# @babel/helpers@7.29.7 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:10:50.000Z
- Files reviewed: 123
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@babel/helpers
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @babel/helpers@7.29.7 on Oct 6, 2026. An AI review of 123 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] dynamic code execution

Finding ID: `NPS-A0F4B763DEBC`

File: `lib/helpers/isNativeFunction.js:9`

Uses Function.toString.call(fn) to inspect a function's source. This is not code execution (no eval/new Function), but it does read the function's string representation, which is a common safe utility pattern used by Babel helpers.

## Files reviewed

- `lib/helpers/AwaitValue.js` (safe): No malicious patterns detected
- `lib/helpers/OverloadYield.js` (safe): No malicious patterns detected; the file is a trivial Babel helper constructor with no I/O, network, or dynamic execution.
- `lib/helpers/applyDecoratedDescriptor.js` (safe): No malicious patterns detected; this is a standard Babel helper for applying decorated descriptors.
- `lib/helpers/applyDecs.js` (safe): No malicious patterns detected; this is a legitimate Babel helper implementation for decorators.
- `lib/helpers/applyDecs2203.js` (safe): This is a legitimate Babel helper for applying decorators (applyDecs2203) with no malicious patterns, network activity, process execution, or credential access.
- `lib/helpers/applyDecs2203R.js` (safe): No malicious patterns detected; the file is a standard Babel decorators helper implementation with no network, filesystem, process, or dynamic execution behavior.
- `lib/helpers/applyDecs2301.js` (safe): This is a legitimate Babel decorators transform helper (applyDecs2301) with no malicious patterns; it only implements decorator application logic using standard library calls and no network, filesystem, process, or eval operations.
- `lib/helpers/applyDecs2305.js` (safe): This is a legitimate Babel runtime helper implementing JavaScript decorators, with no malicious patterns or security concerns.
- `lib/helpers/applyDecs2311.js` (safe): No malicious patterns detected; file is a standard Babel decorator helper with no network, filesystem, process, or dynamic-execution activity.
- `lib/helpers/arrayLikeToArray.js` (safe): No malicious patterns detected; the code is a standard array-like to array conversion helper with no network, filesystem, process, or dynamic execution behavior.
- `lib/helpers/arrayWithHoles.js` (safe): No malicious patterns detected; the file is a simple Babel helper that checks if a value is an array.
- `lib/helpers/arrayWithoutHoles.js` (safe): No malicious patterns detected; the file is a simple Babel helper function that safely converts array-like objects to arrays.
- `lib/helpers/assertClassBrand.js` (safe): No malicious patterns detected
- `lib/helpers/assertThisInitialized.js` (safe): No malicious patterns detected
- `lib/helpers/asyncGeneratorDelegate.js` (safe): No malicious patterns detected; this is a standard Babel helper for async generator delegation with no network, filesystem, process, or dynamic execution activity.
- `lib/helpers/asyncIterator.js` (safe): No malicious patterns detected; the code is a standard Babel helper for async iterator normalization.
- `lib/helpers/asyncToGenerator.js` (safe): This is a standard Babel-generated asyncToGenerator helper with no malicious patterns, network access, file system operations, or dynamic code execution.
- `lib/helpers/awaitAsyncGenerator.js` (safe): No malicious patterns detected
- `lib/helpers/callSuper.js` (safe): This is benign Babel helper code for calling super constructors; no malicious patterns detected.
- `lib/helpers/checkInRHS.js` (safe): No malicious patterns detected
- `lib/helpers/checkPrivateRedeclaration.js` (safe): No malicious patterns detected
- `lib/helpers/classApplyDescriptorDestructureSet.js` (safe): No malicious patterns detected; this is a benign Babel helper for applying private field descriptors in destructuring assignment.
- `lib/helpers/classApplyDescriptorGet.js` (safe): No malicious patterns detected
- `lib/helpers/classApplyDescriptorSet.js` (safe): This is a standard Babel helper function for applying property descriptors; no malicious patterns detected.
- `lib/helpers/classCallCheck.js` (safe): No malicious patterns detected
- `lib/helpers/classCheckPrivateStaticAccess.js` (safe): No malicious patterns detected
- `lib/helpers/classCheckPrivateStaticFieldDescriptor.js` (safe): No malicious patterns detected
- `lib/helpers/classExtractFieldDescriptor.js` (safe): No malicious patterns detected
- `lib/helpers/classNameTDZError.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateFieldDestructureSet.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateFieldGet.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateFieldGet2.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateFieldInitSpec.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateFieldLooseBase.js` (safe): No malicious patterns detected; the file is a standard Babel helper for private field access with no network, file system, process, or dynamic execution activity.
- `lib/helpers/classPrivateFieldLooseKey.js` (safe): No malicious patterns detected; the file is a simple Babel helper that generates unique private field keys with no network, filesystem, or dynamic code execution behavior.
- `lib/helpers/classPrivateFieldSet.js` (safe): No malicious patterns detected; this is a standard Babel helper for setting private class fields.
- `lib/helpers/classPrivateFieldSet2.js` (safe): No malicious patterns detected; the file is a standard Babel helper for setting private class fields with no network, filesystem, process, or dynamic execution behavior.
- `lib/helpers/classPrivateGetter.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateMethodGet.js` (safe): No malicious patterns detected
- `lib/helpers/classPrivateMethodInitSpec.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for private method initialization with no network, filesystem, process, or dynamic code execution behavior.
- `lib/helpers/classPrivateMethodSet.js` (safe): No malicious patterns detected; the file is a harmless Babel helper that throws a TypeError when attempting to reassign a private method.
- `lib/helpers/classPrivateSetter.js` (safe): No malicious patterns detected
- `lib/helpers/classStaticPrivateFieldDestructureSet.js` (safe): No malicious patterns detected; the code is a standard Babel helper for private static field destructuring with no network, filesystem, or process activity.
- `lib/helpers/classStaticPrivateFieldSpecGet.js` (safe): No malicious patterns detected
- `lib/helpers/classStaticPrivateFieldSpecSet.js` (safe): This is a standard Babel runtime helper for setting private static fields; no malicious patterns detected.
- `lib/helpers/classStaticPrivateMethodGet.js` (safe): No malicious patterns detected; the file only contains a Babel-generated helper function for accessing static private methods with a simple brand assertion.
- `lib/helpers/classStaticPrivateMethodSet.js` (safe): No malicious patterns detected
- `lib/helpers/construct.js` (safe): This is a standard Babel helper for the _construct function, with no malicious patterns, network activity, obfuscation, or install-time behavior detected.
- `lib/helpers/createClass.js` (safe): This is a standard Babel helper for creating ES6 classes with proto and static properties; no malicious patterns detected.
- `lib/helpers/createForOfIteratorHelper.js` (safe): No malicious patterns detected; the code is a standard Babel helper for iterating over iterables and arrays.
- `lib/helpers/createForOfIteratorHelperLoose.js` (safe): No malicious patterns detected; the file is a standard Babel runtime helper for loosely iterating over iterables.
- `lib/helpers/createSuper.js` (safe): No malicious patterns detected
- `lib/helpers/decorate.js` (safe): No malicious patterns detected; the file is a standard Babel/TypeScript decorator helper implementation with no network, filesystem, process, or dynamic code execution concerns.
- `lib/helpers/defaults.js` (safe): No malicious patterns detected
- `lib/helpers/defineAccessor.js` (safe): No malicious patterns detected
- `lib/helpers/defineEnumerableProperties.js` (safe): This is a standard Babel helper that defines enumerable properties on objects; no malicious patterns, network activity, credential harvesting, or dynamic code execution are present.
- `lib/helpers/defineProperty.js` (safe): No malicious patterns detected; the file is a standard Babel helper for defining object properties.
- `lib/helpers/dispose.js` (safe): No malicious patterns detected
- `lib/helpers/extends.js` (safe): This is a standard Babel transpiled Object.assign polyfill/helper with no malicious patterns, network activity, credential access, or dynamic code execution.
- `lib/helpers/get.js` (safe): No malicious patterns detected; this is a standard Babel-transpiled helper for Reflect.get with a fallback implementation.
- `lib/helpers/getPrototypeOf.js` (safe): No malicious patterns detected
- `lib/helpers/identity.js` (safe): No malicious patterns detected
- `lib/helpers/importDeferProxy.js` (safe): No malicious patterns detected; the code is a standard import defer proxy implementation with no network, filesystem, process, or credential access.
- `lib/helpers/inherits.js` (safe): No malicious patterns detected; this is a standard Babel helper implementing prototype inheritance.
- `lib/helpers/inheritsLoose.js` (safe): No malicious patterns detected
- `lib/helpers/initializerDefineProperty.js` (safe): No malicious patterns detected
- `lib/helpers/initializerWarningHelper.js` (safe): No malicious patterns detected; the file only throws a descriptive error for missing decorator transform configuration.
- `lib/helpers/instanceof.js` (safe): No malicious patterns detected
- `lib/helpers/interopRequireDefault.js` (safe): No malicious patterns detected
- `lib/helpers/interopRequireWildcard.js` (safe): This is a standard Babel interop helper that safely wraps module objects using WeakMap caching and performs no malicious operations.
- `lib/helpers/isNativeFunction.js` (safe): The helper only inspects a function's string representation to detect native functions and contains no malicious patterns, network activity, credential access, or code execution.
- `lib/helpers/isNativeReflectConstruct.js` (safe): This is a benign Babel transpilation helper that detects native Reflect.construct support; no malicious patterns were found.
- `lib/helpers/iterableToArray.js` (safe): No malicious patterns detected in the iterableToArray helper function, which only performs a safe iterable-to-array conversion.
- `lib/helpers/iterableToArrayLimit.js` (safe): No malicious patterns detected
- `lib/helpers/jsx.js` (safe): This is a standard Babel-compiled React JSX element creation helper with no network, filesystem, process, or dynamic code execution activity.
- `lib/helpers/maybeArrayLike.js` (safe): This is a standard Babel helper that safely converts array-like values to arrays with no malicious patterns.
- `lib/helpers/newArrowCheck.js` (safe): No malicious patterns detected
- `lib/helpers/nonIterableRest.js` (safe): No malicious patterns detected; the file only provides a Babel helper that throws a TypeError for non-iterable destructuring.
- `lib/helpers/nonIterableSpread.js` (safe): No malicious patterns detected
- `lib/helpers/nullishReceiverError.js` (safe): No malicious patterns detected
- `lib/helpers/objectDestructuringEmpty.js` (safe): No malicious patterns detected
- `lib/helpers/objectSpread.js` (safe): No malicious patterns detected; this is a standard Babel-generated helper for object spread that only uses local module imports and object property operations.
- `lib/helpers/objectSpread2.js` (safe): This is a standard Babel helper implementing Object spread semantics with no network, filesystem, process, or dynamic code execution patterns.
- `lib/helpers/objectWithoutProperties.js` (safe): This is a standard Babel helper function for omitting properties from objects with no malicious patterns detected
- `lib/helpers/objectWithoutPropertiesLoose.js` (safe): No malicious patterns detected
- `lib/helpers/possibleConstructorReturn.js` (safe): This is a standard Babel runtime helper for enforcing derived constructor return semantics with no malicious patterns detected.
- `lib/helpers/readOnlyError.js` (safe): No malicious patterns detected
- `lib/helpers/regenerator.js` (safe): This is a standard Babel regenerator runtime helper with no malicious patterns, network activity, or credential access.
- `lib/helpers/regeneratorAsync.js` (safe): No malicious patterns detected; the file is a standard Babel helper for async generator execution.
- `lib/helpers/regeneratorAsyncGen.js` (safe): No malicious patterns detected; this is a standard Babel/regenerator runtime helper for async generators with no network, filesystem, process, or dynamic execution behavior.
- `lib/helpers/regeneratorAsyncIterator.js` (safe): No malicious patterns detected; the code implements a standard async iterator helper for regenerator runtime without any suspicious behavior.
- `lib/helpers/regeneratorDefine.js` (safe): No malicious patterns detected; this is a benign Babel regenerator helper defining iterator methods and polyfilling Object.defineProperty behavior.
- `lib/helpers/regeneratorKeys.js` (safe): No malicious patterns detected; the file is a standard regenerator runtime helper for iterating object keys with no network, filesystem, process, or dynamic code execution activity.
- `lib/helpers/regeneratorRuntime.js` (safe): No malicious patterns detected; this is a legitimate Babel helper implementing the regenerator runtime for async/generator functions with no network, filesystem, process, or obfuscation concerns.
- `lib/helpers/regeneratorValues.js` (safe): No malicious patterns detected; the file only implements a standard iterable-to-iterator helper without network, filesystem, process, or dynamic code execution.
- `lib/helpers/set.js` (safe): No malicious patterns detected; the code is a standard Babel helper for property assignment with prototype chain fallbacks.
- `lib/helpers/setFunctionName.js` (safe): No malicious patterns detected
- `lib/helpers/setPrototypeOf.js` (safe): No malicious patterns detected; the file is a standard Babel transpiled helper for setting an object's prototype.
- `lib/helpers/skipFirstGeneratorNext.js` (safe): No malicious patterns detected; the file contains a benign helper for skipping the first yield of a generator function.
- `lib/helpers/slicedToArray.js` (safe): No malicious patterns detected; this is a standard Babel helper for destructuring arrays into slices.
- `lib/helpers/superPropBase.js` (safe): No malicious patterns detected; this is a standard Babel helper for resolving superclass property access.
- `lib/helpers/superPropGet.js` (safe): This is a standard Babel helper for accessing super class properties; no malicious patterns detected.
- `lib/helpers/superPropSet.js` (safe): No malicious patterns detected
- `lib/helpers/taggedTemplateLiteral.js` (safe): No malicious patterns detected
- `lib/helpers/taggedTemplateLiteralLoose.js` (safe): No malicious patterns detected
- `lib/helpers/tdz.js` (safe): No malicious patterns detected
- `lib/helpers/temporalRef.js` (safe): No malicious patterns detected; this is a standard Babel helper for temporal dead zone reference checking.
- `lib/helpers/temporalUndefined.js` (safe): No malicious patterns detected
- `lib/helpers/toArray.js` (safe): This is a standard Babel transpiled helper function for converting values to arrays, with no malicious patterns detected.
- `lib/helpers/toConsumableArray.js` (safe): No malicious patterns detected
- `lib/helpers/toPrimitive.js` (safe): No malicious patterns detected; the code is a standard Babel helper implementing the ECMAScript ToPrimitive abstract operation.
- `lib/helpers/toPropertyKey.js` (safe): No malicious patterns detected; the code is a straightforward Babel-compiled utility for converting values to property keys.
- `lib/helpers/toSetter.js` (safe): No malicious patterns detected; the file contains a small utility function that creates an object with a setter invoking a provided callback.
- `lib/helpers/tsRewriteRelativeImportExtensions.js` (safe): No malicious patterns detected
- `lib/helpers/typeof.js` (safe): No malicious patterns detected; this is a standard Babel-generated _typeof helper function with no external I/O, dynamic code execution, or suspicious behavior.
- `lib/helpers/unsupportedIterableToArray.js` (safe): The file is a standard Babel helper for converting iterable-like objects to arrays, with no malicious patterns detected.
- `lib/helpers/using.js` (safe): No malicious patterns detected; the code is a standard Babel helper implementing the `using` declaration disposal logic without any network, filesystem, process, or dynamic execution behavior.
- `lib/helpers/usingCtx.js` (safe): This is a standard Babel-transpiled helper implementing the TC39 'using' / 'await using' (explicit resource management) proposal; it contains no malicious patterns such as network access, credential harvesting, obfuscation, or process spawning.
- `lib/helpers/wrapAsyncGenerator.js` (safe): This is a standard Babel runtime helper for wrapping async generators with no network, filesystem, process, or obfuscated code patterns.
- `lib/helpers/wrapNativeSuper.js` (safe): No malicious patterns detected; the code is a standard Babel helper for wrapping native super classes without any network, filesystem, shell, or dynamic execution activity.
- `lib/helpers/wrapRegExp.js` (safe): No malicious patterns detected; the code is a legitimate Babel helper for wrapping RegExp with named capture group support.
- `lib/helpers/writeOnlyError.js` (safe): No malicious patterns detected
- `lib/index.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
