# ws@8.17.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:28:25.000Z
- Files reviewed: 16
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/ws@8.17.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package ws@8.17.1 on Oct 4, 2026. An AI review of 16 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Environment variable read

Finding ID: `NPS-177B453C4A86`

File: `lib/validation.js:126`

Reads process.env.WS_NO_UTF_8_VALIDATE to allow users to opt out of using the optional native utf-8-validate module. This is a benign configuration toggle and does not harvest or exfiltrate credentials.

### [low] Dynamic module loading (optional dependency)

Finding ID: `NPS-0C5438080EBE`

File: `lib/validation.js:130`

The code attempts to require('utf-8-validate') inside a try/catch as an optional performance optimization for UTF-8 validation. This is a common pattern in the widely-used 'ws' WebSocket library and falls back to a built-in implementation if the module is unavailable. The module name is hardcoded, not computed from external input, and is only loaded when process.env.WS_NO_UTF_8_VALIDATE is not set.

## Files reviewed

- `browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/buffer-util.js` (safe): This is a standard buffer utility module from the ws WebSocket library with no malicious patterns detected.
- `lib/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/event-target.js` (safe): No malicious patterns detected; the file implements standard Event, CloseEvent, ErrorEvent, MessageEvent, and EventTarget classes with no external network, file system, process, or dynamic code execution activity.
- `lib/extension.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/limiter.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/permessage-deflate.js` (safe): This is a legitimate permessage-deflate implementation for the 'ws' WebSocket library, containing only standard zlib compression/decompression logic with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/process activity.
- `lib/receiver.js` (safe): No malicious patterns detected; this is a standard WebSocket frame receiver implementation from the ws library.
- `lib/sender.js` (safe): No malicious patterns detected; the code is a standard WebSocket frame sender implementation from the ws library.
- `lib/stream.js` (safe): No malicious patterns detected
- `lib/subprotocol.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/validation.js` (safe): This is a standard UTF-8 and status code validation module (appearing to be lib/validation.js from the ws WebSocket library) with no malicious behavior; the only noteworthy patterns are a benign env-var toggle and an optional native module load with a safe fallback.
- `lib/websocket-server.js` (safe): No malicious patterns detected
- `lib/websocket.js` (safe): No malicious patterns detected; this is the standard 'ws' WebSocket client library implementation with only legitimate networking, crypto, and stream handling code.
- `wrapper.mjs` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 5 scanned versions of ws are flagged high or critical. The latest scanned version, 8.21.3, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.21.0 – 8.21.3 (`>=8.21.0 <=8.21.3`): not scanned
- 7.5.13 – 8.18.3 (`>=7.5.13 <=8.18.3`): clean
- 7.5.11 (`7.5.11`): not scanned
- 7.5.10 (`7.5.10`): clean
- 6.2.4 (`6.2.4`): not scanned

## Scanned versions

- [8.18.3](https://security.togoder.click/npm/ws@8.18.3): safe, 2026-10-04T16:46:03.000Z
- [8.18.0](https://security.togoder.click/npm/ws@8.18.0): safe, 2026-10-04T16:14:48.000Z
- [8.17.1](https://security.togoder.click/npm/ws@8.17.1): safe, 2026-10-04T16:28:25.000Z
- [7.5.13](https://security.togoder.click/npm/ws@7.5.13): safe, 2026-10-04T21:17:55.000Z
- [7.5.10](https://security.togoder.click/npm/ws@7.5.10): safe, 2026-10-04T16:20:09.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
