# prettier-plugin-tailwindcss@0.8.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:50.000Z
- Files reviewed: 5
- Findings: 3 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/prettier-plugin-tailwindcss
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package prettier-plugin-tailwindcss@0.8.1 on Oct 6, 2026. An AI review of 5 source files produced 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic-import-with-computed-input

Finding ID: `NPS-8EEC64C0DE6F`

File: `dist/index.mjs`

The `loadPlugin`/`loadPlugins` machinery dynamically imports modules based on user-supplied strings (`options.plugins` and names passed via Prettier configuration). Specifically, `importIfExists`/`loadIfExists(name)` and `findEnabledPlugin(options, name)` resolve and dynamically import arbitrary plugin names from `options.plugins`. If `options.plugins` is attacker-controlled (e.g., via a malicious Prettier config file, `package.json` `prettier` field, or `--plugin` CLI argument), an attacker could force loading of arbitrary modules from the filesystem. This is a config-driven code execution surface.

### [medium] Dynamic imports

Finding ID: `NPS-1CADAEBFD351`

File: `dist/sorter-BZkvDMjt.mjs:113`

The code dynamically imports modules based on resolved paths from user/project configuration (e.g., `import(pathToFileURL(resolveJsFrom(baseDir, pkgName)).toString())` and dynamic imports of `./v3-D-mr2VVh.mjs` / `./v4-C-HWEQJm.mjs`). While this appears to be legitimate Tailwind CSS config loading, dynamic imports based on computed paths can be abused if the resolution logic is influenced by attacker-controlled inputs. The `resolveJsFrom` function is imported from another module and its implementation is not shown, so its safety cannot be fully verified.

### [medium] Potential arbitrary code execution via config loading

Finding ID: `NPS-970C0BA8F776`

File: `dist/sorter-BZkvDMjt.mjs:113`

The code loads and executes JavaScript/TypeScript config files (Tailwind config) via dynamic import. If an attacker can place a malicious `tailwind.config.js` in a directory that is searched, it would be executed in the context of the application. This is inherent to the tool's design (loading user configs) but is a security consideration.

### [low] dynamic-imports

Finding ID: `NPS-DF863B0DA9E5`

File: `dist/index.mjs`

Multiple plugin loaders use `importer: () => import(...)` with hardcoded module specifiers, plus a generic loader in `loadPlugins` that iterates over `opts.load` entries. Hardcoded imports are normal; however, the generic loader combined with `findEnabledPlugin` allows loading of locally resolved plugins by name. `maybeResolve(name)` is used to compare against the plugin string, which resolves a module name to a path on disk and compares it. No data exfiltration or command execution is present in these paths, but the ability to dynamically load external modules driven by user/plugin configuration is worth flagging.

### [low] filesystem-and-path-reflective-behavior

Finding ID: `NPS-E0CF2F4A518B`

File: `dist/index.mjs`

The code calls `prettier.resolveConfigFile(filePath)`, uses `path.dirname`, `path.isAbsolute`, and resolves config/stylesheet/entrypoint paths from user-provided options (`tailwindConfig`, `tailwindStylesheet`, `tailwindEntryPoint`). These are read from the file being formatted / user config, and are used to load Tailwind configuration and CSS. This is expected behavior for a Tailwind Prettier plugin (reading local config), not exfiltration.

### [low] File system access outside package scope

Finding ID: `NPS-0927993E8624`

File: `dist/sorter-BZkvDMjt.mjs:155`

The code reads directories and stats files outside the package scope by traversing upward from the current working directory or a provided input directory to locate Tailwind config files (`tailwind.config.js`, `.cjs`, `.mjs`, `.ts`). It also reads arbitrary stylesheet paths. This is expected behavior for a Tailwind CSS tool but represents file system access beyond the immediate package.

## Files reviewed

- `dist/index.mjs` (medium): The code is a legitimate Prettier plugin for sorting Tailwind classes across many template languages; it contains no exfiltration, credential harvesting, obfuscated payloads, or shell/child_process usage. The only notable concern is dynamic module importing driven by Prettier plugin configuration, which is a standard (if potentially risky) pattern for Prettier plugins and requires an already-compromised config to exploit.
- `dist/sorter-BZkvDMjt.mjs` (medium): The code appears to be a legitimate Tailwind CSS sorter utility with expected dynamic imports and file system traversal for config loading, but carries inherent risks from executing project config files and dynamic module resolution.
- `dist/chunk-DSjvVL_1.mjs` (safe): No malicious patterns detected; the file contains only standard ESM/CJS interop and utility helpers generated by a bundler.
- `dist/sorter.mjs` (safe): No malicious patterns detected
- `dist/utils-D8dQkKEd.mjs` (safe): No malicious patterns detected; the code provides AST traversal, string splicing, bigint sign, and directory cache utilities without any network, filesystem, process, or credential access.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
