# date-fns@2.30.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:26:05.000Z
- Files reviewed: 2172
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/date-fns@2.30.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package date-fns@2.30.0 on Oct 4, 2026. An AI review of 2172 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Module side effects

Finding ID: `NPS-CB2604FBD2BA`

File: `addHours/index.js:3`

The file contains top-level code that executes at import time (Object.defineProperty and module exports assignment). While standard for transpiled CommonJS modules, it is technically import-time execution.

### [low] Dynamic module loading

Finding ID: `NPS-733ACF0B6A8D`

File: `addHours/index.js:6`

Uses require() with relative paths for internal dependencies. These paths are static and relative, not computed or external input, so risk is minimal.

## Files reviewed

- `addHours/index.js` (medium): This appears to be a legitimate date-fns 'addHours' utility with no malicious patterns; only benign import-time module initialization is present.
- `_lib/addLeadingZeros/index.js` (safe): No malicious patterns detected
- `_lib/assign/index.js` (safe): No malicious patterns detected
- `_lib/cloneObject/index.js` (safe): No malicious patterns detected
- `_lib/defaultLocale/index.js` (safe): No malicious patterns detected
- `_lib/defaultOptions/index.js` (safe): No malicious patterns detected
- `_lib/format/formatters/index.js` (safe): No malicious patterns detected
- `_lib/format/lightFormatters/index.js` (safe): No malicious patterns detected; code is a legitimate date formatting module with no network, filesystem, process, or dynamic execution activity.
- `_lib/format/longFormatters/index.js` (safe): No malicious patterns detected
- `_lib/getTimezoneOffsetInMilliseconds/index.js` (safe): No malicious patterns detected; the file is a benign timezone-offset utility with no network, filesystem, process, or dynamic code execution behavior.
- `_lib/getUTCDayOfYear/index.js` (safe): No malicious patterns detected
- `_lib/getUTCISOWeek/index.js` (safe): No malicious patterns detected; the file only implements date utility logic using standard relative imports and pure functions.
- `_lib/getUTCISOWeekYear/index.js` (safe): No malicious patterns detected; this is a standard date utility function for calculating UTC ISO week years.
- `_lib/getUTCWeek/index.js` (safe): No malicious patterns detected
- `_lib/getUTCWeekYear/index.js` (safe): No malicious patterns detected; the code is a standard date utility function with only local requires and no network, filesystem, or process manipulation.
- `_lib/isSameUTCWeek/index.js` (safe): No malicious patterns detected
- `_lib/protectedTokens/index.js` (safe): This is a legitimate date-fns utility file that validates protected token names and throws descriptive errors, with no malicious or obfuscated behavior.
- `_lib/requiredArgs/index.js` (safe): No malicious patterns detected
- `_lib/roundingMethods/index.js` (safe): No malicious patterns detected; the code is a simple rounding method utility with no network, filesystem, process, or dynamic execution activity.
- `_lib/setUTCDay/index.js` (safe): No malicious patterns detected; this is a legitimate date utility from the date-fns library with no network, filesystem, or dynamic code execution behavior.
- `_lib/setUTCISODay/index.js` (safe): The code is a legitimate date utility function that manipulates dates without any malicious patterns.
- `_lib/setUTCISOWeek/index.js` (safe): No malicious patterns detected; the code is a standard date manipulation utility with no network, filesystem, process, or dynamic execution activity.
- `_lib/setUTCWeek/index.js` (safe): No malicious patterns detected
- `_lib/startOfUTCISOWeek/index.js` (safe): No malicious patterns detected; the file is a benign date utility function with standard imports and no external interactions.
- `_lib/startOfUTCISOWeekYear/index.js` (safe): No malicious patterns detected; the file is a standard date utility function with no network, filesystem, process, or dynamic execution behavior.
- `_lib/startOfUTCWeek/index.js` (safe): No malicious patterns detected; the code is a standard date utility function for calculating the start of the week in UTC.
- `_lib/startOfUTCWeekYear/index.js` (safe): No malicious patterns detected; the code is a standard date-fns utility for computing the start of a UTC week-year with no network, filesystem, process, or dynamic execution behavior.
- `_lib/toInteger/index.js` (safe): No malicious patterns detected in the toInteger utility function
- `add/index.js` (safe): No malicious patterns detected; this is a standard date manipulation utility from date-fns.
- `addBusinessDays/index.js` (safe): No malicious patterns detected; the code is a standard date utility function with no network, filesystem, process, or dynamic code execution activity.
- `addDays/index.js` (safe): No malicious patterns detected
- `addISOWeekYears/index.js` (safe): No malicious patterns detected; the file is a standard date-fns helper that only performs date arithmetic via internal relative imports.
- `addMilliseconds/index.js` (safe): No malicious patterns detected; the code is a standard date utility function from the date-fns library with no data exfiltration, obfuscation, or dynamic execution.
- `addMinutes/index.js` (safe): No malicious patterns detected
- `addMonths/index.js` (safe): No malicious patterns detected; the file is a standard date utility function from date-fns that performs no network, filesystem, process, or dynamic code operations.
- `addQuarters/index.js` (safe): No malicious patterns detected; the file is a standard date manipulation helper from date-fns with no network, filesystem, or process activity.
- `addSeconds/index.js` (safe): No malicious patterns detected
- `addWeeks/index.js` (safe): No malicious patterns detected; the code is a straightforward date manipulation utility with only local module requires and no network, file system, process, or dynamic code execution behavior.
- `addYears/index.js` (safe): No malicious patterns detected
- `areIntervalsOverlapping/index.js` (safe): No malicious patterns detected; the code is a standard date-fns interval comparison utility with no external network, filesystem, or process activity.
- `clamp/index.js` (safe): The code is a simple date clamping utility with no malicious patterns
- `closestIndexTo/index.js` (safe): No malicious patterns detected; the code is a standard date utility function.
- `closestTo/index.js` (safe): No malicious patterns detected
- `compareAsc/index.js` (safe): No malicious patterns detected; the file is a legitimate Babel-compiled date comparison utility from date-fns with standard imports and no suspicious behavior.
- `compareDesc/index.js` (safe): No malicious patterns detected; the file implements a pure date comparison utility with standard imports and no external I/O or dynamic execution.
- `constants/index.js` (safe): No malicious patterns detected
- `daysToWeeks/index.js` (safe): No malicious patterns detected
- `differenceInBusinessDays/index.js` (safe): No malicious patterns detected
- `differenceInCalendarDays/index.js` (safe): No malicious patterns detected
- `differenceInCalendarISOWeekYears/index.js` (safe): No malicious patterns detected; the file is a straightforward date utility from date-fns that only requires internal dependencies and performs arithmetic on ISO week years.
- `differenceInCalendarISOWeeks/index.js` (safe): No malicious patterns detected
- `differenceInCalendarMonths/index.js` (safe): No malicious patterns detected; the file is a simple date utility function from date-fns with only static relative requires.
- `differenceInCalendarQuarters/index.js` (safe): No malicious patterns detected
- `differenceInCalendarWeeks/index.js` (safe): No malicious patterns detected; the code is a standard date-fns utility for calculating calendar week differences.
- `differenceInCalendarYears/index.js` (safe): No malicious patterns detected
- `differenceInDays/index.js` (safe): No malicious patterns detected; the code is a standard date utility from the date-fns library with no network, file system, or dynamic execution behavior.
- `differenceInHours/index.js` (safe): No malicious patterns detected; the code is a legitimate date-fns module implementing differenceInHours.
- `differenceInISOWeekYears/index.js` (safe): No malicious patterns detected; the code is a standard date utility function from the date-fns library with no external calls, dynamic code execution, or suspicious behavior.
- `differenceInMilliseconds/index.js` (safe): No malicious patterns detected; the code is a simple date difference utility with no network, filesystem, process, or dynamic execution activity.
- `differenceInMinutes/index.js` (safe): No malicious patterns detected
- `differenceInMonths/index.js` (safe): No malicious patterns detected; this is a standard date-difference utility module from the date-fns library.
- `differenceInQuarters/index.js` (safe): No malicious patterns detected
- `differenceInSeconds/index.js` (safe): No malicious patterns detected
- `differenceInWeeks/index.js` (safe): No malicious patterns detected; the code is a standard date utility function with only local module imports and no suspicious behavior.
- `differenceInYears/index.js` (safe): No malicious patterns detected; the code is a standard date utility function from the date-fns library.
- `docs/.eslintrc.js` (safe): Cleared by Jev triage; no further analysis needed
- `docs/Day.js` (safe): Cleared by Jev triage; no further analysis needed
- `docs/Duration.js` (safe): Cleared by Jev triage; no further analysis needed
- `docs/Interval.js` (safe): Cleared by Jev triage; no further analysis needed
- `docs/Locale.js` (safe): Cleared by Jev triage; no further analysis needed
- `docs/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachDayOfInterval/index.js` (safe): No malicious patterns detected
- `eachHourOfInterval/index.js` (safe): No malicious patterns detected
- `eachMinuteOfInterval/index.js` (safe): No malicious patterns detected
- `eachMonthOfInterval/index.js` (safe): No malicious patterns detected; the code is a standard date-fns interval utility with no network, filesystem, process, or dynamic execution activity.
- `eachQuarterOfInterval/index.js` (safe): The file is a standard date-fns utility for computing quarters within an interval, with no malicious patterns detected.
- `eachWeekOfInterval/index.js` (safe): No malicious patterns detected
- `eachWeekendOfInterval/index.js` (safe): The code is a legitimate date utility that lists weekends within an interval, with no malicious patterns or suspicious behavior.
- `eachWeekendOfMonth/index.js` (safe): No malicious patterns detected
- `eachWeekendOfYear/index.js` (safe): No malicious patterns detected; the code is a straightforward date utility function with no network, filesystem, or dynamic execution behavior.
- `eachYearOfInterval/index.js` (safe): No malicious patterns detected; the module is a standard date-fns interval helper with only local date computation and no network, filesystem, process, or dynamic code execution behavior.
- `endOfDay/index.js` (safe): No malicious patterns detected
- `endOfDecade/index.js` (safe): No malicious patterns detected; the code is a standard date-fns utility function for computing the end of a decade.
- `endOfHour/index.js` (safe): No malicious patterns detected
- `endOfISOWeek/index.js` (safe): No malicious patterns detected
- `endOfISOWeekYear/index.js` (safe): No malicious patterns detected; the code is a legitimate date utility function from the date-fns library.
- `endOfMinute/index.js` (safe): No malicious patterns detected
- `endOfMonth/index.js` (safe): No malicious patterns detected; the code is a benign date utility function with no network, filesystem, process, or dynamic code execution behavior.
- `endOfQuarter/index.js` (safe): No malicious patterns detected; the file is a standard date utility implementing endOfQuarter with no network, filesystem, credential, or process activity.
- `endOfSecond/index.js` (safe): No malicious patterns detected; this is a benign date utility function from the date-fns library.
- `endOfToday/index.js` (safe): No malicious patterns detected
- `endOfTomorrow/index.js` (safe): No malicious patterns detected; the code is a simple, pure date utility function with no external interactions or suspicious behavior.
- `endOfWeek/index.js` (safe): No malicious patterns detected
- `endOfYear/index.js` (safe): No malicious patterns detected
- `endOfYesterday/index.js` (safe): No malicious patterns detected
- `esm/_lib/addLeadingZeros/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/assign/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/cloneObject/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/defaultLocale/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/defaultOptions/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/format/formatters/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/format/lightFormatters/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/format/longFormatters/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/getTimezoneOffsetInMilliseconds/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/getUTCDayOfYear/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/getUTCISOWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/getUTCISOWeekYear/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/getUTCWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/getUTCWeekYear/index.js` (safe): No malicious patterns detected in the date utility function; it only performs standard date calculations and option parsing without network, file system, or process access.
- `esm/_lib/isSameUTCWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/protectedTokens/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/requiredArgs/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/roundingMethods/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/setUTCDay/index.js` (safe): No malicious patterns detected
- `esm/_lib/setUTCISODay/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/setUTCISOWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/setUTCWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/startOfUTCISOWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/startOfUTCISOWeekYear/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_lib/startOfUTCWeek/index.js` (safe): No malicious patterns detected; the file is a standard date-fns utility for calculating the start of the UTC week with no network, filesystem, process, or dynamic code execution behavior.
- `esm/_lib/startOfUTCWeekYear/index.js` (safe): No malicious patterns detected; the code is a standard date utility function with no networking, filesystem, process, or dynamic execution behavior.
- `esm/_lib/toInteger/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/add/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addBusinessDays/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addDays/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addHours/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addISOWeekYears/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addMilliseconds/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addMinutes/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addMonths/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addQuarters/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addSeconds/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addWeeks/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/addYears/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/areIntervalsOverlapping/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/clamp/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/closestIndexTo/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/closestTo/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/compareAsc/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/compareDesc/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/constants/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/daysToWeeks/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInBusinessDays/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarDays/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarISOWeekYears/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarISOWeeks/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarMonths/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarQuarters/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarWeeks/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInCalendarYears/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInDays/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInHours/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInISOWeekYears/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInMilliseconds/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInMinutes/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInMonths/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInQuarters/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInSeconds/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInWeeks/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/differenceInYears/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachDayOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachHourOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachMinuteOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachMonthOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachQuarterOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachWeekOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachWeekendOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachWeekendOfMonth/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachWeekendOfYear/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eachYearOfInterval/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfDay/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfDecade/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfHour/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfISOWeek/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfISOWeekYear/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfMinute/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfMonth/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfQuarter/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfSecond/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfToday/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfTomorrow/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfWeek/index.js` (safe): No malicious patterns detected; the code is a standard date-fns utility that computes the end of a week with no network, filesystem, process, or dynamic code execution behavior.
- `esm/endOfYear/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/endOfYesterday/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/format/index.js` (safe): No malicious patterns detected; this is the legitimate date-fns format implementation with only date formatting logic and no network, filesystem, process, or dynamic execution activities.
- `esm/formatDistance/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatDistanceStrict/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatDistanceToNow/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatDistanceToNowStrict/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatDuration/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatISO/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatISO9075/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatISODuration/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatRFC3339/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatRFC7231/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/formatRelative/index.js` (safe): The code is a legitimate date-fns formatRelative module with no malicious patterns, performing only date calculations and locale formatting.
- `esm/fp/_lib/convertToFP/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/fp/add/index.js` (safe): The file is a simple auto-generated functional programming wrapper with no malicious patterns detected.
- `esm/fp/addBusinessDays/index.js` (safe): No malicious patterns detected; the file is a simple auto-generated functional programming wrapper with no external network, filesystem, or process activity.
- `esm/fp/addDays/index.js` (safe): No malicious patterns detected; this is a benign auto-generated functional programming wrapper for date addition.

## Version ranges

None of the 2 scanned versions of date-fns are flagged high or critical. The latest scanned version, 4.4.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.4.0 (`4.4.0`): medium (Dynamic DOM manipulation and script injection +3 more)
- 4.1.0 (`4.1.0`): not scanned
- 2.30.0 (`2.30.0`): medium

## Scanned versions

- [4.4.0](https://security.togoder.click/npm/date-fns@4.4.0): medium, 2026-10-06T14:15:51.000Z
- [2.30.0](https://security.togoder.click/npm/date-fns@2.30.0): medium, 2026-10-04T16:26:05.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
