Togoder security

npm package security report

@scalar/types npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.22.1 Files reviewed 40 Size 50.7 KB Scanned

Summary

Togoder Security scanned the npm package @scalar/types@0.22.1 on Oct 6, 2026. An AI review of 40 source files produced 1 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
4
low

Findings 5

medium

Dynamic module loading with external input

NPS-A0863C4A3187

The schema defines a pluginUrls option documented as ESM module URLs loaded with dynamic import() at runtime. The schema itself only validates these as strings (no allowlist/URL origin validation), meaning untrusted configuration supplied to this library could cause arbitrary external ESM modules to be fetched and executed in the host application context. While this is a documented feature of the Scalar API Reference package rather than an obfuscated backdoor, it constitutes a code-loading primitive driven by potentially external/computed input and is a supply-chain/config-injection risk if configuration is attacker-influenced.

dist/api-reference/api-reference-configuration.js
low

Overly permissive schema validation (z.custom / z.any)

NPS-C5264EE34C73

Multiple fields use z.custom() or z.any() (fetchLikeSchema, hiddenClients, defaultHttpClient, metaData, plugin entries), effectively bypassing validation for functions and arbitrary values. This reduces type-safety guarantees around supplied plugins and customFetch functions, making it harder to bound the behavior of externally supplied configuration that will be executed by the consuming application.

dist/api-reference/api-reference-configuration.js
low

Deprecated URL auto-rewrite

NPS-EFB284931B52

The transform silently rewrites configuration.proxyUrl from OLD_PROXY_URL to NEW_PROXY_URL at parse time. This redirects requests through a hardcoded external proxy endpoint when the deprecated value is detected, which is a behavioral change to network routing based on configuration; it is documented and intentional, but noteworthy for review.

dist/api-reference/api-reference-configuration.js
low

External URLs in configuration

NPS-C108B0706346

The schema defines default external URLs pointing to scalar.com services (dashboard, registry, proxy, api). These are static configuration defaults for the library's intended functionality, not an active data exfiltration mechanism.

dist/api-reference/base-configuration.js
low

Telemetry enabled by default

NPS-BAF21D460DCD

The 'telemetry' option defaults to true. While this is a legitimate feature for usage analytics, it does represent data being sent to external servers by default. Users should be aware of this behavior.

dist/api-reference/base-configuration.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/api-reference/api-reference-configuration.js medium The file is a Zod configuration schema for the Scalar API Reference library; no credential harvesting, obfuscation, process spawning, or exfiltration is present, but it declares a pluginUrls option that is documented to dynamically import and execute external ESM modules from unvalidated URLs, which is a medium-severity dynamic code-loading risk.
dist/api-reference/api-client-plugin.js safe No malicious patterns detected; the file only defines Zod validation schemas for an API client plugin without any executable or exfiltration behavior.
dist/api-reference/api-client-translations.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/api-reference-configuration.test-d.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/api-reference-plugin.js safe Schema definition file using zod for configuration validation with no network, filesystem, process, or dynamic execution patterns.
dist/api-reference/authentication-configuration.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/authentication-configuration.test-d.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/base-configuration.js safe No malicious patterns detected; only static configuration schema definitions with default values for a legitimate API reference tool.
dist/api-reference/hidden-clients.test-d.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/html-api.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/html-rendering-configuration.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/index.js safe No malicious patterns detected
dist/api-reference/source-configuration.js safe Cleared by Jev triage; no further analysis needed
dist/api-reference/types.js safe Cleared by Jev triage; no further analysis needed
dist/asyncapi/3.1/index.generated.js safe No malicious patterns detected
dist/asyncapi/3.1/index.js safe Cleared by Jev triage; no further analysis needed
dist/entities/index.js safe No malicious patterns detected
dist/entities/security-scheme.js safe Cleared by Jev triage; no further analysis needed
dist/extensions/document/index.js safe No malicious patterns detected
dist/extensions/example/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/extensions/general/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/extensions/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/extensions/operation/index.js safe No malicious patterns detected
dist/extensions/parameter/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/extensions/schema/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
Show 15 more files
FileVerdictWhat the reviewer saw
dist/extensions/security/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/extensions/server/index.js safe No malicious patterns detected
dist/extensions/tag/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/extensions/workspace/index.js safe No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
dist/index.js safe Cleared by Jev triage; no further analysis needed
dist/legacy/index.js safe No malicious patterns detected
dist/legacy/reference-config.js safe No malicious patterns detected
dist/openapi/3.1/index.generated.js safe No malicious patterns detected
dist/openapi/3.1/index.js safe Cleared by Jev triage; no further analysis needed
dist/snippetz/index.js safe No malicious patterns detected
dist/snippetz/snippetz.js safe Cleared by Jev triage; no further analysis needed
dist/snippetz/snippetz.test-d.js safe Cleared by Jev triage; no further analysis needed
dist/utils/index.js safe The file only re-exports a schema from a relative module with no dynamic execution, network, filesystem, or process activity.
dist/utils/nanoid.js safe Cleared by Jev triage; no further analysis needed
dist/utils/utility-types.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of @scalar/types

VersionVerdictFilesScanned
0.22.1 Needs review 40 Oct 6, 2026

Frequently asked questions

Is @scalar/types safe to use?

No confirmed malware was found in @scalar/types@0.22.1, but the review flagged 1 medium, 4 low severity findings for risky patterns worth checking before you rely on it.

Does @scalar/types contain malware?

No malware was identified in @scalar/types@0.22.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @scalar/types checked?

Togoder Security downloaded the published npm package and had an AI model read its 40 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @scalar/types together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @scalar/types@0.22.1, cost nothing.

Related security reports