# uuid@9.0.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:42:17.000Z
- Files reviewed: 70
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/uuid@9.0.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package uuid@9.0.1 on Oct 4, 2026. An AI review of 70 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Secure random number generation

Finding ID: `NPS-42A2A1FB7B84`

File: `dist/commonjs-browser/rng.js:15`

Uses crypto.getRandomValues() for cryptographic randomness with proper error handling when unavailable. No malicious patterns such as exfiltration, obfuscation, or dynamic execution are present.

### [low] Secure random number generation

Finding ID: `NPS-42A2A1FB7B84`

File: `dist/rng-browser.js:15`

Uses crypto.getRandomValues() for cryptographic randomness with proper error handling when unavailable. No malicious patterns such as exfiltration, obfuscation, or dynamic execution are present.

## Files reviewed

- `dist/commonjs-browser/index.js` (safe): No malicious patterns detected; this is a standard CommonJS browser bundle entry point re-exporting uuid functions.
- `dist/commonjs-browser/md5.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/native.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/nil.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/parse.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/regex.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/rng.js` (safe): This file implements a secure browser RNG helper using crypto.getRandomValues and contains no malicious patterns.
- `dist/commonjs-browser/sha1.js` (safe): No malicious patterns detected; the file is a standard, self-contained SHA1 hash implementation with no network, filesystem, process, or dynamic code execution behavior.
- `dist/commonjs-browser/stringify.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/v1.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/v3.js` (safe): This file is a standard UUID v3 implementation that imports local modules and exports a function without any suspicious behavior.
- `dist/commonjs-browser/v35.js` (safe): This is a legitimate UUID v3/v5 generation module implementing RFC 4122 namespace-based UUIDs with no malicious patterns detected.
- `dist/commonjs-browser/v4.js` (safe): No malicious patterns detected; this is a standard UUID v4 generation module that uses secure random sources and performs no network, filesystem, or process operations.
- `dist/commonjs-browser/v5.js` (safe): No malicious patterns detected; this is a standard UUID v5 module entry point.
- `dist/commonjs-browser/validate.js` (safe): No malicious patterns detected
- `dist/commonjs-browser/version.js` (safe): No malicious patterns detected; the code is a simple UUID version extraction utility with input validation.
- `dist/esm-browser/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/md5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/native.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/nil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/parse.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/regex.js` (safe): No malicious patterns detected
- `dist/esm-browser/rng.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/stringify.js` (safe): No malicious patterns detected; the code is a standard UUID stringify implementation from the uuid package with only benign validation and formatting logic.
- `dist/esm-browser/v1.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/v3.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/v35.js` (safe): No malicious patterns detected; the file implements standard UUID v3/v5 generation using hashing and contains no exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `dist/esm-browser/v4.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/v5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/validate.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-browser/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/md5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/native.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/nil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/parse.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/regex.js` (safe): No malicious patterns detected
- `dist/esm-node/rng.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/stringify.js` (safe): No malicious patterns detected; the code is a standard UUID stringify implementation from the uuid package with only benign validation and formatting logic.
- `dist/esm-node/v1.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/v3.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/v35.js` (safe): No malicious patterns detected; the file implements standard UUID v3/v5 generation using hashing and contains no exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `dist/esm-node/v4.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/v5.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/validate.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm-node/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/index.js` (safe): This is a standard ES module re-export barrel file for the uuid package; no malicious patterns detected.
- `dist/md5-browser.js` (safe): No malicious patterns detected
- `dist/md5.js` (safe): No malicious patterns detected
- `dist/native-browser.js` (safe): No malicious patterns detected
- `dist/native.js` (safe): No malicious patterns detected
- `dist/nil.js` (safe): No malicious patterns detected
- `dist/parse.js` (safe): No malicious patterns detected
- `dist/regex.js` (safe): No malicious patterns detected
- `dist/rng-browser.js` (safe): This file implements a secure browser RNG helper using crypto.getRandomValues and contains no malicious patterns.
- `dist/rng.js` (safe): No malicious patterns detected; the code is a standard cryptographically secure random number generator using crypto.randomFillSync.
- `dist/sha1-browser.js` (safe): No malicious patterns detected; the file is a standard, self-contained SHA1 hash implementation with no network, filesystem, process, or dynamic code execution behavior.
- `dist/sha1.js` (safe): No malicious patterns detected
- `dist/stringify.js` (safe): No malicious patterns detected
- `dist/uuid-bin.js` (safe): No malicious patterns detected
- `dist/v1.js` (safe): No malicious patterns detected
- `dist/v3.js` (safe): This file is a standard UUID v3 implementation that imports local modules and exports a function without any suspicious behavior.
- `dist/v35.js` (safe): This is a legitimate UUID v3/v5 generation module implementing RFC 4122 namespace-based UUIDs with no malicious patterns detected.
- `dist/v4.js` (safe): No malicious patterns detected; this is a standard UUID v4 generation module that uses secure random sources and performs no network, filesystem, or process operations.
- `dist/v5.js` (safe): No malicious patterns detected; this is a standard UUID v5 module entry point.
- `dist/validate.js` (safe): No malicious patterns detected
- `dist/version.js` (safe): No malicious patterns detected; the code is a simple UUID version extraction utility with input validation.
- `wrapper.mjs` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of uuid are flagged high or critical. The latest scanned version, 14.0.2, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 13.0.2 – 14.0.2 (`>=13.0.2 <=14.0.2`): not scanned
- 11.1.1 (`11.1.1`): clean
- 11.0.3 – 11.1.0 (`>=11.0.3 <=11.1.0`): not scanned
- 8.3.2 – 9.0.1 (`>=8.3.2 <=9.0.1`): clean
- 3.2.1 – 7.0.3 (`>=3.2.1 <=7.0.3`): not scanned

## Scanned versions

- [11.1.1](https://security.togoder.click/npm/uuid@11.1.1): safe, 2026-10-06T14:24:56.000Z
- [9.0.1](https://security.togoder.click/npm/uuid@9.0.1): safe, 2026-10-04T16:42:17.000Z
- [8.3.2](https://security.togoder.click/npm/uuid@8.3.2): safe, 2026-10-04T16:08:42.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
