Togoder security

Go package security report

github.com/davecgh/go-spew Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v1.1.2-0.20180830191138-d8f796af33cc Files reviewed 9 Size 70.8 KB Scanned

Summary

Togoder Security scanned the Go package github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc on Oct 5, 2026. An AI review of 9 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

Unsafe package usage / Reflect internals manipulation

NPS-8F751DACF39B

The code uses the unsafe package to directly manipulate unexported fields of reflect.Value (specifically the internal 'flag' field) to bypass Go's type safety and read unexported struct fields. While this is a legitimate technique used by the spew library for pretty-printing, it circumvents Go's memory safety guarantees and relies on internal implementation details that could change between Go versions.

spew/bypass.go:92
low

Build constraint to enable unsafe code

NPS-E690DB8025FC

The build constraints (!js,!appengine,!safe,!disableunsafe,go1.4) are designed to ensure this unsafe reflection-bypassing code is compiled in by default. The 'safe' tag is an opt-out mechanism, meaning most builds will include the unsafe code automatically without explicit developer consent, which is a questionable default for a library that bypasses type safety.

spew/bypass.go:15
low

Init-time reflection and panic behavior

NPS-FECA4AE463C6

The init() function performs runtime introspection of the reflect package's internal layout at import time. It will panic if the reflect.Value flag semantics don't match expected values. This runs automatically on package import and could cause denial of service in applications using this package if Go's reflect internals change, though this is defensive rather than malicious.

spew/bypass.go:106

Files reviewed

FileVerdictWhat the reviewer saw
spew/bypass.go medium This is a legitimate library file (part of spew) that intentionally uses unsafe reflection internals to access unexported fields for pretty-printing, but it bypasses Go's type safety guarantees and should be reviewed for supply-chain risk if the maintainer or version provenance is untrusted.
spew/bypasssafe.go safe Cleared by Jev triage; no further analysis needed
spew/common.go safe No malicious patterns detected
spew/config.go safe Cleared by Jev triage; no further analysis needed
spew/doc.go safe Cleared by Jev triage; no further analysis needed
spew/dump.go safe No malicious patterns detected; the code is a legitimate reflection-based pretty-printer with no network, filesystem, process, or dynamic-execution capabilities.
spew/format.go safe Cleared by Jev triage; no further analysis needed
spew/spew.go safe Cleared by Jev triage; no further analysis needed
spew/testdata/dumpcgo.go safe No malicious patterns detected in this cgo test file that only contains static C char pointer definitions and test-only accessor functions.

Scanned versions of github.com/davecgh/go-spew

VersionVerdictFilesScanned
v1.1.2-0.20180830191138-d8f796af33cc Needs review 9 Oct 5, 2026

Frequently asked questions

Is github.com/davecgh/go-spew safe to use?

No confirmed malware was found in github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/davecgh/go-spew contain malware?

No malware was identified in github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/davecgh/go-spew checked?

Togoder Security downloaded the published Go package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/davecgh/go-spew together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc, cost nothing.

Related security reports