Togoder security

npm package security report

commander@14.0.0 security report

No malicious code found.

No issues Version 14.0.0 Files reviewed 8 Size 124.0 KB Scanned

Summary

Togoder Security scanned the npm package commander@14.0.0 on Oct 4, 2026. An AI review of 8 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
4
low

Findings 4

low

child_process.spawn usage

NPS-F80E907CEC72

The code spawns child processes to execute subcommands (executable files or node) using childProcess.spawn. This is expected functionality of the Commander CLI library and is gated behind user-defined subcommands. No malicious intent observed; args are derived from parsed CLI input, not from external untrusted sources.

lib/command.js
low

process.exit calls

NPS-B076DF1D8A90

The code calls process.exit in various error/help flows. This is normal CLI library behavior, not a security concern.

lib/command.js
low

environment variable access

NPS-466BB8800C5B

The code reads NO_COLOR, FORCE_COLOR, CLICOLOR_FORCE for color detection, and supports option.envVar for reading configured env vars. These are standard, documented behaviors, not credential harvesting.

lib/command.js
low

fs.existsSync / fs.realpathSync

NPS-791EDF3549AF

File system checks are used to locate executable subcommands relative to the script path and to check for missing mandatory options. Scoped to expected CLI use, no exfiltration or writes outside package scope.

lib/command.js

Files reviewed

FileVerdictWhat the reviewer saw
esm.mjs safe Cleared by Jev triage; no further analysis needed
index.js safe Cleared by Jev triage; no further analysis needed
lib/argument.js safe Cleared by Jev triage; no further analysis needed
lib/command.js safe This is the legitimate Commander.js CLI library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or unauthorized code execution were detected.
lib/error.js safe Cleared by Jev triage; no further analysis needed
lib/help.js safe Cleared by Jev triage; no further analysis needed
lib/option.js safe Cleared by Jev triage; no further analysis needed
lib/suggestSimilar.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 5 scanned versions of commander are flagged high or critical. The latest scanned version, 15.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.20.315.0.0
VersionsVerdictCountRangeTop findings
15.0.0 Needs review 1 15.0.0
14.0.2 – 14.0.3 Not scanned 2 >=14.0.2 <=14.0.3
14.0.1 Needs review 1 14.0.1 process spawning
14.0.0 No issues 1 14.0.0
13.1.0 Not scanned 1 13.1.0
12.1.0 No issues 1 12.1.0
3.0.2 – 10.0.1 Not scanned 8 >=3.0.2 <=10.0.1
2.20.3 Needs review 1 2.20.3 process_spawning

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of commander

VersionVerdictFilesScanned
15.0.0 Needs review 7 Oct 6, 2026
14.0.1 Needs review 8 Oct 4, 2026
14.0.0 No issues 8 Oct 4, 2026
12.1.0 No issues 8 May 15, 2026
2.20.3 Needs review 1 Oct 4, 2026

Frequently asked questions

Is commander safe to use?

Our AI source review of commander@14.0.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does commander contain malware?

No malware was identified in commander@14.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was commander checked?

Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan commander together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in commander@14.0.0, cost nothing.

Related security reports