# date-fns@4.4.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:15:51.000Z
- Files reviewed: 2555
- Findings: 4 medium, 31 low severity findings
- Report: https://security.togoder.click/npm/date-fns@4.4.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package date-fns@4.4.0 on Oct 6, 2026. An AI review of 2555 source files produced 4 medium, 31 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic DOM manipulation and script injection

Finding ID: `NPS-DC3209702477`

File: `_lib/cdnPolyfill.cjs`

The code uses document.write and template.innerHTML to inject and re-execute script tags dynamically. While the intent is a CDN URL migration polyfill, this pattern can be abused for script injection if the current script's HTML is manipulated or if the regex matches unexpected content. The regex only replaces '/date-fns/' with '/@date-fns/cdn/' in matched src attributes, but the dynamic insertion of scripts based on document.currentScript.outerHTML is a potentially risky pattern that could be leveraged in a supply-chain attack scenario.

### [medium] Use of document.write

Finding ID: `NPS-E76BE550981E`

File: `_lib/cdnPolyfill.cjs`

document.write is used to inject HTML content derived from the current script element. If the script's outerHTML is somehow tampered with (e.g., via DOM clobbering or prototype pollution), this could lead to unintended script execution. Modern best practices discourage document.write due to its security and performance implications.

### [medium] Dynamic code execution / DOM manipulation

Finding ID: `NPS-B6F6783073DB`

File: `_lib/cdnPolyfill.js:12`

The script uses document.write with data derived from document.currentScript.outerHTML. If an attacker can control or inject content into the script tag's outerHTML (e.g., via a compromised CDN or DOM clobbering), this could lead to XSS or arbitrary script injection. However, the regex strictly limits replacement to date-fns CDN URLs, mitigating direct exploitation.

### [medium] Potential script injection via insertScriptFromHTML

Finding ID: `NPS-3BD40BE12C70`

File: `_lib/cdnPolyfill.js:23`

The fallback function insertScriptFromHTML creates a new script element from the HTML and appends it to the head. While it copies attributes and does not directly set innerHTML on the new script, the source HTML is derived from outerHTML of the current script. If an attacker can influence the script tag's attributes or content, this could execute arbitrary JavaScript.

### [low] Use of document.write

Finding ID: `NPS-74588C404AFB`

File: `_lib/cdnPolyfill.js:12`

document.write can be dangerous as it may overwrite the entire document if called after page load, and can be used for XSS if the written content is not properly sanitized. Here, the content is conditionally derived from the script's own outerHTML via a regex, which limits the risk.

### [low] obsolete CDN warning

Finding ID: `NPS-8B374A44CDC1`

File: `locale/ar-DZ/cdn.js:389`

The file logs a message that date-fns CDN files have moved to @date-fns/cdn, which is a legitimate deprecation notice, not a malicious pattern.

### [low] Informational

Finding ID: `NPS-BF7315460DD2`

File: `locale/ar-MA/cdn.js`

The file is a date-fns locale bundle for Moroccan Arabic (ar-MA). It only contains locale data, formatting/parsing functions, and attaches the locale to window.dateFns. No network, filesystem, process, eval, or credential-access behavior is present. The console.log is a deprecation notice about CDN URL migration, not exfiltration.

### [low] informational

Finding ID: `NPS-E2394C860D05`

File: `locale/be/cdn.js`

The code is a standard date-fns locale bundle for Belarusian. It contains only locale data, formatting/parsing helpers, and a console.log notice about CDN URL migration. No network, filesystem, process, credential, or dynamic execution patterns are present.

### [low] Console warning message

Finding ID: `NPS-4576E765055D`

File: `locale/bg/cdn.js`

The script prints a deprecation notice to the console indicating CDN files have moved to @date-fns/cdn. This is a benign informational message, not a security concern.

### [low] Deprecation Notice

Finding ID: `NPS-32A639337EC8`

File: `locale/bs/cdn.js`

The code logs a deprecation warning about CDN files moving to @date-fns/cdn. This is not malicious but indicates the package is outdated.

### [low] informational

Finding ID: `NPS-12CE7D0C5997`

File: `locale/en-CA/cdn.js:1`

The code modifies the global window.dateFns object to register the en-CA locale. This is expected behavior for a date-fns CDN locale file and is not malicious.

### [low] console logging / deprecation notice

Finding ID: `NPS-312EFE90917B`

File: `locale/en-US/cdn.js`

The file logs a deprecation notice to the console, which is benign and expected for a CDN build artifact.

### [low] Console message

Finding ID: `NPS-2B1442DFCA8D`

File: `locale/fa-IR/cdn.js`

A console.log message at the end of the file informs users that date-fns CDN files have moved and provides a URL for updated information. This is benign and likely intended as a migration notice.

### [low] deprecation notice

Finding ID: `NPS-60D92B453B32`

File: `locale/hu/cdn.js`

Contains a console.log deprecation notice and a CDN migration message, which is informational and not malicious.

### [low] Install/import-time code execution

Finding ID: `NPS-66A976547B89`

File: `locale/hy/cdn.js`

The IIFE executes at import time and mutates the global `window.dateFns` object, attaching the `hy` locale. While this is normal for a CDN bundle, top-level code that runs on import is a category worth noting.

### [low] Console warning / deprecation notice

Finding ID: `NPS-86DB2BFAD061`

File: `locale/hy/cdn.js`

The script logs a message stating CDN files have moved to @date-fns/cdn. This is benign but indicates stale distribution behavior that could be replaced with a redirect.

### [low] Console warning message

Finding ID: `NPS-727EA80D09C5`

File: `locale/id/cdn.js`

The code logs a deprecation warning about CDN files moving to @date-fns/cdn. This is benign informational output.

### [low] Informational console logging

Finding ID: `NPS-4ADB33DB7CC3`

File: `locale/is/cdn.js`

A console.log message about CDN URL migration is present. This is benign and intended to inform developers about updated CDN URLs.

### [low] Install-time code execution

Finding ID: `NPS-2BCE43F70492`

File: `locale/is/cdn.js:1`

The IIFE runs immediately upon import/load and attaches date-fns locale data to window.dateFns. This is expected behavior for CDN distribution files and does not perform malicious actions.

### [low] Non-malicious global assignment

Finding ID: `NPS-65F9C5BE0936`

File: `locale/ja-Hira/cdn.js:392`

The code assigns a locale object to window.dateFns at import time, which is expected behavior for a CDN build. It does so by merging with any existing window.dateFns.locale object. This is not data exfiltration or backdoor behavior, but it does mutate the global namespace on import, which could have side effects if other code relies on the same global.

### [low] Warning message on import

Finding ID: `NPS-0488CD5CAC98`

File: `locale/ja-Hira/cdn.js:396`

The code logs a deprecation warning that the CDN files have moved to @date-fns/cdn, advising users to update their URLs. This is benign and intended to inform users of a package relocation.

### [low] informational

Finding ID: `NPS-14B1C8F6F003`

File: `locale/ja/cdn.js`

The file registers a Japanese locale on the global window.dateFns object and logs a deprecation notice. This is expected behavior for a CDN distribution file and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or dynamic code execution.

### [low] Informational - Deprecation Notice

Finding ID: `NPS-442EBE8EE84A`

File: `locale/ko/cdn.js`

The code logs a console message indicating that date-fns CDN files have moved to @date-fns/cdn. This is a benign informational message, not a security concern.

### [low] CDN deprecation notice

Finding ID: `NPS-8CBB540AB380`

File: `locale/lt/cdn.js`

The file ends with console.log instructing users to migrate to @date-fns/cdn. This is a benign informational message from the library maintainers, not a security concern.

### [low] Console Warning Message

Finding ID: `NPS-0357FB648455`

File: `locale/mn/cdn.js`

The code logs a deprecation warning to the console indicating that CDN files have moved. This is not malicious and is common for maintaining backwards compatibility.

### [low] informational

Finding ID: `NPS-0F0CC5C1E87D`

File: `locale/sr/cdn.js`

This is a legitimate date-fns locale file for Serbian (Cyrillic) localization. It contains only locale data (strings, format patterns, match patterns) and pure helper functions for date formatting/parsing. The IIFE at the top is Babel-generated helper boilerplate for object spread. The only side effect is assigning to window.dateFns.locale.sr, which is the intended CDN behavior for this library. The console.log at the end is a deprecation notice pointing users to the new @date-fns/cdn package. No network requests, no filesystem access, no eval/Function constructors, no process spawning, no credential harvesting, no obfuscation.

### [low] Deprecation notice

Finding ID: `NPS-38436148B311`

File: `locale/sv/cdn.js`

The code logs a deprecation message indicating CDN files have moved to @date-fns/cdn, which is informational and not malicious.

### [low] console output on import

Finding ID: `NPS-3546661C7EF9`

File: `locale/ta/cdn.js`

The script logs a deprecation notice to the console at the top level, which executes on import. This is benign informational output and does not perform any sensitive actions.

### [low] global window mutation

Finding ID: `NPS-E10707214C37`

File: `locale/ta/cdn.js`

The script attaches the 'ta' locale object onto window.dateFns at load time. This is expected behavior for a CDN locale bundle and does not exfiltrate data or execute untrusted code.

### [low] Top-level code execution on import

Finding ID: `NPS-599A1E5B740B`

File: `locale/uk/cdn.js`

The file executes an IIFE immediately upon being loaded. At the end, it assigns the 'uk' locale into the global window.dateFns object. This is expected for a CDN locale bundle but constitutes top-level code that mutates global state at import time.

### [low] Console output / informational message

Finding ID: `NPS-DFB7BFF87339`

File: `locale/uk/cdn.js`

The script logs a deprecation notice to the console ('date-fns CDN files have moved to @date-fns/cdn...'). This is benign but illustrates that the file performs side effects at load time, which could be abused in modified versions.

### [low] Dead/obfuscated numeric expression

Finding ID: `NPS-735417471837`

File: `locale/uk/cdn.js`

An expression `-(Math.pow(10, 8) * 24 * 60 * 60 * 1e3);` appears standalone near the constructFromSymbol definition. It computes a constant (milliseconds in 10^8 days) but is unused. This kind of stray expression is often characteristic of code that has been mangled or that hides values; it is not malicious here but is a minor code-smell worth noting.

### [low] Information Disclosure

Finding ID: `NPS-3F93779B3CCD`

File: `locale/vi/cdn.js:723`

The code uses console.log to display a deprecation notice. This is a benign informational message, not a security risk, but it logs to the console without user control.

### [low] Informational

Finding ID: `NPS-203941696E48`

File: `locale/zh-CN/cdn.js`

Deprecation notice logged to console indicating CDN files moved to @date-fns/cdn; not malicious, just a migration message.

### [low] Deprecation Notice

Finding ID: `NPS-50C7B4D459A6`

File: `locale/zh-TW/cdn.js`

The file logs a message indicating that date-fns CDN files have moved to @date-fns/cdn, advising users to update their URLs. This is informational and not a security risk.

## Files reviewed

- `_lib/cdnPolyfill.cjs` (medium): The code is a CDN URL migration polyfill that dynamically rewrites and re-injects script tags; while not overtly malicious, it uses risky dynamic script injection patterns that warrant caution.
- `_lib/cdnPolyfill.js` (medium): The code appears to be a legitimate CDN migration polyfill for date-fns, but it uses potentially risky DOM manipulation techniques (document.write, dynamic script insertion) that could be exploited if an attacker controls the script's outerHTML.
- `locale/hy/cdn.js` (medium): The file is a standard date-fns Armenian locale CDN bundle that only sets localization data and a global namespace, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution.
- `locale/uk/cdn.js` (medium): The file is a legitimate date-fns Ukrainian locale CDN bundle with expected global window.dateFns mutation and console notice; no malicious exfiltration, credential harvesting, command execution, or obfuscated payloads were found.
- `_lib/addLeadingZeros.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/addLeadingZeros.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/defaultLocale.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/defaultLocale.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/defaultOptions.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/defaultOptions.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/format/formatters.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/format/formatters.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/format/lightFormatters.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/format/lightFormatters.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/format/longFormatters.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/format/longFormatters.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/getRoundingMethod.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/getRoundingMethod.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/getTimezoneOffsetInMilliseconds.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/getTimezoneOffsetInMilliseconds.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/normalizeDates.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/normalizeDates.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/normalizeInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/normalizeInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/protectedTokens.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/protectedTokens.js` (safe): Cleared by Jev triage; no further analysis needed
- `_lib/test.cjs` (safe): No malicious patterns detected; the file contains test helper functions for date manipulation and type assertion.
- `_lib/test.js` (safe): No malicious patterns detected; the file contains only standard test utilities for date/timezone handling and fake timers.
- `add.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `add.js` (safe): Cleared by Jev triage; no further analysis needed
- `addBusinessDays.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addBusinessDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `addDays.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `addHours.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addHours.js` (safe): Cleared by Jev triage; no further analysis needed
- `addISOWeekYears.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addISOWeekYears.js` (safe): Cleared by Jev triage; no further analysis needed
- `addMilliseconds.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addMilliseconds.js` (safe): Cleared by Jev triage; no further analysis needed
- `addMinutes.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addMinutes.js` (safe): Cleared by Jev triage; no further analysis needed
- `addMonths.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addMonths.js` (safe): Cleared by Jev triage; no further analysis needed
- `addQuarters.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addQuarters.js` (safe): Cleared by Jev triage; no further analysis needed
- `addSeconds.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addSeconds.js` (safe): Cleared by Jev triage; no further analysis needed
- `addWeeks.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addWeeks.js` (safe): Cleared by Jev triage; no further analysis needed
- `addYears.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `addYears.js` (safe): Cleared by Jev triage; no further analysis needed
- `areIntervalsOverlapping.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `areIntervalsOverlapping.js` (safe): Cleared by Jev triage; no further analysis needed
- `clamp.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `clamp.js` (safe): Cleared by Jev triage; no further analysis needed
- `closestIndexTo.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `closestIndexTo.js` (safe): Cleared by Jev triage; no further analysis needed
- `closestTo.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `closestTo.js` (safe): Cleared by Jev triage; no further analysis needed
- `compareAsc.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `compareAsc.js` (safe): Cleared by Jev triage; no further analysis needed
- `compareDesc.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `compareDesc.js` (safe): Cleared by Jev triage; no further analysis needed
- `constants.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `constructFrom.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `constructFrom.js` (safe): Cleared by Jev triage; no further analysis needed
- `constructNow.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `constructNow.js` (safe): Cleared by Jev triage; no further analysis needed
- `daysToWeeks.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `daysToWeeks.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInBusinessDays.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInBusinessDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarDays.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarISOWeekYears.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarISOWeekYears.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarISOWeeks.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarISOWeeks.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarMonths.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarMonths.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarQuarters.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarQuarters.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarWeeks.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarWeeks.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarYears.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInCalendarYears.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInDays.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInHours.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInHours.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInISOWeekYears.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInISOWeekYears.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInMilliseconds.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInMilliseconds.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInMinutes.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInMinutes.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInMonths.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInMonths.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInQuarters.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInQuarters.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInSeconds.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInSeconds.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInWeeks.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInWeeks.js` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInYears.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `differenceInYears.js` (safe): Cleared by Jev triage; no further analysis needed
- `docs/config.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachDayOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachDayOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachHourOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachHourOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachMinuteOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachMinuteOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachMonthOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachMonthOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachQuarterOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachQuarterOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekendOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekendOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekendOfMonth.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekendOfMonth.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekendOfYear.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachWeekendOfYear.js` (safe): Cleared by Jev triage; no further analysis needed
- `eachYearOfInterval.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `eachYearOfInterval.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfDay.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfDay.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfDecade.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfDecade.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfHour.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfHour.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfISOWeek.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfISOWeek.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfISOWeekYear.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfISOWeekYear.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfMinute.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfMinute.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfMonth.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfMonth.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfQuarter.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfQuarter.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfSecond.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfSecond.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfToday.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfToday.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfTomorrow.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfTomorrow.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfWeek.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfWeek.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfYear.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfYear.js` (safe): Cleared by Jev triage; no further analysis needed
- `endOfYesterday.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `endOfYesterday.js` (safe): Cleared by Jev triage; no further analysis needed
- `format.cjs` (safe): No malicious patterns detected; the code is a standard date-fns format module with only internal relative imports and no external network, filesystem, or process activity.
- `format.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistance.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistance.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistanceStrict.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistanceStrict.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistanceToNow.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistanceToNow.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistanceToNowStrict.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatDistanceToNowStrict.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatDuration.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatDuration.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatISO.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatISO.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatISO9075.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatISO9075.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatISODuration.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatISODuration.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatRFC3339.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatRFC3339.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatRFC7231.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatRFC7231.js` (safe): Cleared by Jev triage; no further analysis needed
- `formatRelative.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `formatRelative.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp.js` (safe): No malicious patterns detected
- `fp/_lib/convertToFP.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `fp/_lib/convertToFP.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/add.cjs` (safe): No malicious patterns detected; the file is a simple auto-generated functional programming wrapper for the add utility.
- `fp/add.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/addBusinessDays.cjs` (safe): No malicious patterns detected
- `fp/addBusinessDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/addBusinessDaysWithOptions.cjs` (safe): No malicious patterns detected; this is a simple auto-generated functional programming wrapper for addBusinessDays.
- `fp/addBusinessDaysWithOptions.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/addDays.cjs` (safe): No malicious patterns detected
- `fp/addDays.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/addDaysWithOptions.cjs` (safe): No malicious patterns detected; the file is a simple generated wrapper that converts addDays to a functional programming variant.
- `fp/addDaysWithOptions.js` (safe): No malicious patterns detected; the file is a simple auto-generated functional programming wrapper that imports addDays and convertToFP without any suspicious behavior.
- `fp/addHours.cjs` (safe): No malicious patterns detected
- `fp/addHours.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/addHoursWithOptions.cjs` (safe): No malicious patterns detected
- `fp/addHoursWithOptions.js` (safe): Cleared by Jev triage; no further analysis needed
- `fp/addISOWeekYears.cjs` (safe): No malicious patterns detected; the file is a simple auto-generated functional programming wrapper around an internal date utility.
- `fp/addISOWeekYears.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of date-fns are flagged high or critical. The latest scanned version, 4.4.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.4.0 (`4.4.0`): medium (Dynamic DOM manipulation and script injection +3 more)
- 4.1.0 (`4.1.0`): not scanned
- 2.30.0 (`2.30.0`): medium

## Scanned versions

- [4.4.0](https://security.togoder.click/npm/date-fns@4.4.0): medium, 2026-10-06T14:15:51.000Z
- [2.30.0](https://security.togoder.click/npm/date-fns@2.30.0): medium, 2026-10-04T16:26:05.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
