Togoder security

npm package security report

super-regex npm package: is it safe?

No malicious code found.

No issues Version 1.1.0 Files reviewed 1 Size 6.7 KB Scanned

Summary

Togoder Security scanned the npm package super-regex@1.1.0 on Oct 6, 2026. An AI review of 1 source file produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

Worker thread usage

NPS-05AD9F263EAB

Uses make-asynchronous to run regex operations in worker threads. This is a legitimate pattern documented in the code for enabling true timeout support, not a backdoor. No shell spawning, process execution, or external network requests are present.

index.js:120
low

Dynamic code execution

NPS-625459A64C53

Uses new RegExp(source, flags) to construct regular expressions from user-provided source and flags strings. While RegExp construction is not arbitrary code execution like eval, it accepts untrusted input and could in theory allow ReDoS if not timeout-protected. The package wraps all regex execution in timeouts, mitigating this risk.

index.js:125

Files reviewed

FileVerdictWhat the reviewer saw
index.js safe The package implements regex timeout utilities using worker threads and timeouts with no evidence of malicious behavior such as data exfiltration, credential harvesting, obfuscation, or backdoor installation.

Scanned versions of super-regex

VersionVerdictFilesScanned
1.1.0 No issues 1 Oct 6, 2026

Frequently asked questions

Is super-regex safe to use?

Our AI source review of super-regex@1.1.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does super-regex contain malware?

No malware was identified in super-regex@1.1.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was super-regex checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan super-regex together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in super-regex@1.1.0, cost nothing.

Related security reports