# @solana/rpc-transport-http@3.0.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:05:11.000Z
- Files reviewed: 5
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/@solana/rpc-transport-http@3.0.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @solana/rpc-transport-http@3.0.3 on Oct 4, 2026. An AI review of 5 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Header validation logic

Finding ID: `NPS-6476DB69962B`

File: `dist/index.browser.cjs`

The code implements strict validation of HTTP request headers using DISALLOWED_HEADERS and FORBIDDEN_HEADERS. It blocks sensitive headers like cookie, host, authorization, and sec-* prefixes. This is a security hardening measure, not a vulnerability.

### [low] Non-production warning

Finding ID: `NPS-5110E4A9F67D`

File: `dist/index.browser.cjs`

In non-production environments, a console.warn is triggered if a 'dispatcher_NODE_ONLY' config is supplied. This is a benign developer warning with no security implications.

## Files reviewed

- `dist/index.browser.cjs` (safe): No malicious patterns detected; the code is a standard HTTP transport implementation for Solana RPC with header filtering and no data exfiltration, obfuscation, or dynamic code execution.
- `dist/index.browser.mjs` (safe): No malicious patterns detected; the code is a legitimate Solana JSON-RPC HTTP transport implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/index.native.mjs` (safe): This is a legitimate Solana RPC HTTP transport implementation with proper header validation and no malicious patterns detected.
- `dist/index.node.cjs` (safe): No malicious patterns detected; the code is a legitimate Solana RPC HTTP transport client with proper header validation and no suspicious behavior.
- `dist/index.node.mjs` (safe): No malicious patterns detected; this is a standard Solana RPC HTTP transport implementation with proper header validation and no suspicious behavior.

## Version ranges

None of the 2 scanned versions of @solana/rpc-transport-http are flagged high or critical. The latest scanned version, 5.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 3.0.3 – 5.0.0 (`>=3.0.3 <=5.0.0`): clean
- 2.1.1 (`2.1.1`): not scanned

## Scanned versions

- [5.0.0](https://security.togoder.click/npm/@solana/rpc-transport-http@5.0.0): safe, 2026-10-04T16:17:04.000Z
- [3.0.3](https://security.togoder.click/npm/@solana/rpc-transport-http@3.0.3): safe, 2026-10-04T16:05:11.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
