# axios@1.20.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:47.000Z
- Files reviewed: 70
- Findings: no findings
- Report: https://security.togoder.click/npm/axios
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package axios@1.20.0 on Oct 6, 2026. An AI review of 70 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/adapters/adapters.js` (safe): No malicious patterns detected; the file is a legitimate Axios adapter resolution module with no external communication, credential harvesting, dynamic execution, or process spawning.
- `lib/adapters/fetch.js` (safe): This is the standard axios fetch adapter; no data exfiltration, credential harvesting, obfuscation, dynamic code execution, or other malicious patterns were detected.
- `lib/adapters/http.js` (safe): No malicious patterns detected; the code is a legitimate HTTP adapter with proxy support, redirect handling, and safety measures against prototype pollution.
- `lib/adapters/xhr.js` (safe): No malicious patterns detected in the XHR adapter; the code is a standard XMLHttpRequest wrapper for the axios library with no exfiltration, credential harvesting, dynamic execution, or process spawning.
- `lib/axios.js` (safe): No malicious patterns detected; the file is a standard Axios library entry point that only exposes API components without any execution of external commands or data exfiltration.
- `lib/cancel/CancelToken.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cancel/CanceledError.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cancel/isCancel.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/Axios.js` (safe): This is a legitimate Axios HTTP client library file with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
- `lib/core/AxiosError.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/AxiosHeaders.js` (safe): The file implements HTTP header normalization and sanitization for Axios and contains no malicious patterns such as exfiltration, credential harvesting, code execution, or network activity.
- `lib/core/InterceptorManager.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/buildFullPath.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/dispatchRequest.js` (safe): No malicious patterns detected; this is a standard Axios request dispatch module with no exfiltration, code execution, or environment access.
- `lib/core/mergeConfig.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/methodList.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/setFormDataHeaders.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/settle.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/core/transformData.js` (safe): No malicious patterns detected; the code is a standard Axios data transformation utility with no network, file system, process, or dynamic execution activity.
- `lib/defaults/index.js` (safe): No malicious patterns detected; the file contains standard Axios request/response transformation defaults with no data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
- `lib/defaults/transitional.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/env/classes/FormData.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/env/data.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/AxiosTransformStream.js` (safe): No malicious patterns detected
- `lib/helpers/AxiosURLSearchParams.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/Http2Sessions.js` (safe): Code implements HTTP/2 session pooling with no malicious patterns, network exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/helpers/HttpStatusCode.js` (safe): No malicious patterns detected
- `lib/helpers/ZlibHeaderTransformStream.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/bind.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/buildURL.js` (safe): No malicious patterns detected; the code is a standard URL-building utility with no network, filesystem, process, or code-execution behavior.
- `lib/helpers/callbackify.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/combineURLs.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/composeSignals.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/cookies.js` (safe): No malicious patterns detected; the code is a standard browser cookie helper with safe read/write/remove logic and no exfiltration, credential harvesting, dynamic execution, or install-time behavior.
- `lib/helpers/deprecatedMethod.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/estimateDataURLDecodedBytes.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/formDataToJSON.js` (safe): The code is a utility for converting FormData to a JSON object with strict depth limits and prototype pollution protection; no malicious patterns were detected.
- `lib/helpers/formDataToStream.js` (safe): No malicious patterns detected; the code implements standard multipart/form-data stream serialization with boundary generation and proper header escaping.
- `lib/helpers/fromDataURI.js` (safe): No malicious patterns detected; the file only parses data URIs into Buffer/Blob objects using standard Axios helpers and platform abstractions without exfiltration, dynamic execution, or filesystem/process manipulation.
- `lib/helpers/isAbsoluteURL.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/isAxiosError.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/isURLSameOrigin.js` (safe): No malicious patterns detected; code only performs same-origin URL comparison using the standard URL API.
- `lib/helpers/normalizeURLForProtocolCheck.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/null.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/parseHeaders.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/parseProtocol.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/progressEventReducer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/readBlob.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/resolveConfig.js` (safe): No malicious patterns detected; this is a benign Axios config resolver with prototype pollution hardening and standard request header logic.
- `lib/helpers/sanitizeHeaderValue.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/shouldBypassProxy.js` (safe): No malicious patterns detected; the code is a legitimate NO_PROXY bypass helper with careful IP canonicalization and no network, filesystem, or process side effects.
- `lib/helpers/speedometer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/spread.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/throttle.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/toFormData.js` (safe): No malicious patterns detected; this is a legitimate Axios utility for converting objects to FormData with depth limits and no external network, process, or filesystem activity.
- `lib/helpers/toURLEncodedForm.js` (safe): No malicious patterns detected; the file contains a straightforward helper for converting data to URL-encoded form format with no exfiltration, credential harvesting, obfuscation, or shell/network activity.
- `lib/helpers/trackStream.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/helpers/validator.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/browser/classes/Blob.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/browser/classes/FormData.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/browser/classes/URLSearchParams.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/browser/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/common/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/node/classes/Buffer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/node/classes/FormData.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/node/classes/URLSearchParams.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/platform/node/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/utils.js` (safe): This is a legitimate axios utility module containing defensive prototype-pollution protections and generic helper functions with no malicious, exfiltration, or code-execution patterns.

## Version ranges

None of the 3 scanned versions of axios are flagged high or critical. The latest scanned version, 1.20.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.20.0 (`1.20.0`): clean
- 1.18.1 (`1.18.1`): not scanned
- 1.13.1 – 1.13.2 (`>=1.13.1 <=1.13.2`): clean
- 1.12.2 (`1.12.2`): not scanned

## Scanned versions

- [1.20.0](https://security.togoder.click/npm/axios@1.20.0): safe, 2026-10-06T14:13:47.000Z
- [1.13.2](https://security.togoder.click/npm/axios@1.13.2): safe, 2026-10-04T16:55:49.000Z
- [1.13.1](https://security.togoder.click/npm/axios@1.13.1): safe, 2026-05-15T12:29:04.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
