Togoder security

npm package security report

ajv npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 8.20.0 Files reviewed 213 Size 587.6 KB Scanned

Summary

Togoder Security scanned the npm package ajv@8.20.0 on Oct 6, 2026. An AI review of 213 source files produced 13 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
13
medium
2
low

Findings 15

medium

Code generation from external input

NPS-789DE550EA33

Generates JavaScript source code from schema definitions provided at runtime and compiles it into executable functions. If untrusted schemas are processed, this could potentially lead to code injection depending on how schema values are stringified into the generated code.

dist/compile/index.js:76
medium

Dynamic code execution

NPS-C101A8F12E3A

Uses new Function(...) to dynamically compile and execute source code generated from JSON schema input. While this is a legitimate AJV pattern for schema compilation, dynamic code execution can be dangerous if schema input is user-controlled or untrusted.

dist/compile/index.js:81
medium

Dynamic code execution

NPS-6853E9D335CD

The code uses new Function(...) to compile generated parser code at runtime. While this is a legitimate technique in code-generation libraries (like Ajv), it is a dynamic code execution primitive that could be abused if the generated code is influenced by untrusted input.

dist/compile/jtd/parse.js:42
medium

Use of eval-like compilation

NPS-E393E9365388

The makeParse function is created from a string built via gen.toString() and then invoked. This pattern is functionally equivalent to eval and is a red flag for static analysis, though in this context it appears to be part of a JSON schema compiler.

dist/compile/jtd/parse.js:42
medium

code generation from schema input

NPS-BBD4853E8D59

This module compiles JSON schemas into JavaScript functions by string concatenation and dynamic evaluation. The sourceCode variable is built from generated code strings and passed to new Function(). If an application uses this library to compile untrusted schemas, it could lead to arbitrary code execution. The schema properties, type names, and references are all incorporated into the generated code.

dist/compile/jtd/serialize.js:44
medium

dynamic code execution

NPS-B2C44F024437

The code uses new Function() to dynamically compile and execute generated JavaScript source code. While this is a legitimate pattern in code generation libraries (this appears to be Ajv's JTD serializer compiler), dynamic code execution from string input is a security concern if the schema being compiled comes from untrusted sources. An attacker who can control the schema could potentially inject arbitrary code through the code generation process.

dist/compile/jtd/serialize.js:47
medium

Dynamic code execution

NPS-A06F3C8B8CB5

The code uses require-from-string to load and execute JavaScript code generated at runtime by the standalone code generator. While this is intended for AJV standalone validation code, it represents dynamic code execution that could be exploited if the generated code is influenced by untrusted input.

dist/standalone/instance.js:21
medium

Code generation and execution at import/build time

NPS-318E3A63D28B

The module compiles parsers at runtime using generated code. This involves creating functions via new Function, which executes dynamically generated code. This is a standard pattern for performance optimization in Ajv but can be a security concern if the input schemas are not trusted.

lib/compile/jtd/parse.ts
medium

Dynamic code execution

NPS-52B7CCC056E1

The compileParser function constructs a new function from generated source code using new Function(...) and executes it. While this is a legitimate code generation technique used by Ajv for compiling JSON parsers, it represents dynamic code execution that could be abused if the schema input is attacker-controlled or if the generated code is tampered with. However, in this context, it is part of the intended functionality and not inherently malicious.

lib/compile/jtd/parse.ts:75
medium

Dynamic code execution

NPS-ABAFBEA45BA1

The code uses new Function to dynamically compile generated serializer source code. While this is a known and expected pattern for the Ajv library (which compiles JSON schemas into JavaScript functions at runtime), dynamic code execution can be a security concern if the schema inputs are not trusted. The generated code is constructed from schema properties and JSON.stringify output, but the general pattern warrants caution.

lib/compile/jtd/serialize.ts:74
medium

Code generation from schema input

NPS-31702C21CEB2

The serializer generates JavaScript source code strings based on schema definitions (e.g., property names, discriminator tags, refs) and then executes them via new Function. If an attacker can control the JSON schema (JTD schema) passed to this compiler, they may be able to inject arbitrary code into the generated function. Property keys are escaped with JSON.stringify in some places, but discriminator values in serializeDiscriminator are interpolated directly into code (gen.elseIf(_${tag} === ${tagValue})) without validation, which could potentially allow code injection if tag values are attacker-controlled.

lib/compile/jtd/serialize.ts:122
medium

Dynamic code execution

NPS-E9F6105114D1

The code uses require-from-string to execute dynamically generated JavaScript at runtime via the getStandalone method. While this is intended to compile standalone validation functions, it represents a dynamic code execution vector where the generated code is evaluated in the current process context. This is inherent to the ajv standalone feature but should be noted as a potential risk if the input schema is attacker-controlled.

lib/standalone/instance.ts:27
medium

Dynamic module loading

NPS-8565DF2B3195

require-from-string loads modules from computed strings rather than files on disk. This bypasses normal module resolution and can be abused to execute arbitrary code if an attacker can influence the schema passed to compile/getSchema.

lib/standalone/instance.ts:27
low

File System Access via Module Loading

NPS-7D93B0287F8D

The code references require("ajv/dist/runtime/validation_error") in generated code, which is standard module loading. No suspicious file system operations outside the package scope were detected.

lib/compile/index.ts:109
low

Dynamic Code Execution

NPS-5C16B9D95212

The code uses new Function() to compile generated validation functions at runtime. While this is the core mechanism of Ajv (a widely-used JSON schema validator), it does represent dynamic code execution. In this context, the code being executed is generated from JSON schemas provided by the user of the library, which is expected behavior. However, if schemas come from untrusted sources, this could potentially be exploited. The code.process option also allows arbitrary transformation of source code before execution.

lib/compile/index.ts:168

Files reviewed

FileVerdictWhat the reviewer saw
dist/compile/index.js medium This appears to be legitimate AJV schema compilation code that uses dynamic Function construction, which is expected for schema-to-validator code generation but represents a code-injection surface if untrusted schemas are processed.
dist/compile/jtd/parse.js medium This is a legitimate JSON schema parser compiler from the Ajv library that uses runtime code generation via new Function, which is a common but potentially risky pattern; no data exfiltration, credential harvesting, or backdoor behavior was found.
dist/compile/jtd/serialize.js medium This is legitimate code from the Ajv JSON schema validator library that compiles JTD schemas to serialization functions, using dynamic code generation via new Function(), which is a standard pattern for this library but carries inherent risk if used with untrusted schemas.
dist/standalone/instance.js medium The code uses dynamic module loading via require-from-string, which is a potential security concern but appears to be a legitimate use for AJV standalone validation code.
lib/compile/index.ts medium This is legitimate Ajv schema compilation code that uses new Function() for code generation, which is expected behavior for a JSON schema validator, but does involve dynamic code execution from schema-generated source.
lib/compile/jtd/parse.ts medium The code uses dynamic code generation via new Function for performance optimization, which is a potential security risk if schemas are untrusted, but no overt malicious patterns like data exfiltration, credential harvesting, or backdoors were found.
lib/compile/jtd/serialize.ts medium This file is part of the legitimate Ajv JSON schema validator and uses dynamic code generation (new Function) as a core design pattern, which is expected but carries inherent risks if untrusted schemas are compiled; no data exfiltration, credential harvesting, backdoors, or other overtly malicious patterns were found.
lib/standalone/instance.ts medium This appears to be the legitimate AjvPack wrapper from the ajv package that uses require-from-string to compile standalone validation code, but the dynamic code execution pattern warrants caution if schemas are untrusted.
.runkit_example.js safe No malicious patterns detected
dist/2019.js safe This file is a legitimate part of the Ajv JSON schema validator, exporting the Ajv2019 class and related utilities with no malicious patterns.
dist/2020.js safe This is the standard Ajv2020 JSON Schema validator entry point with no malicious patterns detected.
dist/ajv.js safe No malicious patterns detected in the analyzed Ajv library entry point; all imports and exports are legitimate JSON schema validation functionality.
dist/compile/codegen/code.js safe No malicious patterns detected; the code is a benign code-generation utility with no network, filesystem, process, or dynamic-execution behavior.
dist/compile/codegen/index.js safe No malicious patterns detected; this is a legitimate code generation utility from the Ajv ecosystem with no network, filesystem, process, or dynamic execution concerns.
dist/compile/codegen/scope.js safe This is a legitimate code-generation utility module from the AJV JSON schema validator that only manipulates in-memory scope and naming data with no network, filesystem, process, or dynamic code execution behavior.
dist/compile/errors.js safe No malicious patterns detected; this file is a legitimate part of AJV's error-code generation module with no network, filesystem, process, or dynamic execution activity.
dist/compile/jtd/types.js safe No malicious patterns detected
dist/compile/names.js safe Cleared by Jev triage; no further analysis needed
dist/compile/ref_error.js safe No malicious patterns detected; the file defines a simple custom error class for reference resolution errors.
dist/compile/resolve.js safe No malicious patterns detected; the code is a legitimate JSON schema reference resolver with no network, filesystem, process, or dynamic execution concerns.
dist/compile/rules.js safe No malicious patterns detected
dist/compile/util.js safe No malicious patterns detected
dist/compile/validate/applicability.js safe No malicious patterns detected
dist/compile/validate/boolSchema.js safe No malicious patterns detected
dist/compile/validate/dataType.js safe No malicious patterns detected; this is a standard JSON Schema data type validation module with no network, filesystem, process, or dynamic execution concerns.
Show 188 more files
FileVerdictWhat the reviewer saw
dist/compile/validate/defaults.js safe No malicious patterns detected; the code is a standard JSON Schema default assignment utility with no network, filesystem, process, or dynamic code execution concerns.
dist/compile/validate/index.js safe This is a legitimate JSON schema validation compiler (Ajv) with no malicious patterns detected.
dist/compile/validate/keyword.js safe This is a legitimate Ajv JSON schema compiler module for handling custom keyword validation; no malicious patterns detected.
dist/compile/validate/subschema.js safe No malicious patterns detected; the code is a standard part of the AJV JSON schema validator library for managing subschema data and modes.
dist/core.js safe No malicious patterns detected; this is the legitimate Ajv JSON schema validator core module with no suspicious network, filesystem, or execution behavior.
dist/jtd.js safe No malicious patterns detected; this is a standard Ajv JTD module export file with no dynamic code execution, network, filesystem, or credential access.
dist/refs/json-schema-2019-09/index.js safe No malicious patterns detected; the file only loads JSON schema modules and registers them with Ajv without any network, filesystem, process, or dynamic execution activity.
dist/refs/json-schema-2020-12/index.js safe The file is a benign AJV meta-schema registration module that only imports local JSON schemas and registers them with no network, filesystem, process, or dynamic code execution activity.
dist/refs/jtd-schema.js safe No malicious patterns detected; the code is a benign JTD meta-schema definition with no network, filesystem, process, or dynamic execution activity.
dist/runtime/equal.js safe No malicious patterns detected; the file is a simple wrapper around fast-deep-equal used for Ajv's runtime equality checks.
dist/runtime/parseJson.js safe No malicious patterns detected
dist/runtime/quote.js safe No malicious patterns detected; the file is a benign JSON string quoting utility from the Ajv library with no network, credential, code execution, or filesystem activity.
dist/runtime/re2.js safe No malicious patterns detected; the file is a thin wrapper that re-exports the 're2' module with an added code property for ajv runtime resolution.
dist/runtime/timestamp.js safe The code is a pure timestamp validation utility with no network, filesystem, process execution, or obfuscated behavior.
dist/runtime/ucs2length.js safe The file contains only a pure JavaScript function for counting Unicode code points via UTF-16 surrogate pair handling, with no network, filesystem, process, environment, or dynamic code execution behavior.
dist/runtime/uri.js safe This is a legitimate Ajv runtime URI module that wraps the fast-uri package with no malicious patterns, network activity, or code execution.
dist/runtime/validation_error.js safe No malicious patterns detected
dist/standalone/index.js safe No malicious patterns detected; this is legitimate Ajv standalone code generation logic.
dist/types/index.js safe The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns.
dist/types/json-schema.js safe No malicious patterns detected
dist/types/jtd-schema.js safe No malicious patterns detected
dist/vocabularies/applicator/additionalItems.js safe No malicious patterns detected; the file contains legitimate JSON Schema validation logic for the 'additionalItems' keyword.
dist/vocabularies/applicator/additionalProperties.js safe This file is a legitimate Ajv JSON Schema validator implementation for the 'additionalProperties' keyword with no malicious patterns detected.
dist/vocabularies/applicator/allOf.js safe The file is a legitimate Ajv JSON schema validation keyword implementation with no malicious patterns, network calls, credential access, or dynamic code execution.
dist/vocabularies/applicator/anyOf.js safe No malicious patterns detected
dist/vocabularies/applicator/contains.js safe No malicious patterns detected; this is a legitimate JSON Schema 'contains' keyword implementation from the Ajv validator.
dist/vocabularies/applicator/dependencies.js safe The file is a legitimate part of the Ajv JSON schema validator, implementing the 'dependencies' keyword with no malicious patterns, network calls, process execution, or obfuscation.
dist/vocabularies/applicator/dependentSchemas.js safe No malicious patterns detected
dist/vocabularies/applicator/if.js safe No malicious patterns detected; the code is a standard JSON Schema 'if' keyword validator.
dist/vocabularies/applicator/index.js safe No malicious patterns detected
dist/vocabularies/applicator/items.js safe No malicious patterns detected; the file is a legitimate JSON schema validation code generator for the 'items' keyword with no network, filesystem, process, or dynamic execution activity.
dist/vocabularies/applicator/items2020.js safe No malicious patterns detected
dist/vocabularies/applicator/not.js safe No malicious patterns detected; the code is a benign JSON Schema validation keyword implementation for 'not'.
dist/vocabularies/applicator/oneOf.js safe This is a legitimate Ajv JSON schema validation keyword implementation with no malicious patterns, network calls, or code execution risks.
dist/vocabularies/applicator/patternProperties.js safe No malicious patterns detected; the code is a legitimate JSON Schema validation keyword implementation for patternProperties.
dist/vocabularies/applicator/prefixItems.js safe No malicious patterns detected
dist/vocabularies/applicator/properties.js safe No malicious patterns detected
dist/vocabularies/applicator/propertyNames.js safe No malicious patterns detected; this is a standard JSON schema validation module for the propertyNames keyword.
dist/vocabularies/applicator/thenElse.js safe No malicious patterns detected
dist/vocabularies/code.js safe This is a legitimate AJV (JSON schema validator) source file that generates validation code without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity.
dist/vocabularies/core/id.js safe No malicious patterns detected
dist/vocabularies/core/index.js safe No malicious patterns detected
dist/vocabularies/core/ref.js safe No malicious patterns detected; the code is a legitimate JSON schema $ref resolver from the Ajv validation library.
dist/vocabularies/discriminator/index.js safe No malicious patterns detected; this is a legitimate JSON Schema discriminator vocabulary implementation with no network, filesystem, process, or credential access.
dist/vocabularies/discriminator/types.js safe No malicious patterns detected
dist/vocabularies/draft2020.js safe No malicious patterns detected
dist/vocabularies/draft7.js safe The file only imports local vocabulary modules and exports an array, with no malicious patterns detected.
dist/vocabularies/dynamic/dynamicAnchor.js safe No malicious patterns detected; the code is a legitimate JSON schema $dynamicAnchor vocabulary implementation without any obfuscation, network, file system, process spawning, or dynamic code execution concerns.
dist/vocabularies/dynamic/dynamicRef.js safe No malicious patterns detected; the code implements JSON Schema $dynamicRef compilation logic without external network, filesystem, process, or dynamic code execution concerns.
dist/vocabularies/dynamic/index.js safe No malicious patterns detected; the file only imports and re-exports JSON Schema dynamic vocabulary modules without any suspicious behavior.
dist/vocabularies/dynamic/recursiveAnchor.js safe No malicious patterns detected
dist/vocabularies/dynamic/recursiveRef.js safe No malicious patterns detected
dist/vocabularies/errors.js safe No malicious patterns detected
dist/vocabularies/format/format.js safe No malicious patterns detected; this is a legitimate JSON Schema format validation module that generates validation code without any exfiltration, credential harvesting, or dynamic code execution.
dist/vocabularies/format/index.js safe No malicious patterns detected
dist/vocabularies/jtd/discriminator.js safe No malicious patterns detected; this is standard JSON Type Definition discriminator code for the ajv validation library with no exfiltration, dynamic execution, or lifecycle hooks.
dist/vocabularies/jtd/elements.js safe No malicious patterns detected
dist/vocabularies/jtd/enum.js safe No malicious patterns detected in the enum validation keyword implementation.
dist/vocabularies/jtd/error.js safe No malicious patterns detected; the code only defines error message and parameter generation functions for JTD schema validation.
dist/vocabularies/jtd/index.js safe No malicious patterns detected
dist/vocabularies/jtd/metadata.js safe No malicious patterns detected
dist/vocabularies/jtd/nullable.js safe No malicious patterns detected; the code is a standard JSON Type Definition nullable schema validator that only performs code generation and type checking.
dist/vocabularies/jtd/optionalProperties.js safe No malicious patterns detected
dist/vocabularies/jtd/properties.js safe No malicious patterns detected; the code is a legitimate JSON Schema/JTD properties validator with no network, filesystem, process, or dynamic execution behavior.
dist/vocabularies/jtd/ref.js safe No malicious patterns detected; the code implements JSON Type Definition 'ref' keyword validation and reference resolution without any exfiltration, obfuscation, or execution of untrusted input.
dist/vocabularies/jtd/type.js safe No malicious patterns detected; the code is a legitimate JSON Type Definition type validator with no network, filesystem, process, or dynamic code execution concerns.
dist/vocabularies/jtd/union.js safe No malicious patterns detected
dist/vocabularies/jtd/values.js safe No malicious patterns detected; the code is a standard JSON Type Definition 'values' keyword validator using code generation utilities.
dist/vocabularies/metadata.js safe No malicious patterns detected
dist/vocabularies/next.js safe No malicious patterns detected
dist/vocabularies/unevaluated/index.js safe Cleared by Jev triage; no further analysis needed
dist/vocabularies/unevaluated/unevaluatedItems.js safe No malicious patterns detected; this is a legitimate JSON Schema validation keyword implementation from the Ajv library.
dist/vocabularies/unevaluated/unevaluatedProperties.js safe No malicious patterns detected; this is a legitimate Ajv JSON Schema validator module implementing the unevaluatedProperties keyword.
dist/vocabularies/validation/const.js safe No malicious patterns detected; this is a standard JSON Schema 'const' keyword implementation with no network, filesystem, process, or dynamic code execution behavior.
dist/vocabularies/validation/dependentRequired.js safe No malicious patterns detected
dist/vocabularies/validation/enum.js safe This is a standard Ajv JSON schema validation keyword implementation for 'enum' with no malicious patterns detected.
dist/vocabularies/validation/index.js safe No malicious patterns detected; the file only imports and assembles validation keyword handlers.
dist/vocabularies/validation/limitContains.js safe No malicious patterns detected
dist/vocabularies/validation/limitItems.js safe This is a standard JSON Schema validation module for maxItems/minItems with no malicious patterns, network activity, filesystem access, or dynamic code execution.
dist/vocabularies/validation/limitLength.js safe No malicious patterns detected
dist/vocabularies/validation/limitNumber.js safe No malicious patterns detected
dist/vocabularies/validation/limitProperties.js safe No malicious patterns detected
dist/vocabularies/validation/multipleOf.js safe No malicious patterns detected; the file is a legitimate JSON Schema validation keyword implementation for multipleOf with no network, filesystem, process, or dynamic code execution behavior.
dist/vocabularies/validation/pattern.js safe No malicious patterns detected; this is a standard validation keyword implementation for regex pattern matching from the Ajv JSON schema validator package.
dist/vocabularies/validation/required.js safe This is a legitimate JSON Schema validation module for the 'required' keyword with no malicious patterns detected.
dist/vocabularies/validation/uniqueItems.js safe No malicious patterns detected; this is a standard JSON Schema uniqueItems validation compiler module with no network, filesystem, process, or dynamic code execution behavior.
lib/2019.ts safe Cleared by Jev triage; no further analysis needed
lib/2020.ts safe Cleared by Jev triage; no further analysis needed
lib/ajv.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/codegen/code.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/codegen/index.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/codegen/scope.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/errors.ts safe No malicious patterns detected in this Ajv error compilation module, which only contains schema validation error formatting logic.
lib/compile/jtd/types.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/names.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/ref_error.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/resolve.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/rules.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/util.ts safe No malicious patterns detected; the code is a legitimate JSON Schema compiler utility with no network, filesystem, process, or dynamic execution concerns.
lib/compile/validate/applicability.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/validate/boolSchema.ts safe Cleared by Jev triage; no further analysis needed
lib/compile/validate/dataType.ts safe This file contains standard JSON Schema data type validation and coercion logic with no malicious patterns, external communications, or dynamic code execution.
lib/compile/validate/defaults.ts safe No malicious patterns detected; the file implements standard JSON schema default value assignment without any suspicious behavior.
lib/compile/validate/index.ts safe This is the standard Ajv JSON Schema validator compilation code; no malicious patterns, exfiltration, obfuscation, or dynamic code execution beyond the library's intended schema-to-code generation were detected.
lib/compile/validate/keyword.ts safe No malicious patterns detected; the code is a legitimate part of Ajv's keyword compilation logic with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns.
lib/compile/validate/subschema.ts safe Cleared by Jev triage; no further analysis needed
lib/core.ts safe This is the standard Ajv JSON Schema validator core module with no malicious patterns detected.
lib/jtd.ts safe The TypeScript file is a legitimate Ajv JTD (JSON Type Definition) plugin with no malicious patterns, only standard schema compilation and class export logic.
lib/refs/json-schema-2019-09/index.ts safe Cleared by Jev triage; no further analysis needed
lib/refs/json-schema-2020-12/index.ts safe Cleared by Jev triage; no further analysis needed
lib/refs/jtd-schema.ts safe Cleared by Jev triage; no further analysis needed
lib/runtime/equal.ts safe Cleared by Jev triage; no further analysis needed
lib/runtime/parseJson.ts safe No malicious patterns detected; the code is a legitimate JSON parsing utility for ajv with no external calls, obfuscation, or dangerous operations.
lib/runtime/quote.ts safe Cleared by Jev triage; no further analysis needed
lib/runtime/re2.ts safe No malicious patterns detected; the code simply imports the 're2' module and annotates it with a static code string for Ajv compatibility.
lib/runtime/timestamp.ts safe Cleared by Jev triage; no further analysis needed
lib/runtime/ucs2length.ts safe Cleared by Jev triage; no further analysis needed
lib/runtime/uri.ts safe Cleared by Jev triage; no further analysis needed
lib/runtime/validation_error.ts safe Cleared by Jev triage; no further analysis needed
lib/standalone/index.ts safe No malicious patterns detected; the code is a legitimate Ajv standalone code generation module with no network, filesystem, process, or obfuscation concerns.
lib/types/index.ts safe Cleared by Jev triage; no further analysis needed
lib/types/json-schema.ts safe Cleared by Jev triage; no further analysis needed
lib/types/jtd-schema.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/additionalItems.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/additionalProperties.ts safe No malicious patterns detected in the additionalProperties keyword implementation; it is legitimate JSON Schema validation logic from the Ajv library.
lib/vocabularies/applicator/allOf.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/anyOf.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/contains.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/dependencies.ts safe No malicious patterns detected; this is a legitimate JSON Schema keyword definition for 'dependencies' validation with no network, filesystem, process, or dynamic code execution behavior.
lib/vocabularies/applicator/dependentSchemas.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/if.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/items.ts safe No malicious patterns detected
lib/vocabularies/applicator/items2020.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/not.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/oneOf.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/patternProperties.ts safe No malicious patterns detected; the code is a legitimate JSON schema validation keyword implementation for patternProperties.
lib/vocabularies/applicator/prefixItems.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/properties.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/applicator/propertyNames.ts safe No malicious patterns detected
lib/vocabularies/applicator/thenElse.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/code.ts safe No malicious patterns detected; the code is a standard AJV validation vocabulary implementation with no exfiltration, credential harvesting, obfuscation, or process spawning.
lib/vocabularies/core/id.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/core/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/core/ref.ts safe This is a legitimate JSON Schema $ref keyword implementation from the Ajv library with no malicious patterns detected.
lib/vocabularies/discriminator/index.ts safe No malicious patterns detected; this is legitimate JSON Schema discriminator keyword implementation from Ajv.
lib/vocabularies/discriminator/types.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/draft2020.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/draft7.ts safe No malicious patterns detected
lib/vocabularies/dynamic/dynamicAnchor.ts safe No malicious patterns detected; the code is a legitimate JSON Schema dynamic anchor implementation without network, filesystem, process, or obfuscation concerns.
lib/vocabularies/dynamic/dynamicRef.ts safe This file is a legitimate part of the Ajv JSON schema validator implementing the $dynamicRef keyword; it contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
lib/vocabularies/dynamic/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/dynamic/recursiveAnchor.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/dynamic/recursiveRef.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/errors.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/format/format.ts safe No malicious patterns detected
lib/vocabularies/format/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/discriminator.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/elements.ts safe No malicious patterns detected
lib/vocabularies/jtd/enum.ts safe This is a legitimate Ajv JSON Type Definition keyword implementation for enum validation with no malicious patterns detected.
lib/vocabularies/jtd/error.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/metadata.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/nullable.ts safe No malicious patterns detected; code is part of the ajv JTD validation library with no network, filesystem, process, or dynamic execution behavior.
lib/vocabularies/jtd/optionalProperties.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/properties.ts safe No malicious patterns detected; this is a legitimate JSON Type Definition (JTD) schema validation module for the Ajv validator library.
lib/vocabularies/jtd/ref.ts safe No malicious patterns detected; this is a legitimate JSON Type Definition reference-handling module from the Ajv validator library.
lib/vocabularies/jtd/type.ts safe No malicious patterns detected
lib/vocabularies/jtd/union.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/jtd/values.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/metadata.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/next.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/unevaluated/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/unevaluated/unevaluatedItems.ts safe No malicious patterns detected; the file is a legitimate JSON Schema keyword implementation for unevaluatedItems validation.
lib/vocabularies/unevaluated/unevaluatedProperties.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/validation/const.ts safe No malicious patterns detected; the file is a standard JSON Schema 'const' keyword validator implementation with no network, filesystem, process, or dynamic code execution behavior.
lib/vocabularies/validation/dependentRequired.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/validation/enum.ts safe No malicious patterns detected; this is a legitimate Ajv JSON schema validation keyword implementation for enum checks.
lib/vocabularies/validation/index.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/validation/limitContains.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/validation/limitItems.ts safe Cleared by Jev triage; no further analysis needed
lib/vocabularies/validation/limitLength.ts safe No malicious patterns detected
lib/vocabularies/validation/limitNumber.ts safe No malicious patterns detected; the code implements JSON schema numeric limit validation with no network, filesystem, process execution, or obfuscation concerns.
lib/vocabularies/validation/limitProperties.ts safe No malicious patterns detected; the file only defines a standard JSON Schema validation keyword for min/max properties.
lib/vocabularies/validation/multipleOf.ts safe No malicious patterns detected; the code is a standard JSON schema validation keyword implementation for 'multipleOf' with no network, filesystem, process, or dynamic code execution activity.
lib/vocabularies/validation/pattern.ts safe No malicious patterns detected; the code is a standard JSON Schema 'pattern' keyword validator with no network, filesystem, process, or credential access.
lib/vocabularies/validation/required.ts safe No malicious patterns detected; this is a legitimate JSON Schema validation keyword implementation for the 'required' property.
lib/vocabularies/validation/uniqueItems.ts safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of ajv are flagged high or critical. The latest scanned version, 8.20.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

6.12.68.20.0
VersionsVerdictCountRangeTop findings
8.20.0 Needs review 1 8.20.0 Dynamic code execution; Code generation from external input
8.11.0 โ€“ 8.17.1 Not scanned 2 >=8.11.0 <=8.17.1
6.15.0 Needs review 1 6.15.0 Dynamic code execution via new Function; Custom keyword code execution
6.12.6 Not scanned 1 6.12.6

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of ajv

VersionVerdictFilesScanned
8.20.0 Needs review 213 Oct 6, 2026
6.15.0 Needs review 44 Oct 6, 2026

Frequently asked questions

Is ajv safe to use?

No confirmed malware was found in ajv@8.20.0, but the review flagged 13 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does ajv contain malware?

No malware was identified in ajv@8.20.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was ajv checked?

Togoder Security downloaded the published npm package and had an AI model read its 213 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan ajv together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ajv@8.20.0, cost nothing.

Related security reports