# uuid@11.1.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:24:56.000Z
- Files reviewed: 92
- Findings: no findings
- Report: https://security.togoder.click/npm/uuid
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package uuid@11.1.1 on Oct 6, 2026. An AI review of 92 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/cjs-browser/index.js` (safe): This is the standard CommonJS entry point for the well-known 'uuid' npm package, containing only re-exports of UUID generation and parsing functions with no malicious patterns.
- `dist/cjs-browser/max.js` (safe): The file only exports a constant UUID string with no network, filesystem, process, or dynamic code execution behavior.
- `dist/cjs-browser/md5.js` (safe): No malicious patterns detected; the code is a standard implementation of the MD5 hashing algorithm.
- `dist/cjs-browser/native.js` (safe): No malicious patterns detected
- `dist/cjs-browser/nil.js` (safe): No malicious patterns detected
- `dist/cjs-browser/parse.js` (safe): No malicious patterns detected
- `dist/cjs-browser/regex.js` (safe): No malicious patterns detected
- `dist/cjs-browser/rng.js` (safe): The code is a standard UUID v4 random number generator using crypto.getRandomValues with no malicious patterns detected.
- `dist/cjs-browser/sha1.js` (safe): No malicious patterns detected; the file is a standard SHA-1 hash implementation with no network, filesystem, process, or obfuscated code.
- `dist/cjs-browser/stringify.js` (safe): No malicious patterns detected
- `dist/cjs-browser/types.js` (safe): No malicious patterns detected
- `dist/cjs-browser/uuid-bin.js` (safe): No malicious patterns detected
- `dist/cjs-browser/v1.js` (safe): No malicious patterns detected; the code is a standard UUID v1/v6 generator implementing RFC 4122 structure with timestamp, clock sequence, and node handling.
- `dist/cjs-browser/v1ToV6.js` (safe): No malicious patterns detected; the code is a simple UUID v1 to v6 conversion utility with no external calls or suspicious behavior.
- `dist/cjs-browser/v3.js` (safe): This is a legitimate UUID v3 implementation that exports DNS/URL namespace constants and uses standard require statements with no malicious patterns.
- `dist/cjs-browser/v35.js` (safe): No malicious patterns detected
- `dist/cjs-browser/v4.js` (safe): This is a standard UUID v4 generator implementation using existing internal modules with no malicious patterns detected.
- `dist/cjs-browser/v5.js` (safe): No malicious patterns detected
- `dist/cjs-browser/v6.js` (safe): No malicious patterns detected; the code is a standard UUID v6 generation implementation with no external calls, dynamic execution, or filesystem manipulation.
- `dist/cjs-browser/v6ToV1.js` (safe): No malicious patterns detected
- `dist/cjs-browser/v7.js` (safe): No malicious patterns detected; the code implements UUID v7 generation using local RNG and state management without any exfiltration, dynamic execution, or suspicious behavior.
- `dist/cjs-browser/validate.js` (safe): No malicious patterns detected
- `dist/cjs-browser/version.js` (safe): No malicious patterns detected
- `dist/cjs/index.js` (safe): This is the standard CommonJS entry point for the well-known 'uuid' npm package, containing only re-exports of UUID generation and parsing functions with no malicious patterns.
- `dist/cjs/max.js` (safe): The file only exports a constant UUID string with no network, filesystem, process, or dynamic code execution behavior.
- `dist/cjs/md5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/cjs/native.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/cjs/nil.js` (safe): No malicious patterns detected
- `dist/cjs/parse.js` (safe): No malicious patterns detected
- `dist/cjs/regex.js` (safe): No malicious patterns detected
- `dist/cjs/rng.js` (safe): The code provides a cryptographically secure random number generator using Node.js crypto.randomFillSync with an internal pool; no malicious patterns detected.
- `dist/cjs/sha1.js` (safe): No malicious patterns detected
- `dist/cjs/stringify.js` (safe): No malicious patterns detected
- `dist/cjs/types.js` (safe): No malicious patterns detected
- `dist/cjs/uuid-bin.js` (safe): No malicious patterns detected
- `dist/cjs/v1.js` (safe): No malicious patterns detected; the code is a standard UUID v1/v6 generator implementing RFC 4122 structure with timestamp, clock sequence, and node handling.
- `dist/cjs/v1ToV6.js` (safe): No malicious patterns detected; the code is a simple UUID v1 to v6 conversion utility with no external calls or suspicious behavior.
- `dist/cjs/v3.js` (safe): This is a legitimate UUID v3 implementation that exports DNS/URL namespace constants and uses standard require statements with no malicious patterns.
- `dist/cjs/v35.js` (safe): No malicious patterns detected
- `dist/cjs/v4.js` (safe): This is a standard UUID v4 generator implementation using existing internal modules with no malicious patterns detected.
- `dist/cjs/v5.js` (safe): No malicious patterns detected
- `dist/cjs/v6.js` (safe): No malicious patterns detected; the code is a standard UUID v6 generation implementation with no external calls, dynamic execution, or filesystem manipulation.
- `dist/cjs/v6ToV1.js` (safe): No malicious patterns detected
- `dist/cjs/v7.js` (safe): No malicious patterns detected; the code implements UUID v7 generation using local RNG and state management without any exfiltration, dynamic execution, or suspicious behavior.
- `dist/cjs/validate.js` (safe): No malicious patterns detected
- `dist/cjs/version.js` (safe): No malicious patterns detected
- `dist/esm-browser/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/max.js` (safe): No malicious patterns detected
- `dist/esm-browser/md5.js` (safe): No malicious patterns detected
- `dist/esm-browser/native.js` (safe): No malicious patterns detected
- `dist/esm-browser/nil.js` (safe): No malicious patterns detected
- `dist/esm-browser/parse.js` (safe): No malicious patterns detected; the code is a standard UUID parser with no network, filesystem, process, or dynamic code execution activity.
- `dist/esm-browser/regex.js` (safe): No malicious patterns detected
- `dist/esm-browser/rng.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/sha1.js` (safe): No malicious patterns detected; the file is a standard SHA-1 implementation.
- `dist/esm-browser/stringify.js` (safe): No malicious patterns detected
- `dist/esm-browser/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/uuid-bin.js` (safe): No malicious patterns detected; the file is a standard UUID CLI wrapper with no network, filesystem, or process execution beyond normal console output.
- `dist/esm-browser/v1.js` (safe): This is a legitimate UUID v1/v6 generation module with no malicious patterns detected.
- `dist/esm-browser/v1ToV6.js` (safe): No malicious patterns detected
- `dist/esm-browser/v3.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/v35.js` (safe): No malicious patterns detected
- `dist/esm-browser/v4.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/v5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/v6.js` (safe): No malicious patterns detected
- `dist/esm-browser/v6ToV1.js` (safe): No malicious patterns detected; the file contains only pure UUID conversion logic using local byte manipulation and no network, filesystem, process, or dynamic execution features.
- `dist/esm-browser/v7.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/validate.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/max.js` (safe): No malicious patterns detected
- `dist/esm/md5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/native.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/nil.js` (safe): No malicious patterns detected
- `dist/esm/parse.js` (safe): No malicious patterns detected; the code is a standard UUID parser with no network, filesystem, process, or dynamic code execution activity.
- `dist/esm/regex.js` (safe): No malicious patterns detected
- `dist/esm/rng.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/stringify.js` (safe): No malicious patterns detected
- `dist/esm/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/uuid-bin.js` (safe): No malicious patterns detected; the file is a standard UUID CLI wrapper with no network, filesystem, or process execution beyond normal console output.
- `dist/esm/v1.js` (safe): This is a legitimate UUID v1/v6 generation module with no malicious patterns detected.
- `dist/esm/v1ToV6.js` (safe): No malicious patterns detected
- `dist/esm/v3.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/v35.js` (safe): No malicious patterns detected
- `dist/esm/v4.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/v5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/v6.js` (safe): No malicious patterns detected
- `dist/esm/v6ToV1.js` (safe): No malicious patterns detected; the file contains only pure UUID conversion logic using local byte manipulation and no network, filesystem, process, or dynamic execution features.
- `dist/esm/v7.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/validate.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/version.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of uuid are flagged high or critical. The latest scanned version, 14.0.2, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 13.0.2 – 14.0.2 (`>=13.0.2 <=14.0.2`): not scanned
- 11.1.1 (`11.1.1`): clean
- 11.0.3 – 11.1.0 (`>=11.0.3 <=11.1.0`): not scanned
- 8.3.2 – 9.0.1 (`>=8.3.2 <=9.0.1`): clean
- 3.2.1 – 7.0.3 (`>=3.2.1 <=7.0.3`): not scanned

## Scanned versions

- [11.1.1](https://security.togoder.click/npm/uuid@11.1.1): safe, 2026-10-06T14:24:56.000Z
- [9.0.1](https://security.togoder.click/npm/uuid@9.0.1): safe, 2026-10-04T16:42:17.000Z
- [8.3.2](https://security.togoder.click/npm/uuid@8.3.2): safe, 2026-10-04T16:08:42.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
