# ws@8.18.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:46:03.000Z
- Files reviewed: 16
- Findings: no findings
- Report: https://security.togoder.click/npm/ws@8.18.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package ws@8.18.3 on Oct 4, 2026. An AI review of 16 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/buffer-util.js` (safe): This is a standard buffer utility module from the ws WebSocket library with no malicious patterns detected.
- `lib/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/event-target.js` (safe): No malicious patterns detected; the file implements standard Event, CloseEvent, ErrorEvent, MessageEvent, and EventTarget classes with no external network, file system, process, or dynamic code execution activity.
- `lib/extension.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/limiter.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/permessage-deflate.js` (safe): The code is a legitimate implementation of the permessage-deflate WebSocket extension with only standard compression logic and no malicious patterns.
- `lib/receiver.js` (safe): No malicious patterns detected; this is a standard WebSocket frame receiver implementation from the ws library with no exfiltration, credential harvesting, obfuscation, or process execution code.
- `lib/sender.js` (safe): No malicious patterns detected; this is the legitimate ws library WebSocket sender implementation using standard Node.js crypto, stream, and buffer utilities.
- `lib/stream.js` (safe): No malicious patterns detected; the code is a legitimate WebSocket-to-Duplex stream wrapper.
- `lib/subprotocol.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/validation.js` (safe): No malicious patterns detected; the code performs legitimate WebSocket-related validation tasks without any exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `lib/websocket-server.js` (safe): No malicious patterns detected; this is the well-known ws WebSocket server implementation with only legitimate networking, stream, and crypto operations.
- `lib/websocket.js` (safe): No malicious patterns detected; the code is a legitimate WebSocket implementation from the 'ws' package with standard networking primitives, proper input validation, and no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `wrapper.mjs` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 5 scanned versions of ws are flagged high or critical. The latest scanned version, 8.21.3, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.21.0 – 8.21.3 (`>=8.21.0 <=8.21.3`): not scanned
- 7.5.13 – 8.18.3 (`>=7.5.13 <=8.18.3`): clean
- 7.5.11 (`7.5.11`): not scanned
- 7.5.10 (`7.5.10`): clean
- 6.2.4 (`6.2.4`): not scanned

## Scanned versions

- [8.18.3](https://security.togoder.click/npm/ws@8.18.3): safe, 2026-10-04T16:46:03.000Z
- [8.18.0](https://security.togoder.click/npm/ws@8.18.0): safe, 2026-10-04T16:14:48.000Z
- [8.17.1](https://security.togoder.click/npm/ws@8.17.1): safe, 2026-10-04T16:28:25.000Z
- [7.5.13](https://security.togoder.click/npm/ws@7.5.13): safe, 2026-10-04T21:17:55.000Z
- [7.5.10](https://security.togoder.click/npm/ws@7.5.10): safe, 2026-10-04T16:20:09.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
