# abort-controller@3.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:20:42.000Z
- Files reviewed: 7
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/abort-controller
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package abort-controller@3.0.0 on Oct 4, 2026. An AI review of 7 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Dynamic code execution

Finding ID: `NPS-813BCCAA7A6D`

File: `dist/abort-controller.umd.js`

The code uses `Function("return this")()` to obtain the global object when `module` and `define` are undefined. While this pattern is a known UMD fallback and not inherently malicious, `new Function` (or `Function` constructor) is a dynamic code execution primitive that could be abused if input were ever passed to it. Here the string is static, so risk is low, but it is a red flag worth noting.

### [low] Global object modification

Finding ID: `NPS-C9AB215790FC`

File: `dist/abort-controller.umd.js`

At the end of the UMD wrapper, the code checks for `AbortController` on the global object and conditionally assigns `AbortController` and `AbortSignal` polyfills. This modifies global state, which is expected for a polyfill but should be noted as it affects the runtime environment.

## Files reviewed

- `dist/abort-controller.umd.js` (medium): The file is a standard UMD polyfill for AbortController/AbortSignal with no malicious network, filesystem, credential-harvesting, or process-spawning behavior; only minor concerns are the use of the Function constructor and global mutation typical of polyfills.
- `browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `browser.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/abort-controller.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/abort-controller.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `polyfill.js` (safe): No malicious patterns detected; the code is a standard polyfill for AbortController and AbortSignal that conditionally assigns them to the global object.
- `polyfill.mjs` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
