# @babel/types@7.29.8 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:11:01.000Z
- Files reviewed: 86
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@babel/types
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @babel/types@7.29.8 on Oct 6, 2026. An AI review of 86 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] code-quality

Finding ID: `NPS-269649104AE4`

File: `lib/definitions/placeholders.js:20`

Minor bug: `hasOwnProperty.call(...)` uses the global `hasOwnProperty` instead of `Object.prototype.hasOwnProperty.call(...)`, which could throw if the global is shadowed or unavailable. This is a functional concern, not a security vulnerability.

## Files reviewed

- `lib/asserts/assertNode.js` (safe): No malicious patterns detected
- `lib/asserts/generated/index.js` (safe): This is a standard Babel AST type assertion module that only performs type validation and throws errors; no malicious patterns detected.
- `lib/ast-types/generated/index.js` (safe): No malicious patterns detected; the file only contains a strict mode directive and a source map reference.
- `lib/builders/flow/createFlowUnionType.js` (safe): No malicious patterns detected; the file is a straightforward Flow union type builder with static imports and no network, filesystem, process, or dynamic execution activity.
- `lib/builders/flow/createTypeAnnotationBasedOnTypeof.js` (safe): No malicious patterns detected
- `lib/builders/generated/index.js` (safe): No malicious patterns detected; the file only re-exports named exports from two local modules using standard ES module interop patterns.
- `lib/builders/generated/lowercase.js` (safe): This is a standard Babel AST node builder module containing only pure constructor functions and no malicious patterns.
- `lib/builders/generated/uppercase.js` (safe): No malicious patterns detected; the file only re-exports AST builder aliases from lowercase.js and a deprecation warning utility.
- `lib/builders/productions.js` (safe): No malicious patterns detected
- `lib/builders/react/buildChildren.js` (safe): No malicious patterns detected
- `lib/builders/typescript/createTSUnionType.js` (safe): No malicious patterns detected; the file is a pure AST builder utility with only static local imports and no network, filesystem, process, or dynamic execution behavior.
- `lib/builders/validateNode.js` (safe): No malicious patterns detected; the file contains a straightforward AST node validation function with no dangerous operations.
- `lib/clone/clone.js` (safe): No malicious patterns detected
- `lib/clone/cloneDeep.js` (safe): No malicious patterns detected
- `lib/clone/cloneDeepWithoutLoc.js` (safe): No malicious patterns detected
- `lib/clone/cloneNode.js` (safe): No malicious patterns detected; the code is a legitimate AST node cloning utility with no exfiltration, credential harvesting, dynamic execution, or suspicious behavior.
- `lib/clone/cloneWithoutLoc.js` (safe): No malicious patterns detected; the file only re-exports a wrapper around cloneNode with no network, filesystem, process, or dynamic execution activity.
- `lib/comments/addComment.js` (safe): No malicious patterns detected
- `lib/comments/addComments.js` (safe): No malicious patterns detected
- `lib/comments/inheritInnerComments.js` (safe): No malicious patterns detected
- `lib/comments/inheritLeadingComments.js` (safe): The file is a simple Babel-transpiled utility function that delegates to an internal inherit helper with no suspicious, obfuscated, or dangerous behavior.
- `lib/comments/inheritTrailingComments.js` (safe): No malicious patterns detected
- `lib/comments/inheritsComments.js` (safe): No malicious patterns detected
- `lib/comments/removeComments.js` (safe): No malicious patterns detected
- `lib/constants/generated/index.js` (safe): No malicious patterns detected
- `lib/constants/index.js` (safe): No malicious patterns detected; the file only exports constant arrays and objects of JavaScript operator and AST key names.
- `lib/converters/ensureBlock.js` (safe): No malicious patterns detected; the file is a small utility that normalizes AST node bodies via a local toBlock converter.
- `lib/converters/gatherSequenceExpressions.js` (safe): No malicious patterns detected; this is a standard Babel AST utility function for gathering sequence expressions.
- `lib/converters/toBindingIdentifierName.js` (safe): No malicious patterns detected
- `lib/converters/toBlock.js` (safe): No malicious patterns detected
- `lib/converters/toComputedKey.js` (safe): This is a benign Babel AST utility function with no malicious patterns detected.
- `lib/converters/toExpression.js` (safe): No malicious patterns detected
- `lib/converters/toIdentifier.js` (safe): No malicious patterns detected; the code is a straightforward utility for converting strings into valid JavaScript identifiers.
- `lib/converters/toKeyAlias.js` (safe): No malicious patterns detected
- `lib/converters/toSequenceExpression.js` (safe): No malicious patterns detected
- `lib/converters/toStatement.js` (safe): The code is a standard AST utility function from Babel with no malicious patterns detected.
- `lib/converters/valueToNode.js` (safe): No malicious patterns detected
- `lib/definitions/core.js` (safe): This file defines AST node type schemas for @babel/types; no malicious patterns, network activity, credential access, or dynamic code execution were detected.
- `lib/definitions/deprecated-aliases.js` (safe): No malicious patterns detected
- `lib/definitions/experimental.js` (safe): This is a standard Babel AST definition file that only registers node type definitions and contains no malicious patterns such as network calls, code execution, credential harvesting, or file system manipulation.
- `lib/definitions/flow.js` (safe): No malicious patterns detected
- `lib/definitions/index.js` (safe): No malicious patterns detected
- `lib/definitions/jsx.js` (safe): No malicious patterns detected
- `lib/definitions/misc.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/definitions/placeholders.js` (safe): The file only defines AST placeholder constant arrays and alias mappings; no exfiltration, credential harvesting, dynamic execution, network calls, process spawning, or other malicious patterns were detected.
- `lib/definitions/typescript.js` (safe): No malicious patterns detected; this is a standard AST node type definition file for TypeScript syntax in a parser library.
- `lib/definitions/utils.js` (safe): No malicious patterns detected; this is a standard Babel type-definition utility with validation logic and no network, filesystem, or process execution activity.
- `lib/index.js` (safe): No malicious patterns detected; the file is a standard Babel helper module re-exporting internal utilities via static require and Object.defineProperty.
- `lib/modifications/appendToMemberExpression.js` (safe): No malicious patterns detected; the code is a straightforward Babel AST utility for appending to member expressions.
- `lib/modifications/flow/removeTypeDuplicates.js` (safe): No malicious patterns detected; the code is a legitimate Babel helper for removing duplicate Flow type annotations.
- `lib/modifications/inherits.js` (safe): No malicious patterns detected; the code is a simple utility function that copies inherited properties and comments between objects.
- `lib/modifications/prependToMemberExpression.js` (safe): No malicious patterns detected; the file is a straightforward AST utility from Babel that modifies member expressions without any network, filesystem, or dynamic execution behavior.
- `lib/modifications/removeProperties.js` (safe): No malicious patterns detected
- `lib/modifications/removePropertiesDeep.js` (safe): No malicious patterns detected
- `lib/modifications/typescript/removeTypeDuplicates.js` (safe): No malicious patterns detected
- `lib/retrievers/getAssignmentIdentifiers.js` (safe): No malicious patterns detected; the code is a pure AST utility function with no network, filesystem, process, or dynamic execution behavior.
- `lib/retrievers/getBindingIdentifiers.js` (safe): No malicious patterns detected; the code is a standard AST utility for extracting binding identifiers.
- `lib/retrievers/getFunctionName.js` (safe): No malicious patterns detected; the code is a standard utility for extracting function names from AST nodes.
- `lib/retrievers/getOuterBindingIdentifiers.js` (safe): No malicious patterns detected
- `lib/traverse/traverse.js` (safe): No malicious patterns detected; this is a standard AST traversal utility with no network, filesystem, process, or dynamic execution behavior.
- `lib/traverse/traverseFast.js` (safe): No malicious patterns detected
- `lib/utils/deprecationWarning.js` (safe): No malicious patterns detected; this is a standard Babel deprecation warning utility that only manipulates the Error stack trace and logs to console.
- `lib/utils/inherit.js` (safe): No malicious patterns detected
- `lib/utils/react/cleanJSXElementLiteralChild.js` (safe): No malicious patterns detected; the code is a standard JSX text normalization utility with no exfiltration, dynamic execution, or process spawning.
- `lib/utils/shallowEqual.js` (safe): No malicious patterns detected
- `lib/validators/buildMatchMemberExpression.js` (safe): No malicious patterns detected; the file is a simple AST utility that builds a member expression matcher and contains no network, filesystem, process, or dynamic execution behavior.
- `lib/validators/generated/index.js` (safe): This is a standard Babel type validator utility file with no malicious patterns, network activity, credential access, or dynamic code execution.
- `lib/validators/is.js` (safe): No malicious patterns detected
- `lib/validators/isBinding.js` (safe): No malicious patterns detected; the code is a straightforward AST utility for checking binding identifiers without any network, filesystem, or dynamic execution behavior.
- `lib/validators/isBlockScoped.js` (safe): No malicious patterns detected; the file is a simple utility that checks whether an AST node is block-scoped by delegating to other modules.
- `lib/validators/isImmutable.js` (safe): No malicious patterns detected
- `lib/validators/isLet.js` (safe): The file contains a simple AST validator function for checking 'let' declarations with no malicious patterns, network activity, credential access, or dynamic execution.
- `lib/validators/isNode.js` (safe): No malicious patterns detected
- `lib/validators/isNodesEquivalent.js` (safe): The file contains a pure recursive AST node comparison utility with no network, filesystem, process, or dynamic code execution patterns.
- `lib/validators/isPlaceholderType.js` (safe): No malicious patterns detected
- `lib/validators/isReferenced.js` (safe): This is a legitimate AST utility function for checking node references, with no malicious patterns or security concerns.
- `lib/validators/isScope.js` (safe): No malicious patterns detected
- `lib/validators/isSpecifierDefault.js` (safe): No malicious patterns detected
- `lib/validators/isType.js` (safe): No malicious patterns detected
- `lib/validators/isValidES3Identifier.js` (safe): No malicious patterns detected
- `lib/validators/isValidIdentifier.js` (safe): No malicious patterns detected
- `lib/validators/isVar.js` (safe): No malicious patterns detected
- `lib/validators/matchesPattern.js` (safe): No malicious patterns detected; the file contains a pure AST pattern-matching utility with no network, filesystem, process, or dynamic execution behavior.
- `lib/validators/react/isCompatTag.js` (safe): No malicious patterns detected
- `lib/validators/react/isReactComponent.js` (safe): No malicious patterns detected
- `lib/validators/validate.js` (safe): No malicious patterns detected; this is a standard AST node validation module with no network, filesystem, process, or dynamic code execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
