No malicious patterns detected
dist/esm/export/index.js safe No malicious patterns detected; this is standard Next.js static export orchestration code that reads/writes within the project's distDir/outDir and does not exfiltrate data, harvest credentials, execute dynamic code, or spawn suspicious processes.
dist/esm/export/routes/app-page.js safe No malicious patterns detected; the code is part of Next.js static export logic with no external data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/export/routes/app-route.js safe No malicious patterns detected; this is legitimate Next.js app-route export logic with no data exfiltration, credential harvesting, obfuscation, or shell execution.
dist/esm/export/routes/pages.js safe This is legitimate Next.js static export code with no malicious patterns detected.
dist/esm/export/routes/types.js safe No malicious patterns detected
dist/esm/export/types.js safe No malicious patterns detected
dist/esm/export/utils.js safe Cleared by Jev triage; no further analysis needed
dist/esm/export/worker.js safe This is legitimate Next.js export worker code with no malicious patterns; it only performs normal build-time page rendering, caching, and filesystem writes within the build output directory.
dist/esm/lib/batcher.js safe No malicious patterns detected; the code is a legitimate batching utility with no suspicious network, filesystem, process, or dynamic execution behavior.
dist/esm/lib/build-custom-route.js safe No malicious patterns detected
dist/esm/lib/bundler.js safe The code only manages bundler selection via environment variables and flags, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/lib/client-and-server-references.js safe No malicious patterns detected; the code contains only React server/client reference type checks with no network, filesystem, process, or dynamic execution behavior.
dist/esm/lib/coalesced-function.js safe No malicious patterns detected; the code is a benign request-coalescing utility with no external I/O, credential access, code execution, or install-time behavior.
dist/esm/lib/compile-error.js safe No malicious patterns detected
dist/esm/lib/constants.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/create-client-router-filter.js safe No malicious patterns detected; the code only builds Bloom filters for static and dynamic routes without any exfiltration, credential access, obfuscation, or process execution.
dist/esm/lib/detached-promise.js safe No malicious patterns detected
dist/esm/lib/detect-typo.js safe The code implements a Levenshtein distance algorithm for typo detection without any malicious patterns, network activity, or system access.
dist/esm/lib/error-telemetry-utils.js safe This utility module only formats and extracts error codes from error digests without any network, filesystem, process, or dynamic code execution behavior.
dist/esm/lib/fallback.js safe No malicious patterns detected; the file contains only pure fallback-mode parsing logic with no network, filesystem, process, or dynamic execution behavior.
dist/esm/lib/file-exists.js safe No malicious patterns detected; the code only checks file existence and type using standard fs APIs.
dist/esm/lib/find-pages-dir.js safe No malicious patterns detected; the code only performs standard filesystem directory lookups for Next.js project structure.
dist/esm/lib/find-root.js safe No malicious patterns detected; code performs expected filesystem inspection for workspace root detection.
dist/esm/lib/format-cli-help-output.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/format-dynamic-import-path.js safe The code performs legitimate path resolution and URL formatting with no malicious patterns, network activity, environment harvesting, or dynamic code execution.
dist/esm/lib/format-server-error.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/framework/boundary-components.js safe No malicious patterns detected; the code only defines React boundary components that render children with no external effects, network calls, or obfuscation.
dist/esm/lib/framework/boundary-constants.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/fs/rename.js safe No malicious patterns detected; the code is a legitimate, MIT-licensed file rename utility based on Microsoft VS Code's pfs.ts, with no data exfiltration, credential harvesting, obfuscation, process spawning, or other security concerns.
dist/esm/lib/fs/write-atomic.js safe The code implements a standard atomic file write pattern using temporary files and rename, with no suspicious network, process, credential, or obfuscation behavior.
dist/esm/lib/generate-interception-routes-rewrites.js safe No malicious patterns detected; the code performs deterministic route rewrite generation for Next.js interception routes without network, filesystem, process, or dynamic execution behavior.
dist/esm/lib/get-files-in-dir.js safe No malicious patterns detected
dist/esm/lib/get-network-host.js safe No malicious patterns detected
dist/esm/lib/get-package-version.js safe No malicious patterns detected; the code simply reads package.json to resolve dependency versions using Node.js built-ins and bundled libraries.
dist/esm/lib/get-project-dir.js safe No malicious patterns detected; the code only resolves project directory paths and prints typo warnings, which is normal CLI behavior.
dist/esm/lib/git-worktree.js safe No malicious patterns detected; the code only reads local Git worktree metadata and does not perform network, process, or credential-related operations.
dist/esm/lib/has-necessary-dependencies.js safe No malicious patterns detected; the code appears to be a legitimate dependency resolution utility using only local filesystem APIs.
dist/esm/lib/helpers/get-cache-directory.js safe No malicious patterns detected
dist/esm/lib/helpers/get-reserved-port.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/import-next-warning.js safe No malicious patterns detected; the code only logs a warning on import.
dist/esm/lib/inline-static-env.js safe No malicious patterns detected; the code performs legitimate static environment variable inlining and chunk hash updating.
dist/esm/lib/install-dependencies.js safe No malicious patterns detected
dist/esm/lib/interop-default.js safe The file contains only a standard ESM interop helper that returns the default export when present, with no malicious patterns detected.
dist/esm/lib/is-api-route.js safe The file contains a simple utility function to check API routes with no malicious patterns.
dist/esm/lib/is-app-page-route.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/is-app-route-route.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/is-edge-runtime.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/is-error.js safe No malicious patterns detected; the code only provides error-handling utilities with circular-reference-safe stringification and no network, filesystem, process, or dynamic-execution behavior.
dist/esm/lib/is-interception-route-rewrite.js safe No malicious patterns detected
dist/esm/lib/is-internal-component.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/is-serializable-props.js safe No malicious patterns detected
dist/esm/lib/load-custom-routes.js safe No malicious patterns detected
dist/esm/lib/memory/gc-observer.js safe No malicious patterns detected; the code is a benign garbage collection performance observer that only logs warnings locally.
dist/esm/lib/memory/shutdown.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/memory/trace.js safe The code is a legitimate memory tracing utility that records memory metrics and optionally writes a heap snapshot for debugging; no malicious patterns were detected.
dist/esm/lib/metadata/constants.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/metadata/default-metadata.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/metadata/generate/icon-mark.js safe No malicious patterns detected
dist/esm/lib/metadata/generate/utils.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/metadata/get-metadata-route.js safe No malicious patterns detected; the code contains pure path/route normalization logic for Next.js metadata routes with no network, filesystem, process, or dynamic execution behavior.
dist/esm/lib/metadata/is-metadata-route.js safe No malicious patterns detected; the module only performs regex-based file path matching for Next.js metadata routes with no network, filesystem, process, or dynamic execution behavior.
dist/esm/lib/metadata/metadata-context.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/metadata/metadata.js safe This is Next.js metadata rendering code with no malicious patterns, network calls, credential access, dynamic execution, or shell commands detected.
dist/esm/lib/metadata/resolve-metadata.js safe This is legitimate Next.js framework code for resolving page metadata; no malicious patterns, exfiltration, obfuscation, or suspicious behavior were detected.
dist/esm/lib/metadata/resolvers/resolve-basics.js safe No malicious patterns detected
dist/esm/lib/metadata/resolvers/resolve-icons.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/metadata/resolvers/resolve-opengraph.js safe No malicious patterns detected; the code is a legitimate Next.js metadata resolver that only processes Open Graph and Twitter metadata.
dist/esm/lib/metadata/resolvers/resolve-title.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/metadata/resolvers/resolve-url.js safe No malicious patterns detected; the code is a legitimate Next.js metadata URL resolver with no data exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/esm/lib/metadata/types/alternative-urls-types.js safe This file only contains an empty export statement and a source map comment, with no executable code or malicious patterns.
dist/esm/lib/metadata/types/extra-types.js safe The file contains only type declaration comments and an empty export statement with no executable or malicious code.
dist/esm/lib/metadata/types/icons.js safe This file contains only an empty export statement and a source map reference, with no executable code or malicious patterns.
dist/esm/lib/metadata/types/manifest-types.js safe No malicious patterns detected
dist/esm/lib/metadata/types/metadata-interface.js safe This file contains only TypeScript type declarations and documentation comments for the Next.js Metadata API with no executable code or malicious patterns.
dist/esm/lib/metadata/types/metadata-types.js safe No malicious patterns detected
dist/esm/lib/metadata/types/opengraph-types.js safe No malicious patterns detected
dist/esm/lib/metadata/types/resolvers.js safe No malicious patterns detected
dist/esm/lib/metadata/types/twitter-types.js safe No malicious patterns detected
dist/esm/lib/mime-type.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/multi-file-writer.js safe No malicious patterns detected; the code is a straightforward utility for parallel file writing with directory creation.
dist/esm/lib/needs-experimental-react.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/non-nullable.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/normalize-path.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/oxford-comma-list.js safe No malicious patterns detected
dist/esm/lib/page-types.js safe The file defines a simple enum-like object for page types with no malicious patterns, network activity, or dynamic code execution.
dist/esm/lib/pick.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/picocolors.js safe No malicious patterns detected
dist/esm/lib/pretty-bytes.js safe No malicious patterns detected in the pretty-bytes library; it is a benign byte formatting utility.
dist/esm/lib/profiles-dir.js safe No malicious patterns detected
dist/esm/lib/realpath.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/recursive-delete.js safe No malicious patterns detected
dist/esm/lib/recursive-readdir.js safe No malicious patterns detected; the code is a legitimate recursive directory reader with no data exfiltration, credential harvesting, obfuscation, or system command execution.
dist/esm/lib/redirect-status.js safe The code is a utility module for handling redirect status codes and modifying route regexes, with no malicious patterns or security concerns detected.
dist/esm/lib/require-instrumentation-client.js safe No malicious patterns detected; the module simply imports a Next.js client instrumentation hook and optionally logs timing in development.
dist/esm/lib/resolve-build-paths.js safe No malicious patterns detected; the code performs local file path resolution using glob and fs without network, process execution, or credential access.
dist/esm/lib/resolve-from.js safe This is a legitimate module resolution utility with no malicious patterns detected; the use of Module._resolveFilename is standard internal Node.js API usage for resolving module paths.
dist/esm/lib/route-pattern-normalizer.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/scheduler.js safe No malicious patterns detected; the file contains only benign scheduling utilities for Next.js runtime environments.
dist/esm/lib/semver-noop.js safe No malicious patterns detected; the file is a benign semver noop stub with only a hardcoded true return.
dist/esm/lib/setup-exception-listeners.js safe No malicious patterns detected
dist/esm/lib/static-env.js safe No malicious patterns detected; the code performs legitimate Next.js environment variable collection and validation without exfiltration, obfuscation, or unauthorized system access.
dist/esm/lib/try-to-parse-path.js safe The code is a utility for parsing route paths with error handling and normalization, with no malicious patterns detected.
dist/esm/lib/turbopack-cache-seed.js safe The code appears to be a legitimate Turbopack cache seeding mechanism that operates within the project's dist directory and does not exhibit any malicious patterns.
dist/esm/lib/typescript/diagnosticFormatter.js safe No malicious patterns detected
dist/esm/lib/typescript/getTypeScriptConfiguration.js safe No malicious patterns detected; the code performs legitimate TypeScript configuration parsing without data exfiltration, dynamic code execution, or suspicious behavior.
dist/esm/lib/typescript/getTypeScriptIntent.js safe Cleared by Jev triage; no further analysis needed
dist/esm/lib/typescript/loadTsConfig.js safe No malicious patterns detected; the code is a legitimate TypeScript config loader that only reads local files and resolves module paths within the project scope.
dist/esm/lib/typescript/missingDependencyError.js safe No malicious patterns detected; the code only formats and throws a user-friendly error message for missing TypeScript dependencies.
dist/esm/lib/typescript/runTypeCheck.js safe No malicious patterns detected; the code performs TypeScript type checking and diagnostic filtering without network, credential, or process execution behavior.
dist/esm/lib/typescript/runTypeCheckCli.js safe Code performs standard TypeScript type-checking via tsc with no malicious patterns detected.
dist/esm/lib/typescript/runTypeScriptCli.js safe The code is a legitimate TypeScript CLI runner with expected process spawning and filesystem reads, no malicious patterns such as exfiltration, obfuscation, credential theft, or network calls were found.
dist/esm/lib/typescript/type-paths.js safe No malicious patterns detected
dist/esm/lib/typescript/writeAppTypeDeclarations.js safe The file only generates and writes a TypeScript declaration file within the project directory using standard path and filesystem APIs, with no malicious patterns detected.
dist/esm/lib/typescript/writeConfigurationDefaults.js safe The code performs legitimate TypeScript configuration file reads/writes for Next.js project setup; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation were detected.
dist/esm/lib/url.js safe No malicious patterns detected; the code only performs standard URL parsing and query string manipulation with no data exfiltration, dynamic execution, or other security concerns.
dist/esm/lib/verify-root-layout.js safe No malicious patterns detected; the code is a standard Next.js utility for creating a root layout file.
dist/esm/lib/wait.js safe No malicious patterns detected; the file only provides a simple promise-based sleep utility.
dist/esm/lib/with-promise-cache.js safe No malicious patterns detected
dist/esm/lib/worker.js safe This is legitimate Next.js build worker management code with no malicious patterns detected; it uses standard child process spawning for build workers, propagates environment variables for worker configuration, and includes no data exfiltration, credential harvesting, obfuscation, or backdoor mechanisms.
dist/esm/next-devtools/server/dev-indicator-middleware.js safe No malicious patterns detected; the middleware only toggles a local dev-indicator state via an internal endpoint without external communication, credential access, or code execution.
dist/esm/next-devtools/server/font/get-dev-overlay-font-middleware.js safe This Next.js dev overlay font middleware is a static asset server for bundled font files with strict allowlist validation, path traversal protection, and no malicious patterns.
dist/esm/next-devtools/server/get-next-error-feedback-middleware.js safe No malicious patterns detected; the code is a standard Next.js middleware for collecting error feedback telemetry.
dist/esm/next-devtools/server/middleware-response.js safe No malicious patterns detected
dist/esm/next-devtools/server/shared.js safe No malicious patterns detected
dist/esm/next-devtools/shared/console-error.js safe No malicious patterns detected; the code only creates and tags Error objects for Next.js console error identification.
dist/esm/next-devtools/shared/deepmerge.js safe The deepMerge function is a standard recursive object-merge utility with no malicious patterns, network calls, dynamic code execution, or filesystem access.
dist/esm/next-devtools/shared/devtools-config-schema.js safe No malicious patterns detected; the file only defines a Zod validation schema for devtools configuration.
dist/esm/next-devtools/shared/forward-logs-shared.js safe No malicious patterns detected; the code only patches console methods and tags server-side errors for Next.js devtools log forwarding.
dist/esm/next-devtools/shared/hydration-error.js safe The file contains only an empty export statement and a source map reference, with no executable or suspicious code.
dist/esm/next-devtools/shared/react-18-hydration-error.js safe No malicious patterns detected
dist/esm/next-devtools/shared/react-19-hydration-error.js safe No malicious patterns detected
dist/esm/next-devtools/shared/request-insights.js safe The file only re-exports two utility functions from a shared module with no executable code, network calls, or other malicious patterns.
dist/esm/next-devtools/shared/stack-frame.js safe The code is a legitimate Next.js devtools utility for resolving stack frames, with only a same-origin fetch to the framework's own endpoint and no malicious patterns detected.
dist/esm/next-devtools/shared/types.js safe No malicious patterns detected
dist/esm/next-devtools/shared/version-staleness.js safe Cleared by Jev triage; no further analysis needed
dist/esm/next-devtools/shared/webpack-module-path.js safe No malicious patterns detected; the code only performs regex-based string normalization for webpack internal resource paths.
dist/esm/next-devtools/userspace/app/app-dev-overlay-error-boundary.js safe No malicious patterns detected; the code is a standard React error boundary for Next.js development overlay with expected dependencies and no exfiltration, credential harvesting, or code execution.
dist/esm/next-devtools/userspace/app/app-dev-overlay-setup.js safe No malicious patterns detected; the file only initializes error handling and debug log forwarding for a Next.js dev overlay.
dist/esm/next-devtools/userspace/app/client-entry.js safe This is a simple React component that renders an error boundary for Next.js dev overlay; no malicious patterns detected.
dist/esm/next-devtools/userspace/app/errors/index.js safe No malicious patterns detected; the file is a simple ES module re-export barrel with no executable logic or external data flow.
dist/esm/next-devtools/userspace/app/errors/intercept-console-error.js safe No malicious patterns detected; the code is a legitimate Next.js console.error patch for error handling.
dist/esm/next-devtools/userspace/app/errors/replay-ssr-only-errors.js safe No malicious patterns detected; the code is a legitimate Next.js devtools error replay module that reads SSR error data from the DOM and passes it to an internal error handler.
dist/esm/next-devtools/userspace/app/errors/stitched-error.js safe No malicious patterns detected
dist/esm/next-devtools/userspace/app/errors/use-error-handler.js safe No malicious patterns detected; the file contains standard Next.js devtools error handling with no exfiltration, obfuscation, or process execution.
dist/esm/next-devtools/userspace/app/forward-logs-utils.js safe No malicious patterns detected; the code is a straightforward log serialization utility using safe-stable-stringify with depth/breadth limits and no network, filesystem, process, or dynamic execution behaviors.
dist/esm/next-devtools/userspace/app/segment-explorer-node.js safe No malicious patterns detected; the file is legitimate Next.js internal devtools code with no exfiltration, credential harvesting, obfuscation, or suspicious execution.
dist/esm/next-devtools/userspace/app/terminal-logging-config.js safe No malicious patterns detected; the code only reads and parses a framework-specific debug environment variable with a safe fallback.
dist/esm/next-devtools/userspace/pages/hydration-error-state.js safe No malicious patterns detected
dist/esm/next-devtools/userspace/pages/pages-dev-overlay-error-boundary.js safe This is a standard React error boundary component for Next.js dev tools with no malicious patterns, network calls, dynamic execution, or filesystem/process access.
dist/esm/next-devtools/userspace/use-app-dev-rendering-indicator.js safe No malicious patterns detected; the file only uses React hooks and a Next.js devtools dispatcher for rendering indicators.
dist/esm/pages/_app.js safe No malicious patterns detected
dist/esm/pages/_document.js safe This is Vercel Next.js's legitimate _document.js runtime file with no malicious patterns; uses of dangerouslySetInnerHTML are for standard Next.js SSR script injection with proper JSON escaping and nonce support.
dist/esm/pages/_error.js safe This is a standard Next.js built-in error page component with no malicious patterns; the only flagged constructs (server-side dynamic require and static CSS injection) are legitimate framework usage.
dist/esm/server/ReactDOMServerPages.js safe No malicious patterns detected; the code is a standard React DOM server module loader with legitimate error handling.
dist/esm/server/accept-header.js safe No malicious patterns detected
dist/esm/server/after/after-context.js safe No malicious patterns detected in this Next.js after-context module; it implements request lifecycle task queuing and error reporting without any data exfiltration, credential harvesting, obfuscation, or unauthorized process/file operations.
dist/esm/server/after/after.js safe No malicious patterns detected; the file is a legitimate Next.js after() utility that schedules callbacks using internal async storage, with no exfiltration, credential access, obfuscation, or process execution.
dist/esm/server/after/awaiter.js safe No malicious patterns detected; the code is a standard promise-gathering utility with no network, filesystem, process, or dynamic execution behavior.
dist/esm/server/after/builtin-request-context.js safe No malicious patterns detected
dist/esm/server/after/index.js safe No malicious patterns detected
dist/esm/server/after/run-with-after.js safe No malicious patterns detected; the file contains a straightforward AfterRunner class for managing lifecycle callbacks with no network, filesystem, or process activity.
dist/esm/server/api-utils/index.js safe No malicious patterns detected; the code is standard Next.js API route utility code with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
dist/esm/server/api-utils/node/parse-body.js safe No malicious patterns detected; the file is a standard Next.js API body parser with no exfiltration, credential harvesting, obfuscation, or suspicious process/network activity.
dist/esm/server/api-utils/web.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/action-async-storage-instance.js safe No malicious patterns detected
dist/esm/server/app-render/action-async-storage.external.js safe No malicious patterns detected; the file only re-exports an async storage instance from another internal module.
dist/esm/server/app-render/after-task-async-storage-instance.js safe No malicious patterns detected
dist/esm/server/app-render/after-task-async-storage.external.js safe This file only re-exports an AsyncLocalStorage instance from a sibling module with no executable logic, I/O, or malicious patterns.
dist/esm/server/app-render/app-render-prerender-utils.js safe No malicious patterns detected; the file is legitimate Next.js server-side rendering utility code for handling React Server Component streams with no network, filesystem, process, or credential access.
dist/esm/server/app-render/async-local-storage.js safe No malicious patterns detected; the code is a legitimate Next.js polyfill for AsyncLocalStorage with no external communication, credential access, dynamic execution, or install-time behavior.
dist/esm/server/app-render/blocking-route-messages.js safe This file contains only static error message factory functions for Next.js prerendering diagnostics with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/server/app-render/cache-signal.js safe No malicious patterns detected; this is a legitimate concurrency utility for tracking pending cache reads in Next.js.
dist/esm/server/app-render/collect-segment-data.js safe No malicious patterns detected; the code is legitimate Next.js internal segment data collection logic with no exfiltration, credential access, obfuscation, or suspicious execution patterns.
dist/esm/server/app-render/console-async-storage-instance.js safe The file simply creates and exports an AsyncLocalStorage instance with no malicious patterns or suspicious behavior.
dist/esm/server/app-render/console-async-storage.external.js safe No malicious patterns detected
dist/esm/server/app-render/create-component-styles-and-scripts.js safe No malicious patterns detected
dist/esm/server/app-render/create-component-tree.js safe No malicious patterns detected; the file is legitimate Next.js internal server rendering logic with no data exfiltration, credential harvesting, obfuscation, network abuse, or shell execution.
dist/esm/server/app-render/create-error-handler.js safe No malicious patterns detected; the code is a legitimate Next.js error-handling module with standard imports, error digesting, and telemetry, and contains no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/server/app-render/create-flight-router-state-from-loader-tree.js safe No malicious patterns detected; the code is a legitimate Next.js internal module that recursively builds flight router state from a loader tree without network, filesystem, process, or dynamic code execution concerns.
dist/esm/server/app-render/csrf-protection.js safe No malicious patterns detected; the code implements CSRF origin validation with wildcard domain matching and contains no network, filesystem, process, or dynamic code execution behavior.
dist/esm/server/app-render/debug-channel-server.node.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/debug-channel-server.web.js safe No malicious patterns detected
dist/esm/server/app-render/dev-validation-error-delivery.js safe No malicious patterns detected; the code is a legitimate Next.js internal module for serializing validation errors for the dev overlay using an in-process render stream and source-map filtering.
dist/esm/server/app-render/dev-validation-events.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/dev-validation-scheduler.js safe No malicious patterns detected; the code is a development-time validation scheduler with no network, filesystem, process, or credential access.
dist/esm/server/app-render/dev-validation-worker-globals.js safe No malicious patterns detected
dist/esm/server/app-render/dev-validation-worker-snapshot.js safe No malicious patterns detected; the code only builds a serializable snapshot for a dev validation worker using standard async data collection and object serialization.
dist/esm/server/app-render/dynamic-access-async-storage-instance.js safe No malicious patterns detected
dist/esm/server/app-render/dynamic-access-async-storage.external.js safe No malicious patterns detected; the file only re-exports an AsyncLocalStorage instance with a Turbopack transition annotation.
dist/esm/server/app-render/dynamic-rendering.js safe The file is a legitimate portion of Next.js's server-side dynamic rendering module with no evidence of data exfiltration, credential harvesting, obfuscated payloads, shell execution, or malicious lifecycle behavior.
dist/esm/server/app-render/encryption-utils.js safe No malicious patterns detected; the file is a legitimate Next.js encryption utility for Server Actions.
dist/esm/server/app-render/encryption.js safe This is legitimate Next.js Server Actions encryption code with no malicious patterns; encryption/decryption uses standard Web Crypto APIs, no external network calls, no credential harvesting, no obfuscation, and no shell/process execution.
dist/esm/server/app-render/flight-render-result.js safe No malicious patterns detected; the file is a simple class extending RenderResult to set the RSC content-type header.
dist/esm/server/app-render/get-asset-query-string.js safe No malicious patterns detected
dist/esm/server/app-render/get-css-inlined-link-tags.js safe No malicious patterns detected
dist/esm/server/app-render/get-layer-assets.js safe No malicious patterns detected; the code appears to be legitimate Next.js server-rendering logic for managing CSS, JavaScript, and font assets.
dist/esm/server/app-render/get-preloadable-fonts.js safe No malicious patterns detected; the code is a pure font preloading utility with no I/O, network, or dynamic execution.
dist/esm/server/app-render/get-script-nonce-from-header.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/get-short-dynamic-param-type.js safe No malicious patterns detected
dist/esm/server/app-render/has-loading-component-in-tree.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/instant-validation/boundary-constants.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/instant-validation/boundary-impl.js safe No malicious patterns detected; this is a legitimate Next.js internal instant validation boundary module with no data exfiltration, credential harvesting, dynamic code execution, or network/file system abuse.
dist/esm/server/app-render/instant-validation/boundary-tracking.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/instant-validation/instant-config.js safe No malicious patterns detected; the code is a legitimate Next.js internal module that traverses a route loader tree to evaluate 'instant' validation configuration.
dist/esm/server/app-render/instant-validation/instant-samples.js safe No malicious patterns detected; the code implements framework-internal validation sample tracking with proxies and error handling, with no network exfiltration, credential harvesting, dynamic code execution, or process spawning.
dist/esm/server/app-render/instant-validation/instant-validation-error.js safe No malicious patterns detected
dist/esm/server/app-render/instant-validation/instant-validation.js safe No malicious patterns detected; the file is legitimate Next.js internal instant validation logic with only development-gated conditional requires.
dist/esm/server/app-render/instant-validation/stream-utils.js safe No malicious patterns detected; the code only creates Node.js Readable streams for internal React rendering with no external network, filesystem, or process manipulation.
dist/esm/server/app-render/interop-default.js safe No malicious patterns detected
dist/esm/server/app-render/make-get-server-inserted-html.js safe No malicious patterns detected; the file appears to be legitimate Next.js internal server-side rendering code with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/server/app-render/manifests-singleton.js safe This is legitimate Next.js framework code for managing server/client reference manifests and server actions, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/esm/server/app-render/metadata-insertion/create-server-inserted-metadata.js safe This file safely constructs a nonce-protected inline script to reinsert icon links into <head>; no malicious patterns were detected.
dist/esm/server/app-render/module-loading/instrument-module-getter.js safe No malicious patterns detected; the code is a legitimate Next.js instrumentation wrapper for tracking pending module imports, with no data exfiltration, credential harvesting, obfuscation, dynamic code execution, or suspicious network/process activity.
dist/esm/server/app-render/module-loading/track-dynamic-import.js safe No malicious patterns detected; the file implements legitimate dynamic import tracking for Next.js caching.
dist/esm/server/app-render/module-loading/track-module-loading.external.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/module-loading/track-module-loading.instance.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/parse-and-validate-flight-router-state.js safe The code parses and validates a router state header with size limits and schema validation, containing no malicious patterns such as data exfiltration, obfuscated execution, or unauthorized system access.
dist/esm/server/app-render/postponed-state.js safe The file is a standard Next.js server rendering module for serializing and parsing postponed render state; it contains no network, filesystem, process, credential, obfuscation, or dynamic execution patterns.
dist/esm/server/app-render/prospective-render-utils.js safe No malicious patterns detected; the code only performs error logging and message formatting for Next.js prospective render debugging.
dist/esm/server/app-render/react-large-shell-error.js safe No malicious patterns detected
dist/esm/server/app-render/react-server.node.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/render-css-resource.js safe No malicious patterns detected; the code is a legitimate Next.js internal utility for rendering CSS resources.
dist/esm/server/app-render/required-scripts.js safe No malicious patterns detected; the code only constructs script URLs and integrity attributes for Next.js asset loading.
dist/esm/server/app-render/rsc/postpone.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/rsc/preloads.js safe No malicious patterns detected; the code only wraps ReactDOM preload/preconnect APIs for RSC rendering helpers.
dist/esm/server/app-render/rsc/taint.js safe No malicious patterns detected; the file only exports React's experimental taint APIs gated by an environment flag.
dist/esm/server/app-render/segment-explorer-path.js safe No malicious patterns detected; the file only performs local path normalization and string manipulation for Next.js segment explorer functionality.
dist/esm/server/app-render/server-inserted-html.js safe No malicious patterns detected; the code is a standard React server-side HTML insertion utility with no exfiltration, obfuscation, or dynamic execution.
dist/esm/server/app-render/staged-rendering.js safe No malicious patterns detected; the code implements a staged rendering controller with no network, filesystem, process execution, obfuscation, or credential access.
dist/esm/server/app-render/stale-time.js safe No malicious patterns detected; the code is a benign internal utility for tracking stale-time values in React Server Components, with no network, filesystem, process, or dynamic-execution activity.
dist/esm/server/app-render/stream-ops.js safe No malicious patterns detected
dist/esm/server/app-render/stream-ops.node.js safe No malicious patterns detected
dist/esm/server/app-render/stream-ops.web.js safe No malicious patterns detected; this is legitimate Next.js internal web stream handling code for React server rendering.
dist/esm/server/app-render/strip-flight-headers.js safe No malicious patterns detected
dist/esm/server/app-render/sync-io-messages.js safe No malicious patterns detected; the file only constructs Next.js prerender error messages with hardcoded documentation URLs and performs no network, filesystem, process, or dynamic code operations.
dist/esm/server/app-render/types.js safe This file only defines schema validation structures using the superstruct library and contains no malicious patterns or security concerns.
dist/esm/server/app-render/use-flight-response.js safe The code is part of a React Server Component rendering utility and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized process execution.
dist/esm/server/app-render/vary-params.js safe No malicious patterns detected; the code implements vary-params tracking for React Server Components using standard language features (classes, Proxy, AsyncIterator, AsyncLocalStorage) without network, filesystem, process, credential, or eval activity.
dist/esm/server/app-render/wait-for-response.js safe Cleared by Jev triage; no further analysis needed
dist/esm/server/app-render/walk-tree-with-flight-router-state.js safe No malicious patterns detected; this is standard Next.js internal server-side routing code with no exfiltration, credential harvesting, obfuscation, or process/network abuse.
dist/esm/server/app-render/work-async-storage-instance.js safe No malicious patterns detected

Scanned versions of next

VersionVerdictFilesScanned
16.3.8 Needs review 3305 Oct 6, 2026

Frequently asked questions

Is next safe to use?

No confirmed malware was found in next@16.3.8, but the review flagged 6 high, 245 medium, 685 low severity findings for risky patterns worth checking before you rely on it.

Does next contain malware?

No malware was identified in next@16.3.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was next checked?

Togoder Security downloaded the published npm package and had an AI model read its 3305 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan next together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in next@16.3.8, cost nothing.

Related security reports