Togoder security

npm package security report

node-mock-http@1.0.4 security report

No malicious code found.

No issues Version 1.0.4 Files reviewed 10 Size 92.6 KB Scanned

Summary

Togoder Security scanned the npm package node-mock-http@1.0.4 on Oct 4, 2026. An AI review of 10 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Informational

NPS-4264FA51A477

This is a bundled, minified/obfuscated polyfill of the standard Node.js 'buffer' module (nodeless/browser build). It contains standard buffer implementation code, base64/hex/utf8 conversions, and IEEE754 float read/write helpers. No network calls, environment/credential access, file system manipulation, process spawning, eval/Function usage, or other malicious patterns are present.

dist/_polyfill/buffer/nodeless.cjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/_polyfill/buffer/node.cjs safe No malicious patterns detected
dist/_polyfill/buffer/node.mjs safe No malicious patterns detected
dist/_polyfill/buffer/nodeless.cjs safe The file is a legitimate 'buffer' polyfill with no detectable malicious patterns; risk is limited to the usual obfuscation from bundling/minification.
dist/_polyfill/buffer/nodeless.mjs safe No malicious patterns detected; the code is a legitimate Buffer polyfill with no data exfiltration, obfuscation, or dynamic code execution.
dist/_polyfill/events/node.cjs safe No malicious patterns detected
dist/_polyfill/events/node.mjs safe This file simply re-exports the built-in Node.js EventEmitter from node:events with no obfuscation, side effects, or malicious patterns.
dist/_polyfill/events/nodeless.cjs safe This is a legitimate bundled polyfill implementation of Node.js's events module with no malicious patterns detected.
dist/_polyfill/events/nodeless.mjs safe This is a legitimate nodeless EventEmitter polyfill with no malicious patterns detected.
dist/index.cjs safe No malicious patterns detected; the code is a polyfill/mock implementation of Node.js HTTP stream modules with no network, filesystem, process, or dynamic code execution behaviors.
dist/index.mjs safe No malicious patterns detected; the code is a Node.js HTTP polyfill with only stub implementations and no data exfiltration, credential harvesting, obfuscation, or process execution.

Affected version ranges

None of the 2 scanned versions of node-mock-http are flagged high or critical. The latest scanned version, 1.0.5, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.0.41.0.5
VersionsVerdictCountRangeTop findings
1.0.4 โ€“ 1.0.5 No issues 2 >=1.0.4 <=1.0.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of node-mock-http

VersionVerdictFilesScanned
1.0.5 No issues 10 Oct 4, 2026
1.0.4 No issues 10 Oct 4, 2026

Frequently asked questions

Is node-mock-http safe to use?

Our AI source review of node-mock-http@1.0.4 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does node-mock-http contain malware?

No malware was identified in node-mock-http@1.0.4 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was node-mock-http checked?

Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan node-mock-http together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in node-mock-http@1.0.4, cost nothing.

Related security reports