# @orval/hono@8.39.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:25.000Z
- Files reviewed: 2
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/@orval/hono
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @orval/hono@8.39.0 on Oct 6, 2026. An AI review of 2 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Dynamic import of optional peer dependency

Finding ID: `NPS-434AFD40883F`

File: `dist/index.mjs`

The code lazily imports the 'typescript' module via `await import('typescript')` inside `ensureTypeScript`. Dynamic imports with module names can be a red flag if the name were attacker-controlled, but here it is a fixed, well-known package. It is used to parse/generate TypeScript code, which is expected for this code generator (orval). Low risk.

### [low] Reads a bundled source file at import time

Finding ID: `NPS-623EE449B7BB`

File: `dist/index.mjs`

At module load time, `ZVALIDATOR_SOURCE = fs.readFileSync(nodePath.join(import.meta.dirname, "zValidator.ts")).toString("utf8")` reads a sibling file. This is top-level code executed on import and reads from the package's own directory. It is not exfiltrating data, but it is side-effectful code at import time reading from the filesystem.

### [low] Filesystem writes outside typical data directories

Finding ID: `NPS-10F4C12F27E0`

File: `dist/index.mjs`

The module writes generated handler/context/zod files to paths derived from user configuration (output.target, output.override.hono.handlers, etc.). This is expected behavior for a code generator, but writing arbitrary filesystem paths based on configuration warrants awareness. No evidence of writing to sensitive OS/credential locations.

### [low] Optional peer dependency fallback

Finding ID: `NPS-CA15AF04C574`

File: `dist/index.mjs`

When 'typescript' is unavailable, `smart`/`full` strategies silently fall back to `skip`, leaving existing handler files unchanged. This is documented and benign.

## Files reviewed

- `dist/index.mjs` (medium): The file is a legitimate orval code-generation module for Hono handlers; it performs expected filesystem reads/writes and lazily imports the optional 'typescript' parser, with no signs of data exfiltration, credential harvesting, shell execution, or obfuscated payloads.
- `dist/zValidator.ts` (safe): No malicious patterns detected; the code is a legitimate Hono zod-validator middleware wrapper with no exfiltration, obfuscation, or suspicious behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
