Togoder security

npm package security report

openid-client npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 5.7.1 Files reviewed 29 Size 99.3 KB Scanned

Summary

Togoder Security scanned the npm package openid-client@5.7.1 on Oct 6, 2026. An AI review of 29 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

Potential SSRF via JWKS URI

NPS-FCADD61B6B2C

No validation or restriction on the jwks_uri scheme or host. An attacker who can control issuer configuration could potentially direct requests to internal services.

lib/helpers/issuer.js:37
low

Network request with dynamic URL

NPS-D3B67D0F034A

The code performs an HTTP GET request to this.jwks_uri, which is a configurable issuer URL. This is normal behavior for JWKS fetching, but the URL is not validated against a whitelist, potentially allowing SSRF if attacker controls issuer configuration.

lib/helpers/issuer.js:37
low

Network requests (benign)

NPS-BD4BCC557AC1

The code makes outbound HTTPS requests to fetch OpenID Connect discovery documents and WebFinger metadata. These are standard, expected behaviors for an OpenID Connect client library and are not data exfiltration. The endpoints are derived from the user-supplied issuer URL and fixed Microsoft AAD discovery URLs.

lib/issuer.js
low

Dynamic property definitions (benign)

NPS-0DA58B032C40

Object.defineProperty is used to expose metadata keys as getters. This is used to build a public API object from trusted/validated response data, not for dynamic code execution. No eval, new Function, or similar constructs are present.

lib/issuer.js:61

Files reviewed

FileVerdictWhat the reviewer saw
lib/helpers/issuer.js medium No malicious patterns detected; the code is a legitimate JWKS keystore manager with standard network fetching, LRU caching, and in-flight request deduplication, though it lacks SSRF protections on the configurable jwks_uri.
lib/client.js safe No malicious patterns detected; the code is a legitimate OpenID Connect client library.
lib/device_flow_handle.js safe No malicious patterns detected
lib/errors.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/assert.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/base64url.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/client.js safe The code is a legitimate OpenID client authentication helper that signs JWTs and constructs auth requests without any malicious patterns such as data exfiltration, credential harvesting, obfuscated execution, or backdoor installation.
lib/helpers/consts.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/decode_jwt.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/deep_clone.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/defaults.js safe No malicious patterns detected; the code is a standard deep object merging utility with prototype pollution protection.
lib/helpers/generators.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/is_key_object.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/is_plain_object.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/keystore.js safe No malicious patterns detected
lib/helpers/merge.js safe No malicious patterns detected; the code is a standard deep merge utility with explicit __proto__ and constructor guards to prevent prototype pollution.
lib/helpers/pick.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/process_response.js safe The code performs normal HTTP response processing without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
lib/helpers/request.js safe No malicious patterns detected
lib/helpers/unix_timestamp.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/weak_cache.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/webfinger_normalize.js safe No malicious patterns detected; the code is a pure string normalization helper for WebFinger URIs with no network, filesystem, process, or dynamic code execution behavior.
lib/helpers/www_authenticate_parser.js safe Cleared by Jev triage; no further analysis needed
lib/index.js safe Cleared by Jev triage; no further analysis needed
lib/index.mjs safe Cleared by Jev triage; no further analysis needed
Show 4 more files
FileVerdictWhat the reviewer saw
lib/issuer.js safe The module implements standard OpenID Connect issuer discovery and metadata handling; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or process spawning were detected.
lib/issuer_registry.js safe Cleared by Jev triage; no further analysis needed
lib/passport_strategy.js safe No malicious patterns detected
lib/token_set.js safe No malicious patterns detected; the code is a legitimate JWT TokenSet utility handling expiration and claims parsing.

Scanned versions of openid-client

VersionVerdictFilesScanned
5.7.1 Needs review 29 Oct 6, 2026

Frequently asked questions

Is openid-client safe to use?

No confirmed malware was found in openid-client@5.7.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does openid-client contain malware?

No malware was identified in openid-client@5.7.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was openid-client checked?

Togoder Security downloaded the published npm package and had an AI model read its 29 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan openid-client together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in openid-client@5.7.1, cost nothing.

Related security reports