# reusify@1.1.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:24:21.000Z
- Files reviewed: 6
- Findings: 6 low severity findings
- Report: https://security.togoder.click/npm/reusify
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package reusify@1.1.0 on Oct 6, 2026. An AI review of 6 source files produced 6 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] No suspicious network activity

Finding ID: `NPS-41B98D072FD6`

File: `benchmarks/reuseNoCodeFunction.js`

No network requests, sockets, or data exfiltration patterns present.

### [low] No credential or environment access

Finding ID: `NPS-786C8DDA2507`

File: `benchmarks/reuseNoCodeFunction.js`

No access to process.env, filesystem credentials, or sensitive paths.

### [low] No dynamic code execution

Finding ID: `NPS-FF9CE2597C3D`

File: `benchmarks/reuseNoCodeFunction.js`

No eval, new Function, vm, or dynamic imports used.

### [low] No process spawning

Finding ID: `NPS-204F3FB9EE98`

File: `benchmarks/reuseNoCodeFunction.js`

No child_process or shell command invocation.

### [low] Import of local modules

Finding ID: `NPS-B2742D090AB8`

File: `benchmarks/reuseNoCodeFunction.js:3`

The file requires '../' (reusify) and './fib' which are local package modules, not external sources.

### [low] Benign top-level code

Finding ID: `NPS-28F2CDEA1EE7`

File: `benchmarks/reuseNoCodeFunction.js:31`

Top-level code only runs a benchmark loop for performance measurement and logs timing to console.

## Files reviewed

- `benchmarks/createNoCodeFunction.js` (safe): This is a legitimate benchmark script that measures function call overhead using a local fib module, with no malicious patterns detected.
- `benchmarks/fib.js` (safe): Cleared by Jev triage; no further analysis needed
- `benchmarks/reuseNoCodeFunction.js` (safe): This is a benign benchmark file for the reusify library; no malicious patterns or security concerns were detected.
- `eslint.config.js` (safe): No malicious patterns detected
- `reusify.js` (safe): Cleared by Jev triage; no further analysis needed
- `test.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
