# depd@2.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T14:40:51.000Z
- Files reviewed: 2
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/depd
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package depd@2.0.0 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-C9542C6FF311`

File: `index.js:435`

The `wrapfunction` function uses `new Function()` to dynamically construct a wrapper function from string concatenation. While this is a legitimate pattern in the depd library for preserving function arity, dynamic code generation of this nature can be a vector for code injection if the input is untrusted. In this specific implementation, all interpolated values (args, which is derived from fn.length) are controlled and numeric, so the risk is low in context, but the pattern warrants flagging.

### [low] File system path exposure

Finding ID: `NPS-38FA718D12FC`

File: `index.js:22`

`basePath = process.cwd()` is captured at module load time and used with `path.relative` to format stack locations for deprecation warnings written to stderr. This is standard diagnostic behavior and does not exfiltrate or manipulate files.

### [low] Environment variable access

Finding ID: `NPS-43456D4B8993`

File: `index.js:185`

The `isignored` and `istraced` functions read `process.env.NO_DEPRECATION` and `process.env.TRACE_DEPRECATION`, and check `process.noDeprecation` and `process.traceDeprecation`. These are standard Node.js deprecation control variables used for legitimate configuration, not credential harvesting.

## Files reviewed

- `index.js` (medium): This is the well-known `depd` deprecation-warning utility; it uses `new Function` for arity-preserving wrappers (a common benign pattern) and reads standard deprecation env vars, with no evidence of exfiltration, credential theft, backdoors, or process spawning.
- `lib/browser/index.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
