# cross-fetch@3.2.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:19:54.000Z
- Files reviewed: 7
- Findings: no findings
- Report: https://security.togoder.click/npm/cross-fetch@3.2.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package cross-fetch@3.2.0 on Oct 4, 2026. An AI review of 7 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/browser-polyfill.js` (safe): No malicious patterns detected; this is a standard whatwg-fetch browser polyfill with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `dist/browser-ponyfill.js` (safe): This is the legitimate cross-fetch ponyfill that patches the global object to provide a fetch polyfill; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution were detected.
- `dist/cross-fetch.js` (safe): No malicious patterns detected; this is a standard cross-fetch polyfill implementing fetch/XHR/Headers/Request/Response without any data exfiltration, obfuscation, or unauthorized system access.
- `dist/node-polyfill.js` (safe): No malicious patterns detected; the code is a standard polyfill that conditionally assigns fetch-related globals.
- `dist/node-ponyfill.js` (safe): No malicious patterns detected
- `dist/react-native-polyfill.js` (safe): The file contains only a license header comment and no executable code or suspicious patterns.
- `dist/react-native-ponyfill.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of cross-fetch are flagged high or critical. The latest scanned version, 4.1.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.1.0 (`4.1.0`): clean
- 4.0.0 (`4.0.0`): not scanned
- 3.2.0 (`3.2.0`): clean

## Scanned versions

- [4.1.0](https://security.togoder.click/npm/cross-fetch@4.1.0): safe, 2026-10-04T16:22:21.000Z
- [3.2.0](https://security.togoder.click/npm/cross-fetch@3.2.0): safe, 2026-10-04T16:19:54.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
