Togoder security

npm package security report

string.prototype.repeat npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.0.0 Files reviewed 5 Size 1.8 KB Scanned

Summary

Togoder Security scanned the npm package string.prototype.repeat@1.0.0 on Oct 6, 2026. An AI review of 5 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
1
low

Findings 1

low

Dynamic module loading / import-time code execution

NPS-1F5075A12C6A

The file immediately invokes require('./shim')(), which loads and executes a sibling module named 'shim' at import time. While this is a common pattern for polyfill packages like String.prototype.repeat, the actual behavior of './shim' cannot be verified from this snippet. Any top-level code execution on import is worth reviewing, especially since the required module could contain arbitrary logic (network calls, file system access, etc.). The comment indicates the package is 'repeat v1.0.0 by @mathias', which is a known legitimate polyfill library, but the analysis is limited to the provided file.

auto.js:3

Files reviewed

FileVerdictWhat the reviewer saw
auto.js medium This is a standard polyfill entry point that executes a sibling 'shim' module on import; no malicious patterns are visible in this file, but the referenced shim should be audited as it runs automatically on import.
implementation.js safe No malicious patterns detected; the code is a clean polyfill implementation of String.prototype.repeat with no network, filesystem, or dynamic code execution concerns.
index.js safe No malicious patterns detected
polyfill.js safe Cleared by Jev triage; no further analysis needed
shim.js safe No malicious patterns detected; the shim simply applies a String.prototype.repeat polyfill.

Scanned versions of string.prototype.repeat

VersionVerdictFilesScanned
1.0.0 Needs review 5 Oct 6, 2026

Frequently asked questions

Is string.prototype.repeat safe to use?

No confirmed malware was found in string.prototype.repeat@1.0.0, but the review flagged 1 low severity finding for risky patterns worth checking before you rely on it.

Does string.prototype.repeat contain malware?

No malware was identified in string.prototype.repeat@1.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was string.prototype.repeat checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan string.prototype.repeat together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in string.prototype.repeat@1.0.0, cost nothing.

Related security reports