# ws@7.5.10 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:20:09.000Z
- Files reviewed: 14
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/ws@7.5.10
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package ws@7.5.10 on Oct 4, 2026. An AI review of 14 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] dynamic require of optional dependency

Finding ID: `NPS-CA84C3BEF4C1`

File: `lib/validation.js:81`

The module conditionally requires 'utf-8-validate' at import time using a try/catch. This is a legitimate optional native binding for fast UTF-8 validation and falls back to a pure-JS implementation if unavailable. The require target is a hardcoded, well-known package name and is not influenced by external input.

## Files reviewed

- `browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/buffer-util.js` (safe): The file contains standard buffer manipulation utilities with no malicious patterns detected.
- `lib/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/event-target.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/extension.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/limiter.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/permessage-deflate.js` (safe): No malicious patterns detected; the code is a legitimate permessage-deflate implementation using zlib with concurrency limiting and payload size checks.
- `lib/receiver.js` (safe): No malicious patterns detected; this is a legitimate WebSocket frame receiver implementation with proper validation and no suspicious behavior.
- `lib/sender.js` (safe): The code implements a legitimate WebSocket message sender (HyBi framing) with standard masking, compression, and queueing behavior; no malicious patterns or unauthorized network, file, or process activity detected.
- `lib/stream.js` (safe): No malicious patterns detected; the code is a legitimate WebSocket-to-Duplex stream adapter with no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/validation.js` (safe): The code is a standard WebSocket validation utility with a benign optional native dependency; no malicious patterns were identified.
- `lib/websocket-server.js` (safe): No malicious patterns detected
- `lib/websocket.js` (safe): No malicious patterns detected; the code is a legitimate WebSocket client implementation from the 'ws' library.

## Version ranges

None of the 5 scanned versions of ws are flagged high or critical. The latest scanned version, 8.21.3, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.21.0 – 8.21.3 (`>=8.21.0 <=8.21.3`): not scanned
- 7.5.13 – 8.18.3 (`>=7.5.13 <=8.18.3`): clean
- 7.5.11 (`7.5.11`): not scanned
- 7.5.10 (`7.5.10`): clean
- 6.2.4 (`6.2.4`): not scanned

## Scanned versions

- [8.18.3](https://security.togoder.click/npm/ws@8.18.3): safe, 2026-10-04T16:46:03.000Z
- [8.18.0](https://security.togoder.click/npm/ws@8.18.0): safe, 2026-10-04T16:14:48.000Z
- [8.17.1](https://security.togoder.click/npm/ws@8.17.1): safe, 2026-10-04T16:28:25.000Z
- [7.5.13](https://security.togoder.click/npm/ws@7.5.13): safe, 2026-10-04T21:17:55.000Z
- [7.5.10](https://security.togoder.click/npm/ws@7.5.10): safe, 2026-10-04T16:20:09.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
