Summary
Togoder Security scanned the npm package prettier-plugin-tailwindcss@0.8.1 on Oct 6, 2026. An AI review of 5 source files produced 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
dynamic-import-with-computed-input
NPS-8EEC64C0DE6F
The loadPlugin/loadPlugins machinery dynamically imports modules based on user-supplied strings (options.plugins and names passed via Prettier configuration). Specifically, importIfExists/loadIfExists(name) and findEnabledPlugin(options, name) resolve and dynamically import arbitrary plugin names from options.plugins. If options.plugins is attacker-controlled (e.g., via a malicious Prettier config file, package.json prettier field, or --plugin CLI argument), an attacker could force loading of arbitrary modules from the filesystem. This is a config-driven code execution surface.
Dynamic imports
NPS-1CADAEBFD351
The code dynamically imports modules based on resolved paths from user/project configuration (e.g., import(pathToFileURL(resolveJsFrom(baseDir, pkgName)).toString()) and dynamic imports of ./v3-D-mr2VVh.mjs / ./v4-C-HWEQJm.mjs). While this appears to be legitimate Tailwind CSS config loading, dynamic imports based on computed paths can be abused if the resolution logic is influenced by attacker-controlled inputs. The resolveJsFrom function is imported from another module and its implementation is not shown, so its safety cannot be fully verified.
Potential arbitrary code execution via config loading
NPS-970C0BA8F776
The code loads and executes JavaScript/TypeScript config files (Tailwind config) via dynamic import. If an attacker can place a malicious tailwind.config.js in a directory that is searched, it would be executed in the context of the application. This is inherent to the tool's design (loading user configs) but is a security consideration.
dynamic-imports
NPS-DF863B0DA9E5
Multiple plugin loaders use importer: () => import(...) with hardcoded module specifiers, plus a generic loader in loadPlugins that iterates over opts.load entries. Hardcoded imports are normal; however, the generic loader combined with findEnabledPlugin allows loading of locally resolved plugins by name. maybeResolve(name) is used to compare against the plugin string, which resolves a module name to a path on disk and compares it. No data exfiltration or command execution is present in these paths, but the ability to dynamically load external modules driven by user/plugin configuration is worth flagging.
filesystem-and-path-reflective-behavior
NPS-E0CF2F4A518B
The code calls prettier.resolveConfigFile(filePath), uses path.dirname, path.isAbsolute, and resolves config/stylesheet/entrypoint paths from user-provided options (tailwindConfig, tailwindStylesheet, tailwindEntryPoint). These are read from the file being formatted / user config, and are used to load Tailwind configuration and CSS. This is expected behavior for a Tailwind Prettier plugin (reading local config), not exfiltration.
File system access outside package scope
NPS-0927993E8624
The code reads directories and stats files outside the package scope by traversing upward from the current working directory or a provided input directory to locate Tailwind config files (tailwind.config.js, .cjs, .mjs, .ts). It also reads arbitrary stylesheet paths. This is expected behavior for a Tailwind CSS tool but represents file system access beyond the immediate package.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.mjs | medium | The code is a legitimate Prettier plugin for sorting Tailwind classes across many template languages; it contains no exfiltration, credential harvesting, obfuscated payloads, or shell/child_process usage. The only notable concern is dynamic module importing driven by Prettier plugin configuration, which is a standard (if potentially risky) pattern for Prettier plugins and requires an already-compromised config to exploit. |
| dist/sorter-BZkvDMjt.mjs | medium | The code appears to be a legitimate Tailwind CSS sorter utility with expected dynamic imports and file system traversal for config loading, but carries inherent risks from executing project config files and dynamic module resolution. |
| dist/chunk-DSjvVL_1.mjs | safe | No malicious patterns detected; the file contains only standard ESM/CJS interop and utility helpers generated by a bundler. |
| dist/sorter.mjs | safe | No malicious patterns detected |
| dist/utils-D8dQkKEd.mjs | safe | No malicious patterns detected; the code provides AST traversal, string splicing, bigint sign, and directory cache utilities without any network, filesystem, process, or credential access. |
Frequently asked questions
Is prettier-plugin-tailwindcss safe to use?
No confirmed malware was found in prettier-plugin-tailwindcss@0.8.1, but the review flagged 3 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does prettier-plugin-tailwindcss contain malware?
No malware was identified in prettier-plugin-tailwindcss@0.8.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was prettier-plugin-tailwindcss checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan prettier-plugin-tailwindcss together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in prettier-plugin-tailwindcss@0.8.1, cost nothing.