# @scalar/openapi-upgrader@0.4.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:04.000Z
- Files reviewed: 14
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@scalar/openapi-upgrader
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @scalar/openapi-upgrader@0.4.0 on Oct 6, 2026. An AI review of 14 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Network request at import time

Finding ID: `NPS-106E271844CD`

File: `dist/upgrade.bench.js:8`

The file performs top-level 'await fetch()' calls to external URLs (STRIPE_URL_3_0 and PETSTORE_URL_2_0) from '@scalar/helpers/url/oas-document-fixtures'. This means importing this module triggers network requests immediately, which is unexpected for a benchmark file. If the referenced URLs are ever compromised or changed, this could be leveraged for data ingestion or tracking. It also creates a dependency on external service availability, though in this benchmark context the URLs appear to be legitimate fixture sources.

## Files reviewed

- `dist/upgrade.bench.js` (medium): The benchmark file is largely benign, but it performs top-level network fetches to external fixture URLs at import time, which is a minor supply-chain concern rather than active malicious behavior.
- `dist/2.0-to-3.0/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/2.0-to-3.0/upgrade-from-two-to-three.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/3.0-to-3.1/index.js` (safe): This file only contains a simple re-export statement with no executable logic or malicious patterns.
- `dist/3.0-to-3.1/upgrade-from-three-to-three-one.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/3.1-to-3.2/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/3.1-to-3.2/migrate-objects.js` (safe): No malicious patterns detected
- `dist/3.1-to-3.2/migrate-tag-groups.js` (safe): No malicious patterns detected; the module only performs pure in-memory document transformation with no I/O, network, process, or dynamic code execution.
- `dist/3.1-to-3.2/upgrade-from-three-one-to-three-two.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/helpers/clone-document.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/helpers/traverse.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/upgrade-incompatibility-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/upgrade.js` (safe): No malicious patterns detected; the code performs local OpenAPI document upgrade logic with no network, filesystem, credential, or dynamic execution activity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
