Analyze your own packages withvet GitHub

next@15.4.7

Safe
Analyzed at:8/18/2025, 9:57:37 PM
Source:https://registry.npmjs.org/next/-/next-15.4.7.tgz
SHA256:2e5e3ccb7efa6fbbb40c7d775b955c28b415313b03a43122969d9a066a650535
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Potential XSS, ReDoS, and dynamic code execution exist, but no conclusive evidence of malicious intent. Classifying as not malware.

Details

The evidences suggest potential vulnerabilities like XSS, ReDoS, and dynamic code execution/import. However, these are potential vulnerabilities and require specific conditions to be exploited. There is no concrete evidence of malicious intent or active exploitation. Next.js is a widely used framework, and these findings are likely areas for improvement rather than deliberate malicious code. Therefore, I classify the package as not malware.