# super-regex@1.1.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:24:35.000Z
- Files reviewed: 1
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/super-regex
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package super-regex@1.1.0 on Oct 6, 2026. An AI review of 1 source file produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Worker thread usage

Finding ID: `NPS-05AD9F263EAB`

File: `index.js:120`

Uses `make-asynchronous` to run regex operations in worker threads. This is a legitimate pattern documented in the code for enabling true timeout support, not a backdoor. No shell spawning, process execution, or external network requests are present.

### [low] Dynamic code execution

Finding ID: `NPS-625459A64C53`

File: `index.js:125`

Uses `new RegExp(source, flags)` to construct regular expressions from user-provided source and flags strings. While RegExp construction is not arbitrary code execution like eval, it accepts untrusted input and could in theory allow ReDoS if not timeout-protected. The package wraps all regex execution in timeouts, mitigating this risk.

## Files reviewed

- `index.js` (safe): The package implements regex timeout utilities using worker threads and timeouts with no evidence of malicious behavior such as data exfiltration, credential harvesting, obfuscation, or backdoor installation.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
