# ox@0.9.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T21:17:51.000Z
- Files reviewed: 331
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/ox@0.9.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package ox@0.9.3 on Oct 4, 2026. An AI review of 331 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Cryptographic Practice

Finding ID: `NPS-247B20285B36`

File: `_cjs/core/WebCryptoP256.js:68`

The sign function normalizes the ECDSA 's' value to low-S form. This is correct and secure but differs from some external expectations if callers assume the WebCrypto signature format verbatim.

### [low] weak randomness

Finding ID: `NPS-C52ADA31D27E`

File: `_cjs/core/internal/uid.js:12`

The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.

## Files reviewed

- `_cjs/core/Abi.js` (safe): No malicious patterns detected
- `_cjs/core/AbiConstructor.js` (safe): No malicious patterns detected
- `_cjs/core/AbiError.js` (safe): No malicious patterns detected
- `_cjs/core/AbiEvent.js` (safe): No malicious patterns detected; the file is a legitimate Ethereum ABI event encoding/decoding utility with standard error handling and no network, filesystem, or shell interactions.
- `_cjs/core/AbiFunction.js` (safe): No malicious patterns detected; the code is a standard ABI encoding/decoding utility with no network, filesystem, process, or dynamic code execution behavior.
- `_cjs/core/AbiItem.js` (safe): No malicious patterns detected; the code is a legitimate ABI utility module with no network, filesystem, process, or dynamic execution behavior.
- `_cjs/core/AbiParameters.js` (safe): No malicious patterns detected
- `_cjs/core/AccessList.js` (safe): No malicious patterns detected; the code only performs local validation and transformation of Ethereum access list structures.
- `_cjs/core/AccountProof.js` (safe): No malicious patterns detected
- `_cjs/core/Address.js` (safe): No malicious patterns detected; the code is a legitimate Ethereum address utility for validation, checksumming, and comparison.
- `_cjs/core/AesGcm.js` (safe): No malicious patterns detected
- `_cjs/core/Authorization.js` (safe): No malicious patterns detected; the file contains only pure data transformation and hashing utilities for EIP-7702 authorization objects.
- `_cjs/core/Base58.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/Base64.js` (safe): No malicious patterns detected; the code is a straightforward Base64 encoder/decoder with no network, filesystem, credential, or dynamic execution activity.
- `_cjs/core/BinaryStateTree.js` (safe): No malicious patterns detected; the file implements a binary state tree using BLAKE3 hashing with no network, filesystem, process, or dynamic execution activity.
- `_cjs/core/Blobs.js` (safe): No malicious patterns detected; the code implements Ethereum EIP-4844 blob/KZG utility functions with no exfiltration, credential harvesting, dynamic execution, or process spawning.
- `_cjs/core/Block.js` (safe): No malicious patterns detected; the code only performs Ethereum block RPC serialization/deserialization using local hex and transaction utilities.
- `_cjs/core/BlockOverrides.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/Bloom.js` (safe): No malicious patterns detected; the code implements a standard Ethereum bloom filter check using only in-package modules and no network, filesystem, or dynamic execution capabilities.
- `_cjs/core/Bls.js` (safe): No malicious patterns detected; code implements BLS signature cryptography using the @noble/curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `_cjs/core/BlsPoint.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/Bytes.js` (safe): No malicious patterns detected; the file is a standard utility library for byte/Uint8Array manipulation.
- `_cjs/core/Caches.js` (safe): No malicious patterns detected
- `_cjs/core/ContractAddress.js` (safe): The code implements standard Ethereum contract address derivation (CREATE/CREATE2) using well-known cryptographic libraries without any malicious patterns.
- `_cjs/core/Ed25519.js` (safe): The code is a standard cryptographic utility for Ed25519 key generation, signing, and verification using the well-known @noble/curves library, with no malicious patterns detected.
- `_cjs/core/Ens.js` (safe): No malicious patterns detected; the file implements ENS name normalization and hashing using only local crypto utilities and a standard normalization library.
- `_cjs/core/Errors.js` (safe): No malicious patterns detected; the file is a standard error class implementation with no network, filesystem, or dynamic execution activity.
- `_cjs/core/Fee.js` (safe): No malicious patterns detected
- `_cjs/core/Filter.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/Hash.js` (safe): The code is a simple cryptographic hash utility that delegates to well-known @noble/hashes functions and contains no malicious patterns.
- `_cjs/core/HdKey.js` (safe): No malicious patterns detected; the code is a thin, standard wrapper around the @scure/bip32 library for HD key derivation.
- `_cjs/core/Hex.js` (safe): No malicious patterns detected; this is a hexadecimal encoding/decoding utility with no network, filesystem, process, or dynamic code execution activity.
- `_cjs/core/Json.js` (safe): No malicious patterns detected; the code only provides JSON parsing/stringifying with BigInt support.
- `_cjs/core/Keystore.js` (safe): This is a legitimate Ethereum keystore encryption/decryption module using standard cryptographic primitives from @noble libraries, with no malicious patterns detected.
- `_cjs/core/Kzg.js` (safe): No malicious patterns detected
- `_cjs/core/Log.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/Mnemonic.js` (safe): No malicious patterns detected
- `_cjs/core/P256.js` (safe): No malicious patterns detected
- `_cjs/core/PersonalMessage.js` (safe): No malicious patterns detected
- `_cjs/core/Provider.js` (safe): No malicious patterns detected; the file only defines Ethereum provider error classes and utility functions for wrapping JSON-RPC providers.
- `_cjs/core/PublicKey.js` (safe): No malicious patterns detected
- `_cjs/core/Rlp.js` (safe): No malicious patterns detected; the code is a standard RLP encoding/decoding implementation with no exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `_cjs/core/RpcRequest.js` (safe): No malicious patterns detected; the code only creates JSON-RPC 2.0 request objects with no network, filesystem, process, or dynamic execution behavior.
- `_cjs/core/RpcResponse.js` (safe): No malicious patterns detected
- `_cjs/core/RpcSchema.js` (safe): No malicious patterns detected
- `_cjs/core/RpcTransport.js` (safe): The code implements a standard HTTP-based RPC transport using fetch with timeout and error handling, and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `_cjs/core/Secp256k1.js` (safe): No malicious patterns detected; the code is a standard secp256k1 cryptographic wrapper with no exfiltration, obfuscation, or process execution.
- `_cjs/core/Signature.js` (safe): No malicious patterns detected; the code is a standard Ethereum signature handling utility with no network, filesystem, process, or obfuscation concerns.
- `_cjs/core/Siwe.js` (safe): No malicious patterns detected; the code is a standard Sign-In with Ethereum (SIWE) message parser and validator with no exfiltration, obfuscation, dynamic execution, or network activity.
- `_cjs/core/Solidity.js` (safe): The code contains only Solidity type definitions and regex patterns with no malicious behavior.
- `_cjs/core/StateOverrides.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/Transaction.js` (safe): No malicious patterns detected
- `_cjs/core/TransactionEnvelope.js` (safe): No malicious patterns detected; the file only defines custom error classes for transaction envelope validation.
- `_cjs/core/TransactionEnvelopeEip1559.js` (safe): No malicious patterns detected
- `_cjs/core/TransactionEnvelopeEip2930.js` (safe): No malicious patterns detected; the code is a standard Ethereum EIP-2930 transaction envelope implementation with no network, filesystem, process, or credential access.
- `_cjs/core/TransactionEnvelopeEip4844.js` (safe): No malicious patterns detected; the file implements standard EIP-4844 transaction serialization/deserialization with no exfiltration, credential access, dynamic code execution, or process spawning.
- `_cjs/core/TransactionEnvelopeEip7702.js` (safe): This is a legitimate Ethereum EIP-7702 transaction envelope serialization/deserialization module with no malicious patterns detected.
- `_cjs/core/TransactionEnvelopeLegacy.js` (safe): No malicious patterns detected; the code implements standard Ethereum legacy transaction serialization and formatting with no network, filesystem, or process-related activity.
- `_cjs/core/TransactionReceipt.js` (safe): No malicious patterns detected
- `_cjs/core/TransactionRequest.js` (safe): No malicious patterns detected; the code is a straightforward Ethereum transaction request serializer that safely converts numeric fields to hex strings without any exfiltration, code execution, or system access.
- `_cjs/core/TypedData.js` (safe): No malicious patterns detected; the code is a legitimate EIP-712 typed data implementation for Ethereum with no network, filesystem, process, or dynamic execution behavior.
- `_cjs/core/ValidatorData.js` (safe): No malicious patterns detected
- `_cjs/core/Value.js` (safe): No malicious patterns detected
- `_cjs/core/WebAuthnP256.js` (safe): No malicious patterns detected; the code is a legitimate WebAuthn/P256 utility module with no exfiltration, credential harvesting, obfuscation, or process/network abuse.
- `_cjs/core/WebCryptoP256.js` (safe): No malicious patterns detected; the code implements standard WebCrypto ECDSA/ECDH operations without exfiltration, process spawning, or dynamic execution.
- `_cjs/core/Withdrawal.js` (safe): No malicious patterns detected; the code only performs straightforward type conversions for withdrawal data.
- `_cjs/core/X25519.js` (safe): No malicious patterns detected; the file is a straightforward X25519 wrapper around @noble/curves with no network, filesystem, process, or dynamic code execution activity.
- `_cjs/core/internal/abi.js` (safe): No malicious patterns detected
- `_cjs/core/internal/abiConstructor.js` (safe): No malicious patterns detected; the file only contains a CommonJS export marker and a source map comment.
- `_cjs/core/internal/abiError.js` (safe): No malicious patterns detected
- `_cjs/core/internal/abiEvent.js` (safe): No malicious patterns detected
- `_cjs/core/internal/abiFunction.js` (safe): No malicious patterns detected
- `_cjs/core/internal/abiItem.js` (safe): No malicious patterns detected; the file contains legitimate ABI signature normalization and type validation logic for the viem Ethereum library.
- `_cjs/core/internal/abiParameters.js` (safe): No malicious patterns detected
- `_cjs/core/internal/base58.js` (safe): No malicious patterns detected; the file implements standard Base58 encoding without network, filesystem, process, or credential access.
- `_cjs/core/internal/bytes.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/internal/cursor.js` (safe): No malicious patterns detected; the code implements a binary cursor with bounds checking and recursion limits, and contains no network, filesystem, process execution, or obfuscated activity.
- `_cjs/core/internal/ens.js` (safe): No malicious patterns detected
- `_cjs/core/internal/entropy.js` (safe): No malicious patterns detected; the file only defines a simple module-level boolean and setter with no network, filesystem, process, or dynamic code execution activity.
- `_cjs/core/internal/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/internal/hdKey.js` (safe): No malicious patterns detected; the code is a straightforward adapter that converts a scure HD key object into a local format using pure cryptographic operations with no network, filesystem, or process activity.
- `_cjs/core/internal/hex.js` (safe): No malicious patterns detected; the code only provides hex string manipulation utilities.
- `_cjs/core/internal/lru.js` (safe): No malicious patterns detected
- `_cjs/core/internal/mnemonic/wordlists.js` (safe): No malicious patterns detected
- `_cjs/core/internal/promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/core/internal/register.js` (safe): No malicious patterns detected
- `_cjs/core/internal/rpcSchema.js` (safe): This file is a generated TypeScript declaration stub with no executable logic other than the standard CommonJS module marker, and contains no malicious patterns.
- `_cjs/core/internal/rpcSchemas/eth.js` (safe): No malicious patterns detected
- `_cjs/core/internal/rpcSchemas/wallet.js` (safe): No malicious patterns detected
- `_cjs/core/internal/rpcTransport.js` (safe): No malicious patterns detected; the file implements a straightforward JSON-RPC transport wrapper with no obfuscation, network exfiltration, process spawning, or filesystem manipulation.
- `_cjs/core/internal/types.js` (safe): No malicious patterns detected
- `_cjs/core/internal/uid.js` (safe): No malicious patterns detected; only a minor use of non-cryptographic randomness for ID generation.
- `_cjs/core/internal/webauthn.js` (safe): No malicious patterns detected; the code performs standard WebAuthn credential parsing using cryptographic primitives from @noble/curves and the Web Crypto API.
- `_cjs/core/version.js` (safe): No malicious patterns detected
- `_cjs/erc4337/EntryPoint.js` (safe): No malicious patterns detected; the file only exports standard ERC-4337 EntryPoint ABIs and contract addresses.
- `_cjs/erc4337/RpcSchema.js` (safe): No malicious patterns detected
- `_cjs/erc4337/UserOperation.js` (safe): No malicious patterns detected; the code is a legitimate ERC-4337 UserOperation utility library with no network, filesystem, or process manipulation.
- `_cjs/erc4337/UserOperationGas.js` (safe): The code performs straightforward conversion of ERC-4337 UserOperation gas fields between RPC and internal BigInt representations with no malicious patterns or security concerns.
- `_cjs/erc4337/UserOperationReceipt.js` (safe): No malicious patterns detected; the code only performs data serialization/deserialization for ERC-4337 user operation receipts.
- `_cjs/erc4337/index.js` (safe): No malicious patterns detected
- `_cjs/erc6492/SignatureErc6492.js` (safe): No malicious patterns detected; the file implements ERC-6492 wrapped signature handling with static bytecode, ABI, and validation logic only.
- `_cjs/erc6492/index.js` (safe): No malicious patterns detected
- `_cjs/erc8010/SignatureErc8010.js` (safe): No malicious patterns detected
- `_cjs/erc8010/index.js` (safe): No malicious patterns detected
- `_cjs/index.docs.js` (safe): No malicious patterns detected; the file only re-exports modules from local index and ERC standard subdirectories with no runtime side effects or suspicious behavior.
- `_cjs/index.js` (safe): No malicious patterns detected; the file is a standard CommonJS barrel export for the viem Ethereum library.
- `_cjs/trusted-setups/Paths.js` (safe): No malicious patterns detected
- `_cjs/trusted-setups/index.js` (safe): No malicious patterns detected
- `_cjs/trusted-setups/internal/paths.js` (safe): The code simply resolves a file path relative to the module directory using Node.js path utilities, with no malicious patterns detected.
- `_cjs/version.js` (safe): No malicious patterns detected
- `_cjs/window/index.js` (safe): The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns.
- `_esm/core/Abi.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/AbiConstructor.js` (safe): No malicious patterns detected in the AbiConstructor.js file; it contains standard ABI encoding/decoding logic with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `_esm/core/AbiError.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/AbiEvent.js` (safe): No malicious patterns detected; the code is a legitimate ABI event encoding/decoding library with no exfiltration, credential harvesting, or suspicious behavior.
- `_esm/core/AbiFunction.js` (safe): No malicious patterns detected; the code performs standard ABI encoding/decoding for Ethereum smart contracts without exfiltration, obfuscation, or suspicious behavior.
- `_esm/core/AbiItem.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/AbiParameters.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/AccessList.js` (safe): No malicious patterns detected; the module only contains pure utility functions for Ethereum access list serialization with input validation.
- `_esm/core/AccountProof.js` (safe): No malicious patterns detected
- `_esm/core/Address.js` (safe): No malicious patterns detected; the file implements standard Ethereum address validation, checksumming, and ECDSA public key conversion using only internal imports and safe string/byte operations.
- `_esm/core/AesGcm.js` (safe): No malicious patterns detected; the code implements standard AES-GCM encryption and PBKDF2 key derivation using the Web Crypto API without data exfiltration, dynamic execution, or process spawning.
- `_esm/core/Authorization.js` (safe): No malicious patterns detected
- `_esm/core/Base58.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Base64.js` (safe): No malicious patterns detected in the Base64 encoding/decoding utility; it is a standard implementation with no external calls, code execution, or file system access.
- `_esm/core/BinaryStateTree.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Blobs.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Block.js` (safe): No malicious patterns detected; the code is a straightforward Ethereum block serialization/deserialization utility with no network, filesystem, or process manipulation.
- `_esm/core/BlockOverrides.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Bloom.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Bls.js` (safe): The code implements BLS12-381 cryptographic operations using the reputable @noble/curves library with no malicious patterns, external calls, or environment access.
- `_esm/core/BlsPoint.js` (safe): No malicious patterns detected; the code only performs standard BLS point serialization and deserialization using the @noble/curves library.
- `_esm/core/Bytes.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Caches.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/ContractAddress.js` (safe): The file is a legitimate Ethereum contract address implementation using CREATE and CREATE2 computation with no malicious patterns detected.
- `_esm/core/Ed25519.js` (safe): No malicious patterns detected; the code is a straightforward wrapper around @noble/curves Ed25519 utilities with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `_esm/core/Ens.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Fee.js` (safe): The file contains only an empty export and a source map reference, with no executable or suspicious code.
- `_esm/core/Filter.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Hash.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/HdKey.js` (safe): No malicious patterns detected in the HD key utility module; it only wraps @scure/bip32 for BIP-32 key derivation.
- `_esm/core/Hex.js` (safe): No malicious patterns detected; the file contains standard hex encoding/decoding utilities with no network, filesystem, process, or dynamic code execution.
- `_esm/core/Json.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Keystore.js` (safe): The file implements standard Ethereum keystore encryption/decryption using well-known cryptographic libraries with no malicious patterns, exfiltration, or dynamic code execution.
- `_esm/core/Kzg.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Log.js` (safe): No malicious patterns detected
- `_esm/core/Mnemonic.js` (safe): No malicious patterns detected; the file provides standard BIP39 mnemonic generation, validation, and HD key derivation using the audited @scure/bip39 library.
- `_esm/core/P256.js` (safe): No malicious patterns detected; the code is a standard cryptographic utility module for P256 ECDSA operations with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `_esm/core/PersonalMessage.js` (safe): The code is a clean implementation of ERC-191 personal message encoding and hashing with no malicious patterns.
- `_esm/core/Provider.js` (safe): No malicious patterns detected; the file defines EIP-1193 provider error classes, an event emitter factory, and error parsing logic without any data exfiltration, credential harvesting, obfuscation, or code execution risks.
- `_esm/core/PublicKey.js` (safe): No malicious patterns detected; this is a legitimate elliptic curve public key utility module with no network, filesystem, process, or dynamic code execution concerns.
- `_esm/core/Rlp.js` (safe): The RLP encoding/decoding module contains only pure data transformation logic with no network, filesystem, process, or dynamic code execution patterns.
- `_esm/core/RpcRequest.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/RpcResponse.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/RpcSchema.js` (safe): No malicious patterns detected
- `_esm/core/RpcTransport.js` (safe): No malicious patterns detected; the code is a standard HTTP JSON-RPC transport implementation with no data exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior.
- `_esm/core/Secp256k1.js` (safe): No malicious patterns detected; the code is a legitimate secp256k1 cryptographic utility module with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `_esm/core/Signature.js` (safe): No malicious patterns detected; the code is a standard Ethereum signature serialization/deserialization utility using secp256k1 with no network, filesystem, process, or dynamic code execution.
- `_esm/core/Siwe.js` (safe): No malicious patterns detected; the code implements EIP-4361 (Sign-In with Ethereum) message creation, parsing, and validation with no network, filesystem, process, or dynamic execution behavior.
- `_esm/core/Solidity.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/StateOverrides.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/Transaction.js` (safe): No malicious patterns detected; the file only performs Ethereum transaction serialization/deserialization and type conversions.
- `_esm/core/TransactionEnvelope.js` (safe): No malicious patterns detected; the code only defines error classes for Ethereum transaction validation with no network, filesystem, or dynamic execution behavior.
- `_esm/core/TransactionEnvelopeEip1559.js` (safe): No malicious patterns detected; the code is a standard EIP-1559 transaction envelope implementation with only local cryptographic and serialization logic.
- `_esm/core/TransactionEnvelopeEip2930.js` (safe): No malicious patterns detected; the code is a standard EIP-2930 transaction envelope implementation with no network, filesystem, process, or credential access.
- `_esm/core/TransactionEnvelopeEip4844.js` (safe): No malicious patterns detected
- `_esm/core/TransactionEnvelopeEip7702.js` (safe): No malicious patterns detected
- `_esm/core/TransactionEnvelopeLegacy.js` (safe): No malicious patterns detected; the file implements Ethereum legacy transaction serialization/deserialization logic without external data exfiltration, code execution, or suspicious behavior.
- `_esm/core/TransactionReceipt.js` (safe): No malicious patterns detected; the code is a pure data transformation module for Ethereum transaction receipts with no network, filesystem, or dynamic execution behavior.
- `_esm/core/TransactionRequest.js` (safe): No malicious patterns detected; the code is a straightforward utility that converts Ethereum transaction request objects to RPC format using hex encoding and authorization list conversion.
- `_esm/core/TypedData.js` (safe): No malicious patterns detected; the file implements standard EIP-712 typed data hashing and validation with no network, filesystem, process, or dynamic code execution activity.
- `_esm/core/ValidatorData.js` (safe): No malicious patterns detected; the file only implements ERC-191 validator data encoding and hashing using local imports.
- `_esm/core/Value.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/WebAuthnP256.js` (safe): No malicious patterns detected; the code is a standard WebAuthn P256 implementation with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
- `_esm/core/WebCryptoP256.js` (safe): No malicious patterns detected
- `_esm/core/Withdrawal.js` (safe): No malicious patterns detected
- `_esm/core/X25519.js` (safe): The code implements X25519 cryptographic utilities using the reputable @noble/curves library with no malicious patterns, network activity, or suspicious behavior.
- `_esm/core/internal/abi.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/abiConstructor.js` (safe): The file contains only an empty export and a source map comment; no executable or malicious code is present.
- `_esm/core/internal/abiError.js` (safe): No malicious patterns detected
- `_esm/core/internal/abiEvent.js` (safe): The file contains only an empty export statement and a source map reference, with no executable code or malicious patterns.
- `_esm/core/internal/abiFunction.js` (safe): No malicious patterns detected
- `_esm/core/internal/abiItem.js` (safe): No malicious patterns detected; the code is legitimate ABI signature normalization and type checking logic.
- `_esm/core/internal/abiParameters.js` (safe): This is a legitimate ABI parameter encoding/decoding module for Ethereum (likely viem) with no malicious patterns, external calls, or security concerns.
- `_esm/core/internal/base58.js` (safe): No malicious patterns detected
- `_esm/core/internal/bytes.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/cursor.js` (safe): No malicious patterns detected; the code is a well-structured binary cursor utility with only defensive error handling and no network, filesystem, process, or dynamic execution activity.
- `_esm/core/internal/ens.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/entropy.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/hdKey.js` (safe): No malicious patterns detected
- `_esm/core/internal/hex.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/lru.js` (safe): No malicious patterns detected; the code is a standard LRU cache implementation with no network, filesystem, process, environment, or obfuscated behavior.
- `_esm/core/internal/mnemonic/wordlists.js` (safe): No malicious patterns detected; the file only re-exports standard BIP39 wordlists from the @scure/bip39 package.
- `_esm/core/internal/promise.js` (safe): Cleared by Jev triage; no further analysis needed
- `_esm/core/internal/register.js` (safe): No malicious patterns detected
- `_esm/core/internal/rpcSchema.js` (safe): No malicious patterns detected; the file contains only an empty export and a source map reference.
- `_esm/core/internal/rpcSchemas/eth.js` (safe): No malicious patterns detected
- `_esm/core/internal/rpcSchemas/wallet.js` (safe): The file contains only an empty export statement and a source map reference, with no executable or suspicious code.

## Version ranges

None of the 4 scanned versions of ox are flagged high or critical. The latest scanned version, 0.14.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 0.9.17 – 0.14.0 (`>=0.9.17 <=0.14.0`): not scanned
- 0.6.7 – 0.9.6 (`>=0.6.7 <=0.9.6`): clean

## Scanned versions

- [0.9.6](https://security.togoder.click/npm/ox@0.9.6): safe, 2026-10-04T16:54:45.000Z
- [0.9.3](https://security.togoder.click/npm/ox@0.9.3): safe, 2026-10-04T21:17:51.000Z
- [0.6.9](https://security.togoder.click/npm/ox@0.6.9): safe, 2026-10-04T16:03:00.000Z
- [0.6.7](https://security.togoder.click/npm/ox@0.6.7): safe, 2026-10-04T16:14:46.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
