Togoder security

npm package security report

axios@1.13.2 security report

No malicious code found.

No issues Version 1.13.2 Files reviewed 64 Size 631.7 KB Scanned

Summary

Togoder Security scanned the npm package axios@1.13.2 on Oct 4, 2026. An AI review of 64 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
dist/browser/axios.cjs safe This is the legitimate Axios v1.13.2 browser build with standard HTTP client functionality and no malicious patterns detected.
index.js safe Cleared by Jev triage; no further analysis needed
lib/adapters/adapters.js safe No malicious patterns detected
lib/adapters/fetch.js safe This is a legitimate Axios fetch adapter with no malicious patterns; it performs standard HTTP request handling, signal composition, progress tracking, and response parsing without any data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
lib/adapters/http.js safe No malicious patterns detected
lib/adapters/xhr.js safe This is a legitimate Axios XHR adapter that implements standard HTTP request functionality without any malicious patterns, credential harvesting, dynamic code execution, or suspicious network activity.
lib/axios.js safe No malicious patterns detected; this is the standard Axios entry point that only assembles and exports the public API without any network, file system, or process manipulation.
lib/cancel/CancelToken.js safe Cleared by Jev triage; no further analysis needed
lib/cancel/CanceledError.js safe Cleared by Jev triage; no further analysis needed
lib/cancel/isCancel.js safe Cleared by Jev triage; no further analysis needed
lib/core/Axios.js safe No malicious patterns detected
lib/core/AxiosError.js safe Cleared by Jev triage; no further analysis needed
lib/core/AxiosHeaders.js safe No malicious patterns detected
lib/core/InterceptorManager.js safe Cleared by Jev triage; no further analysis needed
lib/core/buildFullPath.js safe Cleared by Jev triage; no further analysis needed
lib/core/dispatchRequest.js safe No malicious patterns detected; this is a standard Axios request dispatcher with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
lib/core/mergeConfig.js safe Cleared by Jev triage; no further analysis needed
lib/core/settle.js safe Cleared by Jev triage; no further analysis needed
lib/core/transformData.js safe This is a legitimate data transformation utility from the axios library with no malicious patterns detected.
lib/defaults/index.js safe Cleared by Jev triage; no further analysis needed
lib/defaults/transitional.js safe Cleared by Jev triage; no further analysis needed
lib/env/classes/FormData.js safe Cleared by Jev triage; no further analysis needed
lib/env/data.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/AxiosTransformStream.js safe No malicious patterns detected; the code implements a rate-limiting Transform stream for Axios without any suspicious network, filesystem, or process operations.
lib/helpers/AxiosURLSearchParams.js safe Cleared by Jev triage; no further analysis needed
Show 39 more files
FileVerdictWhat the reviewer saw
lib/helpers/HttpStatusCode.js safe No malicious patterns detected
lib/helpers/ZlibHeaderTransformStream.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/bind.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/buildURL.js safe This is a standard Axios URL-building utility with no malicious patterns, network calls, credential harvesting, or dynamic code execution.
lib/helpers/callbackify.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/combineURLs.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/composeSignals.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/cookies.js safe No malicious patterns detected
lib/helpers/deprecatedMethod.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/estimateDataURLDecodedBytes.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/formDataToJSON.js safe The file contains only a utility function that converts FormData objects to JSON, with proper prototype pollution protection and no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or network activity.
lib/helpers/formDataToStream.js safe No malicious patterns detected
lib/helpers/fromDataURI.js safe The code is a standard data URI parser for Axios and contains no malicious patterns such as data exfiltration, obfuscation, or unauthorized system access.
lib/helpers/isAbsoluteURL.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/isAxiosError.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/isURLSameOrigin.js safe No malicious patterns detected; the code implements a standard same-origin URL check using the browser URL API.
lib/helpers/null.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/parseHeaders.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/parseProtocol.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/progressEventReducer.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/readBlob.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/resolveConfig.js safe No malicious patterns detected
lib/helpers/speedometer.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/spread.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/throttle.js safe Cleared by Jev triage; no further analysis needed
lib/helpers/toFormData.js safe No malicious patterns detected; the file is a standard Axios utility for converting objects to FormData with no network, filesystem, or process manipulation.
lib/helpers/toURLEncodedForm.js safe No malicious patterns detected; the file is a legitimate form-data serialization helper that converts data to URL-encoded form format with a standard Buffer-to-base64 visitor for Node.js.
lib/helpers/trackStream.js safe No malicious patterns detected; the code is a legitimate stream chunking and progress-tracking utility with no external communication, credential harvesting, or dynamic execution.
lib/helpers/validator.js safe Cleared by Jev triage; no further analysis needed
lib/platform/browser/classes/Blob.js safe Cleared by Jev triage; no further analysis needed
lib/platform/browser/classes/FormData.js safe Cleared by Jev triage; no further analysis needed
lib/platform/browser/classes/URLSearchParams.js safe Cleared by Jev triage; no further analysis needed
lib/platform/browser/index.js safe Cleared by Jev triage; no further analysis needed
lib/platform/common/utils.js safe Cleared by Jev triage; no further analysis needed
lib/platform/index.js safe Cleared by Jev triage; no further analysis needed
lib/platform/node/classes/FormData.js safe Cleared by Jev triage; no further analysis needed
lib/platform/node/classes/URLSearchParams.js safe Cleared by Jev triage; no further analysis needed
lib/platform/node/index.js safe Cleared by Jev triage; no further analysis needed
lib/utils.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 3 scanned versions of axios are flagged high or critical. The latest scanned version, 1.20.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.12.21.20.0
VersionsVerdictCountRangeTop findings
1.20.0 No issues 1 1.20.0
1.18.1 Not scanned 1 1.18.1
1.13.1 โ€“ 1.13.2 No issues 2 >=1.13.1 <=1.13.2
1.12.2 Not scanned 1 1.12.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of axios

VersionVerdictFilesScanned
1.20.0 No issues 70 Oct 6, 2026
1.13.2 No issues 64 Oct 4, 2026
1.13.1 No issues 64 May 15, 2026

Frequently asked questions

Is axios safe to use?

Our AI source review of axios@1.13.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does axios contain malware?

No malware was identified in axios@1.13.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was axios checked?

Togoder Security downloaded the published npm package and had an AI model read its 64 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan axios together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in axios@1.13.2, cost nothing.

Related security reports