# node-mock-http@1.0.5 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T21:18:01.000Z
- Files reviewed: 10
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/node-mock-http@1.0.5
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package node-mock-http@1.0.5 on Oct 4, 2026. An AI review of 10 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Informational

Finding ID: `NPS-4264FA51A477`

File: `dist/_polyfill/buffer/nodeless.cjs`

This is a bundled, minified/obfuscated polyfill of the standard Node.js 'buffer' module (nodeless/browser build). It contains standard buffer implementation code, base64/hex/utf8 conversions, and IEEE754 float read/write helpers. No network calls, environment/credential access, file system manipulation, process spawning, eval/Function usage, or other malicious patterns are present.

## Files reviewed

- `dist/_polyfill/buffer/node.cjs` (safe): No malicious patterns detected
- `dist/_polyfill/buffer/node.mjs` (safe): No malicious patterns detected
- `dist/_polyfill/buffer/nodeless.cjs` (safe): The file is a legitimate 'buffer' polyfill with no detectable malicious patterns; risk is limited to the usual obfuscation from bundling/minification.
- `dist/_polyfill/buffer/nodeless.mjs` (safe): No malicious patterns detected; the code is a legitimate Buffer polyfill with no data exfiltration, obfuscation, or dynamic code execution.
- `dist/_polyfill/events/node.cjs` (safe): No malicious patterns detected
- `dist/_polyfill/events/node.mjs` (safe): This file simply re-exports the built-in Node.js EventEmitter from node:events with no obfuscation, side effects, or malicious patterns.
- `dist/_polyfill/events/nodeless.cjs` (safe): The code is a legitimate polyfill-like implementation of Node.js EventEmitter and related utilities with no malicious patterns detected.
- `dist/_polyfill/events/nodeless.mjs` (safe): No malicious patterns detected; the code is a legitimate Node.js events module polyfill with no network, filesystem, process, or obfuscated execution behavior.
- `dist/index.cjs` (safe): No malicious patterns detected; the code appears to be a set of mock/stub HTTP and stream implementations for testing or polyfill purposes.
- `dist/index.mjs` (safe): No malicious patterns detected; the code is a set of Node.js HTTP polyfill/emulation classes and helpers without any exfiltration, credential harvesting, obfuscation, process spawning, or network activity beyond intended request handling.

## Version ranges

None of the 2 scanned versions of node-mock-http are flagged high or critical. The latest scanned version, 1.0.5, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.0.4 – 1.0.5 (`>=1.0.4 <=1.0.5`): clean

## Scanned versions

- [1.0.5](https://security.togoder.click/npm/node-mock-http@1.0.5): safe, 2026-10-04T21:18:01.000Z
- [1.0.4](https://security.togoder.click/npm/node-mock-http@1.0.4): safe, 2026-10-04T16:36:39.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
