# tr46@0.0.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:41:22.000Z
- Files reviewed: 1
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/tr46@0.0.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tr46@0.0.3 on Oct 4, 2026. An AI review of 1 source file produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Potential unhandled null dereference

Finding ID: `NPS-66C4614EBA46`

File: `index.js:57`

`mapChars` calls `findStatus(codePoint)` and immediately dereferences `status[1]` in the switch. `findStatus` can return `null`, which would throw a TypeError. This could be triggered by crafted input and is not guarded.

### [low] ReferenceError from undeclared variable

Finding ID: `NPS-C34CC50DD48C`

File: `index.js:189`

Inside `validateLabel`'s second loop, the condition references `processing` (`processing === PROCESSING_OPTIONS.TRANSITIONAL` and `processing === PROCESSING_OPTIONS.NONTRANSITIONAL`), but `processing` is not defined in that scope; the function parameters are `label` and `processing_option`. This causes a `ReferenceError` at runtime, which is caught by the surrounding try/catch in `processing()` and silently marks the domain as invalid. The intended `processing_option` argument is never used in the validation loop, so per-code-point validity checks are effectively skipped/broken.

### [low] Bug in DNS length verification logic

Finding ID: `NPS-07434B96E710`

File: `index.js:233`

In the verifyDnsLength block, the code computes `var total = labels.slice(0, labels.length - 1).join(".").length;` producing a number, then checks `if (total.length > 253 || total.length === 0)`. Since `total` is a number, `total.length` is undefined, so the length check never triggers. Additionally, inside the loop it checks `labels.length > 63` instead of `labels[i].length > 63`, so individual label length is never validated. This silently disables domain length validation, potentially allowing invalid/overlong domains to pass verification.

## Files reviewed

- `index.js` (medium): No malicious patterns (exfiltration, credential theft, dynamic execution, install-time hooks, or network/process activity) were found; the code is a standard punycode/IDNA utility with several non-security logic bugs.

## Version ranges

None of the 2 scanned versions of tr46 are flagged high or critical. The latest scanned version, 6.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 6.0.0 (`6.0.0`): clean
- 2.1.0 – 3.0.0 (`>=2.1.0 <=3.0.0`): not scanned
- 0.0.3 (`0.0.3`): medium

## Scanned versions

- [6.0.0](https://security.togoder.click/npm/tr46@6.0.0): safe, 2026-10-06T14:24:39.000Z
- [0.0.3](https://security.togoder.click/npm/tr46@0.0.3): medium, 2026-10-04T16:41:22.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
