Togoder security

npm package security report

dayjs@1.11.13 security report

Risky patterns found that deserve a look.

Needs review Version 1.11.13 Files reviewed 364 Size 497.9 KB Scanned

Summary

Togoder Security scanned the npm package dayjs@1.11.13 on Oct 4, 2026. An AI review of 364 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
3
low

Findings 5

medium

Prototype pollution / mutation

NPS-091779B21B3C

The plugin intentionally mutates the prototype of the Day.js library (n.$g, n.set, n.startOf, n.add, n.locale, n.daysInMonth, n.isSame, n.isBefore, n.isAfter). While this is the stated purpose of a 'badMutable' plugin, monkey-patching core library methods can introduce unexpected behavior and potential security risks if these methods are used in security-sensitive contexts (e.g., date validation, token expiry checks).

plugin/badMutable.js:1
medium

Top-level side effects

NPS-635F912DCA02

The code executes immediately upon import and modifies global/prototype behavior of the Day.js library without explicit user opt-in beyond installing the plugin. This could affect other code relying on Day.js immutability.

plugin/badMutable.js:1
low

Unsafe dynamic constructor invocation

NPS-50DA6880678E

Uses Function.prototype.bind.apply(Date, [null].concat(date)) to construct a Date instance. While this pattern is often used to support a variable number of arguments to Date's constructor, it relies on dynamic function construction semantics that are occasionally seen in obfuscated or evasive code. In this context the target is Date (not eval/Function for arbitrary code), and the input is the plugin's own 'date' array, so it is not remote code execution, but it is an unnecessarily obscure and fragile construct that could mask malicious intent if altered.

esm/plugin/arraySupport/index.js:22
low

dynamic code execution

NPS-495CA1B032FE

The code uses Function.prototype.bind.apply(Date, [null].concat(t)) as a way to dynamically construct Date objects. While this is not eval, it dynamically invokes the Date constructor with a variable number of arguments derived from user input. However, this is a known idiom for spreading arguments and not an injection vector by itself, as Date is a built-in. Still, it is a form of dynamic invocation that could be flagged in a strict security review.

plugin/arraySupport.js:1
low

monkey-patching

NPS-9918DBF42852

The plugin overrides the parse method of the Day.js prototype. This is a common plugin pattern but means any code using Day.js after this plugin loads will have its parsing behavior altered. This could be abused by a malicious plugin to intercept or modify date parsing globally, though no data exfiltration or other malicious behavior is present here.

plugin/arraySupport.js:1

Files reviewed

FileVerdictWhat the reviewer saw
esm/plugin/arraySupport/index.js medium No exfiltration, credential harvesting, mining, backdoors, process spawning, or install-time execution was found; the only notable concern is a non-standard dynamic Date construction idiom that carries low risk.
plugin/arraySupport.js medium The code is a legitimate Day.js plugin for array-based date parsing; it uses Function.prototype.bind.apply for argument spreading, which is not malicious, but the dynamic invocation and prototype patching warrant a low-severity warning.
plugin/badMutable.js medium The plugin is not overtly malicious but mutates the Day.js prototype at import time, which could cause unintended side effects or weaken date-related security assumptions in consuming applications.
esm/constant.js safe Cleared by Jev triage; no further analysis needed
esm/index.js safe No malicious patterns detected
esm/locale/af.js safe No malicious patterns detected
esm/locale/am.js safe No malicious patterns detected
esm/locale/ar-dz.js safe No malicious patterns detected
esm/locale/ar-iq.js safe This is a standard Arabic (Iraq) locale configuration file for the dayjs library with no malicious patterns detected.
esm/locale/ar-kw.js safe No malicious patterns detected
esm/locale/ar-ly.js safe No malicious patterns detected; the file is a standard dayjs locale definition.
esm/locale/ar-ma.js safe No malicious patterns detected; file is a standard dayjs locale definition with only static data and pure functions.
esm/locale/ar-sa.js safe No malicious patterns detected; this is a legitimate dayjs locale definition for Arabic (Saudi Arabia) containing only static translation strings and simple formatting functions.
esm/locale/ar-tn.js safe No malicious patterns detected; the file is a standard Day.js Arabic (Tunisia) locale definition with static translations and no network, filesystem, process, or dynamic execution behavior.
esm/locale/ar.js safe No malicious patterns detected; the file is a standard dayjs Arabic locale definition with no network, filesystem, process, or dynamic code execution behavior.
esm/locale/az.js safe No malicious patterns detected
esm/locale/be.js safe No malicious patterns detected; this is a standard dayjs locale definition file for Belarusian with only static locale data and a benign ordinal function.
esm/locale/bg.js safe No malicious patterns detected; this is a standard dayjs Bulgarian locale file with no network, filesystem, process, or dynamic execution behavior.
esm/locale/bi.js safe No malicious patterns detected; this is a standard dayjs locale definition file for Bislama.
esm/locale/bm.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Bambara containing only static localization data and a locale registration call.
esm/locale/bn-bd.js safe No malicious patterns detected; this is a standard dayjs locale file with only string replacement and locale configuration logic.
esm/locale/bn.js safe No malicious patterns detected
esm/locale/bo.js safe No malicious patterns detected; this is a legitimate Day.js Tibetan locale file with static translations and no dynamic behavior.
esm/locale/br.js safe No malicious patterns detected
esm/locale/bs.js safe No malicious patterns detected
Show 339 more files
FileVerdictWhat the reviewer saw
esm/locale/ca.js safe No malicious patterns detected
esm/locale/cs.js safe No malicious patterns detected
esm/locale/cv.js safe No malicious patterns detected
esm/locale/cy.js safe No malicious patterns detected
esm/locale/da.js safe This is a standard Day.js locale definition file for Danish with no malicious patterns, network calls, or dynamic code execution.
esm/locale/de-at.js safe This is a standard Day.js locale definition file for German (Austria) with no malicious patterns, external calls, or dynamic code execution.
esm/locale/de-ch.js safe No malicious patterns detected; this is a legitimate dayjs locale definition file with only static strings and a simple formatter.
esm/locale/de.js safe This is a standard Day.js German locale file with no malicious patterns, network calls, process spawning, or obfuscated code.
esm/locale/dv.js safe This is a standard dayjs locale definition file for Dhivehi with no malicious patterns, no external calls, and no dynamic code execution.
esm/locale/el.js safe No malicious patterns detected
esm/locale/en-au.js safe No malicious patterns detected; this is a standard dayjs locale definition file for English (Australia) with no network, filesystem, process, or dynamic code execution behavior.
esm/locale/en-ca.js safe No malicious patterns detected
esm/locale/en-gb.js safe No malicious patterns detected; the file is a standard dayjs locale definition with no network, filesystem, process execution, or dynamic code evaluation.
esm/locale/en-ie.js safe This is a standard dayjs locale definition file for English (Ireland) with no malicious patterns detected.
esm/locale/en-il.js safe This is a standard Day.js locale definition file containing only static translation strings and formatting configuration with no malicious patterns.
esm/locale/en-in.js safe No malicious patterns detected
esm/locale/en-nz.js safe No malicious patterns detected
esm/locale/en-sg.js safe No malicious patterns detected
esm/locale/en-tt.js safe No malicious patterns detected; the file is a standard dayjs locale definition with no network, filesystem, process, or dynamic code execution behavior.
esm/locale/en.js safe Cleared by Jev triage; no further analysis needed
esm/locale/eo.js safe No malicious patterns detected; the file is a legitimate dayjs Esperanto locale definition with only static data and a simple ordinal function.
esm/locale/es-do.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Spanish (Dominican Republic).
esm/locale/es-mx.js safe No malicious patterns detected
esm/locale/es-pr.js safe No malicious patterns detected in the dayjs locale file
esm/locale/es-us.js safe No malicious patterns detected
esm/locale/es.js safe No malicious patterns detected; this is a standard dayjs Spanish locale definition file.
esm/locale/et.js safe No malicious patterns detected; the file is a standard dayjs locale definition with no network, filesystem, process, or obfuscated code.
esm/locale/eu.js safe No malicious patterns detected
esm/locale/fa.js safe This is a standard dayjs locale definition file for Persian with no malicious patterns, network activity, dynamic code execution, or suspicious behavior.
esm/locale/fi.js safe No malicious patterns detected; this is a standard dayjs locale file for Finnish.
esm/locale/fo.js safe No malicious patterns detected; the file is a standard dayjs Faroese locale definition with no network, filesystem, process, or dynamic code execution behavior.
esm/locale/fr-ca.js safe No malicious patterns detected; the file is a standard French (Canada) locale definition for dayjs.
esm/locale/fr-ch.js safe No malicious patterns detected; the file is a standard Day.js locale definition containing only static translation data and a simple ordinal function.
esm/locale/fr.js safe No malicious patterns detected
esm/locale/fy.js safe No malicious patterns detected; this is a legitimate dayjs locale definition file for Frisian.
esm/locale/ga.js safe No malicious patterns detected
esm/locale/gd.js safe This is a standard dayjs locale definition file for Scottish Gaelic with no malicious patterns, network calls, file access, or dynamic code execution.
esm/locale/gl.js safe This is a legitimate dayjs Galician locale file with only static translations, no network, filesystem, process, or dynamic code execution patterns.
esm/locale/gom-latn.js safe No malicious patterns detected
esm/locale/gu.js safe No malicious patterns detected
esm/locale/he.js safe No malicious patterns detected
esm/locale/hi.js safe No malicious patterns detected; this is a standard dayjs Hindi locale definition file.
esm/locale/hr.js safe No malicious patterns detected
esm/locale/ht.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Haitian Creole.
esm/locale/hu.js safe No malicious patterns detected
esm/locale/hy-am.js safe No malicious patterns detected
esm/locale/id.js safe The file is a standard Day.js Indonesian locale definition with no malicious patterns, network activity, dynamic code execution, or filesystem access.
esm/locale/is.js safe No malicious patterns detected
esm/locale/it-ch.js safe No malicious patterns detected; this is a standard dayjs locale definition file with no network, filesystem, or dynamic execution activity.
esm/locale/it.js safe No malicious patterns detected; the file is a standard dayjs Italian locale definition with only static data and a trivial ordinal formatter.
esm/locale/ja.js safe No malicious patterns detected; the file is a standard dayjs Japanese locale definition with no network, filesystem, process, or dynamic code execution behavior.
esm/locale/jv.js safe No malicious patterns detected
esm/locale/ka.js safe This is a standard dayjs locale definition file for Georgian with no malicious patterns, network activity, or dynamic code execution.
esm/locale/kk.js safe No malicious patterns detected; file is a standard dayjs Kazakh locale definition with only static data and a locale registration call.
esm/locale/km.js safe This is a standard Day.js locale definition file for Cambodian (km) with no malicious patterns, network activity, or dynamic code execution.
esm/locale/kn.js safe No malicious patterns detected in this localization file for the dayjs library.
esm/locale/ko.js safe No malicious patterns detected
esm/locale/ku.js safe No malicious patterns detected; this is a standard dayjs Kurdish locale file with only string localization and number formatting logic.
esm/locale/ky.js safe No malicious patterns detected
esm/locale/lb.js safe No malicious patterns detected
esm/locale/lo.js safe No malicious patterns detected; the file is a standard dayjs Lao locale definition with only static locale data and a locale registration call.
esm/locale/lt.js safe No malicious patterns detected
esm/locale/lv.js safe No malicious patterns detected
esm/locale/me.js safe No malicious patterns detected
esm/locale/mi.js safe No malicious patterns detected; this is a standard Day.js Maori locale definition file with static data and no network, filesystem, or code execution behavior.
esm/locale/mk.js safe This is a standard dayjs locale definition file for Macedonian with no malicious patterns, network calls, or dynamic code execution.
esm/locale/ml.js safe No malicious patterns detected
esm/locale/mn.js safe No malicious patterns detected
esm/locale/mr.js safe No malicious patterns detected
esm/locale/ms-my.js safe No malicious patterns detected
esm/locale/ms.js safe No malicious patterns detected; this is a standard Day.js Malay locale definition file with no network, file system, process, or dynamic code execution activity.
esm/locale/mt.js safe No malicious patterns detected; this is a standard dayjs locale definition file with no network, filesystem, or dynamic execution activity.
esm/locale/my.js safe No malicious patterns detected
esm/locale/nb.js safe No malicious patterns detected
esm/locale/ne.js safe No malicious patterns detected
esm/locale/nl-be.js safe This is a standard Day.js locale definition file for Dutch (Belgium) containing only static translation strings and formatting rules with no malicious patterns.
esm/locale/nl.js safe No malicious patterns detected in this standard dayjs Dutch locale file
esm/locale/nn.js safe No malicious patterns detected
esm/locale/oc-lnc.js safe No malicious patterns detected
esm/locale/pa-in.js safe No malicious patterns detected
esm/locale/pl.js safe No malicious patterns detected
esm/locale/pt-br.js safe This is a standard locale file for the dayjs library containing only Portuguese (Brazil) translations and no malicious patterns.
esm/locale/pt.js safe No malicious patterns detected
esm/locale/rn.js safe No malicious patterns detected; this is a standard dayjs locale definition file with no data exfiltration, dynamic code execution, or suspicious behavior.
esm/locale/ro.js safe No malicious patterns detected; the file is a standard dayjs Romanian locale definition with only static data and locale registration.
esm/locale/ru.js safe No malicious patterns detected in the Russian locale file for dayjs; it contains only locale-specific date formatting data and functions.
esm/locale/rw.js safe No malicious patterns detected
esm/locale/sd.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Sindhi with no network, file system, process, or dynamic execution activity.
esm/locale/se.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Northern Sami with only static data and locale registration.
esm/locale/si.js safe No malicious patterns detected; the file is a standard Day.js Sinhalese locale definition with no network, filesystem, credential, or dynamic execution activity.
esm/locale/sk.js safe The file is a standard dayjs Slovak locale definition with no malicious patterns, network calls, credential access, dynamic code execution, or install-time hooks.
esm/locale/sl.js safe No malicious patterns detected
esm/locale/sq.js safe No malicious patterns detected
esm/locale/sr-cyrl.js safe No malicious patterns detected
esm/locale/sr.js safe No malicious patterns detected; the file is a standard Day.js Serbian locale definition with no network, filesystem, process, or dynamic code execution activity.
esm/locale/ss.js safe No malicious patterns detected
esm/locale/sv-fi.js safe No malicious patterns detected
esm/locale/sv.js safe This is a standard dayjs Swedish locale file with no suspicious behavior; it only defines locale data and registers it via dayjs.locale().
esm/locale/sw.js safe No malicious patterns detected
esm/locale/ta.js safe No malicious patterns detected
esm/locale/te.js safe No malicious patterns detected
esm/locale/tet.js safe No malicious patterns detected
esm/locale/tg.js safe No malicious patterns detected
esm/locale/th.js safe No malicious patterns detected; this is a standard dayjs Thai locale definition file with only static data and a locale registration call.
esm/locale/tk.js safe No malicious patterns detected
esm/locale/tl-ph.js safe No malicious patterns detected
esm/locale/tlh.js safe No malicious patterns detected
esm/locale/tr.js safe No malicious patterns detected; the file is a standard dayjs Turkish locale definition with no network, filesystem, process, or dynamic code execution behavior.
esm/locale/tzl.js safe No malicious patterns detected
esm/locale/tzm-latn.js safe This is a standard dayjs locale definition file containing only static translation strings and configuration; no malicious patterns detected.
esm/locale/tzm.js safe No malicious patterns detected; the file is a standard dayjs locale definition with static data and no dangerous operations.
esm/locale/ug-cn.js safe No malicious patterns detected
esm/locale/uk.js safe No malicious patterns detected
esm/locale/ur.js safe No malicious patterns detected
esm/locale/uz-latn.js safe No malicious patterns detected
esm/locale/uz.js safe No malicious patterns detected
esm/locale/vi.js safe No malicious patterns detected; this is a standard dayjs Vietnamese locale file containing only static translations and configuration.
esm/locale/x-pseudo.js safe This is a standard dayjs locale definition file with static string data, no malicious patterns, network calls, dynamic execution, or filesystem access detected.
esm/locale/yo.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Yoruba.
esm/locale/zh-cn.js safe No malicious patterns detected
esm/locale/zh-hk.js safe No malicious patterns detected; this is a standard dayjs locale definition for Chinese (Hong Kong) with only static string data and locale callbacks.
esm/locale/zh-tw.js safe No malicious patterns detected
esm/locale/zh.js safe No malicious patterns detected; this is a standard Day.js Chinese locale definition file with no network, file system, process, or obfuscated code.
esm/plugin/advancedFormat/index.js safe No malicious patterns detected; the code only extends date formatting with replacement tokens and performs no network, file, process, or credential operations.
esm/plugin/badMutable/index.js safe No malicious patterns detected; the code only patches dayjs prototype methods for mutable behavior, with no network, filesystem, process, or dynamic code execution activity.
esm/plugin/bigIntSupport/index.js safe No malicious patterns detected; the code is a legitimate dayjs plugin that adds BigInt date support with no exfiltration, obfuscation, or system access.
esm/plugin/buddhistEra/index.js safe No malicious patterns detected; the code is a benign dayjs plugin for Buddhist Era calendar formatting, with no network, filesystem, process, or dynamic execution activity.
esm/plugin/calendar/index.js safe The code is a standard Day.js calendar plugin implementation with no malicious patterns such as data exfiltration, obfuscation, or dynamic execution.
esm/plugin/customParseFormat/index.js safe No malicious patterns detected
esm/plugin/dayOfYear/index.js safe This is a clean day-of-year plugin for Day.js with no malicious patterns, external calls, or dangerous operations.
esm/plugin/devHelper/index.js safe No malicious patterns detected; the code only adds development-time console warnings for date parsing and locale usage.
esm/plugin/duration/index.js safe No malicious patterns detected
esm/plugin/isBetween/index.js safe No malicious patterns detected
esm/plugin/isLeapYear/index.js safe The code is a simple, non-malicious addition of an isLeapYear method to a prototype, with no suspicious patterns or security concerns.
esm/plugin/isMoment/index.js safe No malicious patterns detected
esm/plugin/isSameOrAfter/index.js safe No malicious patterns detected; the file defines a simple date-comparison plugin method with no network, filesystem, process, or dynamic execution activity.
esm/plugin/isSameOrBefore/index.js safe No malicious patterns detected
esm/plugin/isToday/index.js safe No malicious patterns detected
esm/plugin/isTomorrow/index.js safe No malicious patterns detected
esm/plugin/isYesterday/index.js safe No malicious patterns detected
esm/plugin/isoWeek/index.js safe No malicious patterns detected; the code implements ISO week date calculations as a standard date library plugin.
esm/plugin/isoWeeksInYear/index.js safe No malicious patterns detected
esm/plugin/localeData/index.js safe The code is a standard locale data plugin for Day.js and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution.
esm/plugin/localizedFormat/index.js safe No malicious patterns detected
esm/plugin/localizedFormat/utils.js safe No malicious patterns detected; the code only performs string formatting and regex replacement for date/time localization.
esm/plugin/minMax/index.js safe No malicious patterns detected; the code is a legitimate dayjs plugin for computing min/max dates.
esm/plugin/negativeYear/index.js safe No malicious patterns detected; the code is a legitimate Day.js plugin for parsing negative year dates.
esm/plugin/objectSupport/index.js safe No malicious patterns detected; the code is a legitimate dayjs plugin for object-based date manipulation.
esm/plugin/pluralGetSet/index.js safe No malicious patterns detected; the code simply adds plural aliases to prototype methods for a date library plugin.
esm/plugin/preParsePostFormat/index.js safe No malicious patterns detected; the code is a legitimate day.js plugin that safely overrides parse and format methods to apply locale-specific preprocessing and postformatting.
esm/plugin/quarterOfYear/index.js safe No malicious patterns detected
esm/plugin/relativeTime/index.js safe No malicious patterns detected; this is a legitimate relative time plugin for the Day.js library.
esm/plugin/timezone/index.js safe This is a legitimate Day.js timezone plugin implementation that uses standard Intl.DateTimeFormat APIs with no malicious patterns detected.
esm/plugin/toArray/index.js safe No malicious patterns detected; the code only adds a toArray method to a prototype.
esm/plugin/toObject/index.js safe The code is a simple plugin that adds a toObject method to a prototype, returning date components, with no malicious patterns detected.
esm/plugin/updateLocale/index.js safe No malicious patterns detected
esm/plugin/utc/index.js safe The code is a legitimate Day.js UTC plugin that performs date/time calculations and formatting, with no malicious patterns or security concerns.
esm/plugin/weekOfYear/index.js safe This Day.js plugin implements week-of-year calculation logic using inherited library methods, with no network, filesystem, process, or dynamic code execution patterns.
esm/plugin/weekYear/index.js safe No malicious patterns detected
esm/plugin/weekday/index.js safe No malicious patterns detected; the code is a benign dayjs plugin that adds a weekday method to the library's prototype.
esm/utils.js safe Cleared by Jev triage; no further analysis needed
locale/af.js safe No malicious patterns detected
locale/am.js safe No malicious patterns detected; the file is a standard Day.js Amharic locale definition with no network, filesystem, or execution risks.
locale/ar-dz.js safe No malicious patterns detected; this is a standard Day.js locale definition for Arabic (Algeria) with only static locale data and a UMD wrapper.
locale/ar-iq.js safe No malicious patterns detected
locale/ar-kw.js safe This is a standard Day.js Arabic (Kuwait) locale file containing only translation strings and date formatting logic, with no malicious patterns detected.
locale/ar-ly.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Arabic (Libya).
locale/ar-ma.js safe No malicious patterns detected; this is a standard Day.js Arabic (Morocco) locale file containing only static localization data and a UMD wrapper.
locale/ar-sa.js safe No malicious patterns detected; the file is a standard Day.js Arabic (Saudi Arabia) locale definition with no suspicious network, filesystem, process, or obfuscated code.
locale/ar-tn.js safe No malicious patterns detected
locale/ar.js safe No malicious patterns detected
locale/az.js safe No malicious patterns detected
locale/be.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Belarusian.
locale/bg.js safe No malicious patterns detected
locale/bi.js safe No malicious patterns detected; the file is a standard Day.js locale definition for the Bislama language.
locale/bm.js safe This is a standard Day.js locale file for the Bambara language containing only translation strings and no executable malicious code.
locale/bn-bd.js safe This is a legitimate Day.js locale definition for Bengali (Bangladesh) with no malicious patterns, network activity, or code execution beyond standard locale setup.
locale/bn.js safe No malicious patterns detected; this is a standard dayjs Bengali locale file with only localization data and character conversion functions.
locale/bo.js safe This is a standard Day.js locale definition file containing Tibetan (bo) translations with no malicious patterns or security concerns.
locale/br.js safe No malicious patterns detected; this is a standard dayjs Breton locale file with no network, filesystem, or code execution risks.
locale/bs.js safe No malicious patterns detected
locale/ca.js safe No malicious patterns detected
locale/cs.js safe No malicious patterns detected; this is a standard Day.js locale file for Czech language support.
locale/cv.js safe This is a legitimate Day.js locale file for the Chuvash language, containing only static locale data and standard module export logic with no malicious patterns.
locale/cy.js safe No malicious patterns detected
locale/da.js safe The file is a standard Day.js Danish locale definition with no malicious patterns, obfuscation, or security concerns.
locale/de-at.js safe No malicious patterns detected; the file is a standard Day.js locale definition for German (Austria) with no network, filesystem, process, or dynamic code execution activity.
locale/de-ch.js safe This is a standard Day.js locale definition file for Swiss German (de-ch) with no malicious patterns, no network activity, no dynamic code execution, and no filesystem or process manipulation.
locale/de.js safe No malicious patterns detected
locale/dv.js safe No malicious patterns detected; this is a standard dayjs locale definition file for Dhivehi (dv) containing only locale data and UMD boilerplate.
locale/el.js safe No malicious patterns detected
locale/en-au.js safe No malicious patterns detected
locale/en-ca.js safe No malicious patterns detected
locale/en-gb.js safe No malicious patterns detected; the file is a standard Day.js locale definition for en-gb with no network, filesystem, process, or dynamic code execution behavior.
locale/en-ie.js safe No malicious patterns detected; this is a standard Day.js locale definition file for English (Ireland).
locale/en-il.js safe No malicious patterns detected
locale/en-in.js safe No malicious patterns detected; the file is a standard dayjs locale definition for English (India).
locale/en-nz.js safe No malicious patterns detected
locale/en-sg.js safe No malicious patterns detected; the file is a standard Day.js locale definition containing only static configuration and formatting strings.
locale/en-tt.js safe No malicious patterns detected
locale/en.js safe No malicious patterns detected
locale/eo.js safe This is a standard dayjs Esperanto locale file (eo.js) that only defines locale data with no malicious patterns, network requests, filesystem access, or dynamic code execution.
locale/es-do.js safe No malicious patterns detected
locale/es-mx.js safe No malicious patterns detected
locale/es-pr.js safe No malicious patterns detected
locale/es-us.js safe This is a standard Day.js locale definition file containing only language strings and date formatting rules, with no malicious patterns detected.
locale/es.js safe This is a standard Day.js Spanish locale file with no malicious patterns, network calls, or suspicious behavior.
locale/et.js safe This is a standard dayjs Estonian locale file with no malicious patterns detected.
locale/eu.js safe No malicious patterns detected; the file is a standard Day.js Basque locale definition with only static data and no network, filesystem, or code execution behavior.
locale/fa.js safe No malicious patterns detected; the file is a standard Day.js locale definition for Persian (Farsi).
locale/fi.js safe No malicious patterns detected in this standard Day.js Finnish locale file.
locale/fo.js safe No malicious patterns detected
locale/fr-ca.js safe No malicious patterns detected
locale/fr-ch.js safe No malicious patterns detected; the file is a legitimate Day.js locale definition for French (Switzerland).
locale/fr.js safe No malicious patterns detected; this is a standard Day.js French locale file containing only locale data and registration code.
locale/fy.js safe This is a standard Day.js locale definition for Western Frisian with no malicious patterns, network activity, or dynamic code execution.
locale/ga.js safe No malicious patterns detected
locale/gd.js safe This is a standard dayjs Scottish Gaelic locale file with no malicious patterns; it only defines locale data and registers it with dayjs.
locale/gl.js safe No malicious patterns detected
locale/gom-latn.js safe This is a legitimate Day.js locale file for the Goan Konkani (Latin script) language containing only month/day names and formatting strings, with no malicious patterns.
locale/gu.js safe No malicious patterns detected; this is a standard Day.js Gujarati locale definition file with no executable, network, filesystem, or environment-harvesting behavior.
locale/he.js safe This is a standard Day.js Hebrew locale file with no malicious patterns; it only defines locale strings and registers the locale.
locale/hi.js safe No malicious patterns detected; this is a standard Day.js locale file for Hindi with no obfuscation, network requests, or suspicious behavior.
locale/hr.js safe No malicious patterns detected; this is a standard Day.js Croatian locale file with only localization data and safe module export logic.
locale/ht.js safe No malicious patterns detected
locale/hu.js safe No malicious patterns detected
locale/hy-am.js safe No malicious patterns detected; this is a legitimate Day.js Armenian locale file containing only language definitions and locale registration.
locale/id.js safe This is a legitimate Day.js Indonesian locale file containing only static translation strings and locale configuration; no malicious patterns detected.
locale/is.js safe This is a standard Day.js Icelandic locale file containing only date/time formatting strings and functions, with no malicious patterns detected.
locale/it-ch.js safe No malicious patterns detected; the file is a standard Day.js locale definition for Italian (Switzerland) with no network, filesystem, or code execution activity.
locale/it.js safe The file is a standard dayjs Italian locale definition with no obfuscation, network access, filesystem manipulation, or other malicious patterns.
locale/ja.js safe This is a standard dayjs Japanese locale definition file with no malicious patterns, network calls, or dynamic code execution.
locale/jv.js safe No malicious patterns detected; this is a standard dayjs Javanese locale file with only static locale data.
locale/ka.js safe No malicious patterns detected
locale/kk.js safe No malicious patterns detected; this is a standard Day.js Kazakh locale file with no external data access, code execution, or network activity.
locale/km.js safe The code is a standard dayjs locale definition for Khmer (km) with no malicious patterns such as data exfiltration, obfuscation, dynamic execution, network activity, or process spawning.
locale/kn.js safe No malicious patterns detected
locale/ko.js safe No malicious patterns detected
locale/ku.js safe This is a legitimate Day.js locale file for Kurdish (ku) containing only date formatting, numeral conversion, and localization logic with no malicious patterns.
locale/ky.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Kyrgyz with no network, filesystem, or code execution activity.
locale/lb.js safe This is a standard Day.js locale definition file for Luxembourgish with no malicious patterns, network requests, credential access, or dynamic code execution.
locale/lo.js safe No malicious patterns detected
locale/lt.js safe No malicious patterns detected; this is a standard Day.js Lithuanian locale file that only defines date/time formatting strings and registers itself with dayjs.
locale/lv.js safe No malicious patterns detected
locale/me.js safe No malicious patterns detected; the file is a standard Day.js locale definition for Montenegrin with no data exfiltration, dynamic code execution, network calls, or process spawning.
locale/mi.js safe No malicious patterns detected in this dayjs Maori locale file; it is a standard UMD module with static locale data.
locale/mk.js safe No malicious patterns detected; this is a standard Day.js Macedonian locale file with no obfuscation, network access, or lifecycle scripts.
locale/ml.js safe No malicious patterns detected
locale/mn.js safe No malicious patterns detected
locale/mr.js safe No malicious patterns detected
locale/ms-my.js safe No malicious patterns detected; the file is a standard Day.js Malay locale definition with no network, filesystem, or dynamic code execution behavior.
locale/ms.js safe This is a standard Day.js Malay locale file with no malicious patterns; it only defines locale strings and registers them with Day.js.
locale/mt.js safe This is a standard Day.js Maltese locale definition file with no malicious patterns or security concerns.
locale/my.js safe No malicious patterns detected; this is a standard dayjs locale definition file for Burmese (my) with no network, filesystem, or execution behaviors.
locale/nb.js safe No malicious patterns detected; this is a standard Day.js locale definition for Norwegian Bokmål.
locale/ne.js safe No malicious patterns detected; this is a legitimate Day.js Nepali locale definition file with standard UMD module loading and locale data only.
locale/nl-be.js safe No malicious patterns detected; this is a standard dayjs locale definition file.
locale/nl.js safe No malicious patterns detected; this is a standard Day.js Dutch locale file that only defines localization strings and registers the locale.
locale/nn.js safe No malicious patterns detected; this is a standard Day.js locale file for Norwegian Nynorsk with no obfuscation, network requests, filesystem access, or dynamic code execution.
locale/oc-lnc.js safe No malicious patterns detected; this is a standard Day.js locale file containing only static translation data and initialization logic.
locale/pa-in.js safe This is a standard dayjs Punjabi (India) locale file containing only static translation strings and no malicious patterns.
locale/pl.js safe This is a standard Day.js Polish locale file with no malicious patterns, no network or file system access, and no dynamic code execution.
locale/pt-br.js safe No malicious patterns detected; the file is a standard Day.js locale module for Brazilian Portuguese.
locale/pt.js safe No malicious patterns detected
locale/rn.js safe This is a legitimate Day.js locale file for Kinyarwanda (Rwanda) with no malicious patterns detected.
locale/ro.js safe No malicious patterns detected; this is a standard Day.js locale definition file for Romanian.
locale/ru.js safe No malicious patterns detected; this is a legitimate Day.js Russian locale file.
locale/rw.js safe No malicious patterns detected
locale/sd.js safe No malicious patterns detected in the dayjs Sindhi locale file; it only defines locale data and registers it with dayjs.
locale/se.js safe No malicious patterns detected; the file is a standard dayjs locale definition for Northern Sami with only static data and no network, filesystem, or dynamic code execution.
locale/si.js safe No malicious patterns detected; this is a standard Day.js Sinhala locale file with only static locale data and no network, filesystem, or execution behavior.
locale/sk.js safe No malicious patterns detected
locale/sl.js safe No malicious patterns detected
locale/sq.js safe No malicious patterns detected; the file is a standard Day.js locale definition for Albanian with no network, filesystem, or execution risks.
locale/sr-cyrl.js safe This is a legitimate Day.js locale file for Serbian Cyrillic containing only translation strings and date formatting logic with no malicious patterns.
locale/sr.js safe No malicious patterns detected
locale/ss.js safe No malicious patterns detected; this is a standard Day.js locale file for Siswati (ss) containing only translation strings and locale configuration.
locale/sv-fi.js safe This is a standard Day.js locale definition file for Swedish (Finland) with no malicious patterns, network activity, or code execution beyond the expected UMD module wrapper.
locale/sv.js safe No malicious patterns detected; this is a standard dayjs locale definition file for Swedish.
locale/sw.js safe No malicious patterns detected
locale/ta.js safe No malicious patterns detected; this is a standard Day.js Tamil locale file with no network, filesystem, process, or dynamic execution concerns.
locale/te.js safe No malicious patterns detected
locale/tet.js safe No malicious patterns detected; this is a standard Day.js locale definition file with no network, filesystem, or code execution activity.
locale/tg.js safe No malicious patterns detected; this is a standard Day.js locale definition file for Tajik that only registers locale strings and performs no network, filesystem, or process operations.
locale/th.js safe No malicious patterns detected
locale/tk.js safe This is a standard dayjs locale definition file for Turkmen (tk) with no malicious patterns detected; it contains only locale data and standard UMD module boilerplate.
locale/tl-ph.js safe No malicious patterns detected; this is a standard Day.js Philippine Tagalog locale definition with no data exfiltration, process spawning, file system access, or dynamic code execution.
locale/tlh.js safe This is a standard Day.js Klingon (tlh) locale file with only static translation strings and no malicious patterns.
locale/tr.js safe No malicious patterns detected
locale/tzl.js safe No malicious patterns detected; the file only defines a Day.js locale for the Tzl language.
locale/tzm-latn.js safe No malicious patterns detected; file is a legitimate dayjs locale definition.
locale/tzm.js safe No malicious patterns detected
locale/ug-cn.js safe No malicious patterns detected; this is a standard dayjs locale file for Uyghur (China).
locale/uk.js safe This is a standard Day.js Ukrainian locale file with no malicious patterns.
locale/ur.js safe This is a standard Day.js Urdu locale file containing only translation strings and no malicious patterns.
locale/uz-latn.js safe No malicious patterns detected; the file is a standard Day.js locale definition for Uzbek (Latin) with no network, filesystem, process, or dynamic code execution behavior.
locale/uz.js safe This is a standard dayjs Uzbek locale definition file with no malicious patterns, network activity, credential access, or dynamic code execution.
locale/vi.js safe No malicious patterns detected
locale/x-pseudo.js safe No malicious patterns detected
locale/yo.js safe No malicious patterns detected; this is a standard Day.js locale file for Yoruba with no network, filesystem, or dynamic code execution activity.
locale/zh-cn.js safe This is a legitimate dayjs locale file for Simplified Chinese containing only static translation strings and date formatting logic, with no malicious patterns detected.
locale/zh-hk.js safe No malicious patterns detected
locale/zh-tw.js safe No malicious patterns detected; this is a standard Day.js locale file for Traditional Chinese with only static locale data and no network, filesystem, or code execution behavior.
locale/zh.js safe No malicious patterns detected in this Day.js Chinese locale file; it only contains standard locale data and module boilerplate.
plugin/advancedFormat.js safe No malicious patterns detected
plugin/bigIntSupport.js safe No malicious patterns detected; the plugin only adds BigInt support to Day.js parsing and unix timestamp methods.
plugin/buddhistEra.js safe The plugin code is a small, minified Day.js extension for Buddhist Era formatting with no suspicious patterns or behaviors.
plugin/calendar.js safe The code is a standard Day.js calendar plugin with no malicious patterns, no network activity, no environment access, and no dynamic code execution.
plugin/customParseFormat.js safe No malicious patterns detected
plugin/dayOfYear.js safe No malicious patterns detected; the code is a legitimate dayjs plugin that adds a dayOfYear method without any obfuscation, network access, or file system interaction.
plugin/devHelper.js safe No malicious patterns detected; the code is a legitimate development helper plugin for dayjs that only adds console warnings in non-production environments.
plugin/duration.js safe The code is a legitimate Day.js duration plugin with no malicious patterns, network calls, filesystem access, or dynamic code execution.
plugin/isBetween.js safe This is a legitimate Day.js plugin implementing the isBetween date comparison method with no malicious patterns detected.
plugin/isLeapYear.js safe The file is a benign Day.js plugin that adds an isLeapYear method with no network, filesystem, or execution related activity.
plugin/isMoment.js safe No malicious patterns detected; the code is a standard UMD wrapper for a Day.js plugin that only checks if an object is a Day.js instance.
plugin/isSameOrAfter.js safe The plugin is a standard dayjs extension that adds an isSameOrAfter method with no malicious behavior, external communication, or dynamic code execution.
plugin/isSameOrBefore.js safe This is a standard Day.js plugin that adds an isSameOrBefore method with no malicious patterns detected.
plugin/isToday.js safe No malicious patterns detected
plugin/isTomorrow.js safe No malicious patterns detected; the file only defines a Day.js plugin for checking tomorrow's date.
plugin/isYesterday.js safe No malicious patterns detected; the file is a legitimate Day.js plugin extending functionality with no suspicious behavior.
plugin/isoWeek.js safe No malicious patterns detected; the code is a standard Day.js ISO week plugin with no network, filesystem, or dynamic execution concerns.
plugin/isoWeeksInYear.js safe No malicious patterns detected
plugin/localeData.js safe No malicious patterns detected; the code is a standard Day.js localeData plugin with no network, filesystem, process execution, or obfuscation concerns.
plugin/localizedFormat.js safe No malicious patterns detected; the code is a legitimate Day.js plugin for localized formatting.
plugin/minMax.js safe No malicious patterns detected; the code is a standard dayjs min/max plugin with no network, filesystem, process, or dynamic code execution activity.
plugin/negativeYear.js safe No malicious patterns detected; the code is a legitimate Day.js plugin for handling negative years.
plugin/objectSupport.js safe No malicious patterns detected; the code is a legitimate Day.js plugin extending object support for date parsing and manipulation.
plugin/pluralGetSet.js safe No malicious patterns detected; the code is a benign Day.js plugin that aliases plural getter/setter methods to their singular counterparts.
plugin/preParsePostFormat.js safe No malicious patterns detected; the code is a legitimate dayjs plugin that wraps locale-based pre-parse and post-format hooks without any data exfiltration, obfuscation, network access, or filesystem/process manipulation.
plugin/quarterOfYear.js safe No malicious patterns detected
plugin/relativeTime.js safe No malicious patterns detected; the code is the standard dayjs relativeTime plugin implementing localization and time formatting without any network, filesystem, or process execution behavior.
plugin/timezone.js safe No malicious patterns detected; the code is a legitimate Day.js timezone plugin using standard Intl APIs without any exfiltration, obfuscation, or suspicious behavior.
plugin/toArray.js safe No malicious patterns detected
plugin/toObject.js safe No malicious patterns detected
plugin/updateLocale.js safe This is a legitimate Day.js plugin for updating locale definitions with no malicious patterns, network activity, credential access, or code execution.
plugin/utc.js safe No malicious patterns detected; the code is a legitimate Day.js UTC plugin with standard date manipulation logic and no network, filesystem, or execution-related security concerns.
plugin/weekOfYear.js safe No malicious patterns detected; the code is a legitimate Day.js plugin implementing ISO week-of-year functionality with no network, filesystem, or process access.
plugin/weekYear.js safe The code is a standard Day.js plugin implementing ISO week-year calculation with a UMD wrapper and no malicious patterns.
plugin/weekday.js safe No malicious patterns detected

Frequently asked questions

Is dayjs safe to use?

No confirmed malware was found in dayjs@1.11.13, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does dayjs contain malware?

No malware was identified in dayjs@1.11.13 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was dayjs checked?

Togoder Security downloaded the published npm package and had an AI model read its 364 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan dayjs together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in dayjs@1.11.13, cost nothing.

Related security reports