# safer-buffer@2.1.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T14:41:51.000Z
- Files reviewed: 3
- Findings: 3 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/safer-buffer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package safer-buffer@2.1.2 on Oct 4, 2026. An AI review of 3 source files produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] unsafe buffer allocation

Finding ID: `NPS-88F499E3D69C`

File: `dangerous.js:34`

This module intentionally exposes Node.js 'unsafe' Buffer allocation methods (allocUnsafe, allocUnsafeSlow, and deprecated legacy Buffer constructor). Uninitialized buffers can leak sensitive process memory (previous allocations containing secrets, tokens, or passwords) to callers. While this is not malicious per se, it is a deliberate re-exposure of dangerous APIs and could facilitate information disclosure if consumers misuse it.

### [medium] deprecated unsafe constructor usage

Finding ID: `NPS-60029AD700F7`

File: `dangerous.js:41`

The fallback implementation of allocUnsafe calls the deprecated Buffer(size) constructor, which allocates uninitialized memory. This reintroduces a known-unsafe API pattern that Node.js has deprecated specifically for security reasons.

### [medium] potential memory disclosure via SlowBuffer

Finding ID: `NPS-49218F2F5E81`

File: `dangerous.js:51`

Dangereous.allocUnsafeSlow falls back to buffer.SlowBuffer(size), which also returns uninitialized memory. Combined with the re-exported unsafe APIs, this module is a known package ('safer-buffer' companion) whose entire purpose is to expose unsafe Buffer methods for callers who explicitly opt in; consumers should be aware this bypasses Node's buffer initialization protections.

### [low] Deprecated API Usage

Finding ID: `NPS-2C3819A16B2F`

File: `safer.js:29`

The code uses Buffer() constructor without 'new' in the 'alloc' and 'from' fallback functions, which is deprecated and can lead to security vulnerabilities (uninitialized memory). However, the code includes safeguards: 'alloc' fills the buffer with zeros if no fill is provided, and 'from' explicitly rejects numbers and non-array-like objects. This is a deliberate attempt to provide a safer alternative to the deprecated Buffer API.

### [low] Dynamic Code Execution

Finding ID: `NPS-4E10D084655F`

File: `safer.js:72`

The use of 'process.binding' is a Node.js internal API that can access native bindings. While not inherently malicious, it is a low-level, non-public API and could be a concern if misused. However, here it is used to retrieve 'kStringMaxLength' and is wrapped in a try-catch to handle unsupported environments.

## Files reviewed

- `dangerous.js` (medium): No malicious exfiltration, credential harvesting, code execution, or backdoor patterns found, but the module deliberately re-exposes unsafe Node.js Buffer APIs that can leak uninitialized process memory to callers.
- `safer.js` (safe): The code appears to be a safety wrapper for the Node.js Buffer API, implementing safeguards against deprecated and unsafe behaviors, with no malicious patterns detected.
- `tests.js` (safe): This is a test file for a Buffer polyfill package that only tests API behavior; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were found.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
