# engine.io-client@6.6.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:28:16.000Z
- Files reviewed: 55
- Findings: 1 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/engine.io-client
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package engine.io-client@6.6.3 on Oct 4, 2026. An AI review of 55 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic code execution

Finding ID: `NPS-44D2A017A41A`

File: `build/cjs/globals.js:18`

The globalThisShim uses `Function('return this')()` to obtain the global object when `self` and `window` are undefined. While this is a common JavaScript polyfill pattern, it relies on dynamic function construction, which can be problematic in environments with strict Content Security Policy (CSP) and is sometimes used to obscure execution context. It is not an outright malicious payload, but it is a notable red flag.

### [low] empty function definition

Finding ID: `NPS-A961CA268C62`

File: `build/cjs/globals.js:23`

createCookieJar is declared but contains no implementation. This is not inherently malicious, but could indicate incomplete or placeholder code. It is not a security concern on its own.

### [low] Dynamic code execution

Finding ID: `NPS-343454B9FA50`

File: `build/esm-debug/globals.js:16`

Uses Function("return this")() to evaluate code dynamically. While this is a common pattern to obtain the global object in environments without 'self' or 'window' (e.g., some JavaScript engines), it is a potential red flag because dynamic code execution via Function constructor can be used for obfuscation or exploitation if the input were ever variable or tainted. Here the string is hardcoded and benign, but it is worth noting as a pattern that can mask malicious intent in other contexts.

### [low] Empty function definition

Finding ID: `NPS-BDF825038780`

File: `build/esm-debug/globals.js:21`

The createCookieJar function is defined but empty, which is unusual. In some packages, stub implementations can be placeholders for functionality that is later replaced or monkey-patched. However, in this isolated file there is no evidence of malicious behavior; it is likely an incomplete or intentionally empty utility.

### [low] No malicious patterns

Finding ID: `NPS-2B6DC317B591`

File: `build/esm-debug/transports/polling-xhr.js`

The code is part of the engine.io-client library and implements XHR polling transport for Socket.IO. It uses standard XMLHttpRequest APIs, has no dynamic code execution (no eval/new Function), no child_process/shell usage, no file system access outside browser context, no credential/secret harvesting, no cryptocurrency mining or wallet draining, and no data exfiltration to unexpected endpoints. Network requests target the configured Socket.IO server URI as expected for the library's purpose.

### [low] Dynamic code execution

Finding ID: `NPS-343454B9FA50`

File: `build/esm/globals.js:16`

Uses Function("return this")() to evaluate code dynamically. While this is a common pattern to obtain the global object in environments without 'self' or 'window' (e.g., some JavaScript engines), it is a potential red flag because dynamic code execution via Function constructor can be used for obfuscation or exploitation if the input were ever variable or tainted. Here the string is hardcoded and benign, but it is worth noting as a pattern that can mask malicious intent in other contexts.

### [low] Empty function definition

Finding ID: `NPS-BDF825038780`

File: `build/esm/globals.js:21`

The createCookieJar function is defined but empty, which is unusual. In some packages, stub implementations can be placeholders for functionality that is later replaced or monkey-patched. However, in this isolated file there is no evidence of malicious behavior; it is likely an incomplete or intentionally empty utility.

## Files reviewed

- `build/cjs/globals.js` (medium): This file contains a dynamic Function constructor for global object shimming, which is a mild security concern, but no data exfiltration, credential harvesting, or network/process activity was found.
- `build/esm-debug/globals.js` (medium): The code uses the Function constructor for global object detection and contains an empty cookie jar stub, but no clear malicious patterns such as data exfiltration, credential harvesting, or backdoor installation were found.
- `build/esm/globals.js` (medium): The code uses the Function constructor for global object detection and contains an empty cookie jar stub, but no clear malicious patterns such as data exfiltration, credential harvesting, or backdoor installation were found.
- `build/cjs/browser-entrypoint.js` (safe): No malicious patterns detected
- `build/cjs/contrib/has-cors.js` (safe): No malicious patterns detected; the code only performs a feature-detection check for XMLHttpRequest CORS support.
- `build/cjs/contrib/parseqs.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/cjs/contrib/parseuri.js` (safe): The code is a legitimate URI parser with no malicious patterns, network calls, credential harvesting, or dynamic execution.
- `build/cjs/globals.node.js` (safe): No malicious patterns detected; the code is a standard cookie parsing and jar implementation for Node.js HTTP clients.
- `build/cjs/index.js` (safe): No malicious patterns detected; this is a standard barrel file re-exporting socket.io-client modules.
- `build/cjs/socket.js` (safe): This is the legitimate engine.io-client Socket implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, backdoors, or suspicious process/network activity.
- `build/cjs/transport.js` (safe): No malicious patterns detected in the provided Transport base class implementation from engine.io-client.
- `build/cjs/transports/index.js` (safe): No malicious patterns detected
- `build/cjs/transports/polling-fetch.js` (safe): No malicious patterns detected; the code implements a standard fetch-based HTTP long-polling transport with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/cjs/transports/polling-xhr.js` (safe): This is the standard engine.io-client XHR polling transport implementation with no malicious patterns detected.
- `build/cjs/transports/polling-xhr.node.js` (safe): No malicious patterns detected; the code is a standard TypeScript-compiled CommonJS module implementing XMLHttpRequest-based polling transport for Socket.IO.
- `build/cjs/transports/polling.js` (safe): This file is a standard engine.io-client polling transport implementation with no malicious patterns, obfuscation, data exfiltration, or suspicious behavior detected.
- `build/cjs/transports/websocket.js` (safe): This file is a legitimate engine.io-client WebSocket transport implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution.
- `build/cjs/transports/websocket.node.js` (safe): No malicious patterns detected; the file is a standard WebSocket transport implementation using the 'ws' package with expected cookie handling and compression logic.
- `build/cjs/transports/webtransport.js` (safe): This is a legitimate WebTransport transport implementation for engine.io-client with no malicious patterns detected.
- `build/cjs/util.js` (safe): No malicious patterns detected; the code contains only benign utility functions for object picking, timer installation, byte length calculation, and random string generation.
- `build/esm-debug/browser-entrypoint.js` (safe): No malicious patterns detected
- `build/esm-debug/contrib/has-cors.js` (safe): No malicious patterns detected; the code is a straightforward feature-detection snippet for CORS support in browsers.
- `build/esm-debug/contrib/parseqs.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/esm-debug/contrib/parseuri.js` (safe): No malicious patterns detected; the code is a standard URI parser with no network, filesystem, process execution, or obfuscation concerns.
- `build/esm-debug/globals.node.js` (safe): No malicious patterns detected; the code implements a standard Node.js cookie jar utility with no network, filesystem, or process manipulation beyond normal HTTP header handling.
- `build/esm-debug/index.js` (safe): No malicious patterns detected; file only contains standard re-exports for the socket.io-client package.
- `build/esm-debug/socket.js` (safe): This is the legitimate engine.io-client socket implementation; no malicious patterns such as exfiltration, eval, credential harvesting, or process spawning were detected.
- `build/esm-debug/transport.js` (safe): No malicious patterns detected in the transport.js file; it is a legitimate part of the engine.io-client library with standard networking and error handling code.
- `build/esm-debug/transports/index.js` (safe): No malicious patterns detected; the file only imports transport implementations and exports a mapping with no executable or suspicious behavior.
- `build/esm-debug/transports/polling-fetch.js` (safe): No malicious patterns detected; the file implements standard HTTP long-polling using fetch with cookie handling and no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `build/esm-debug/transports/polling-xhr.js` (safe): No malicious patterns detected; this is legitimate engine.io-client XHR polling transport code.
- `build/esm-debug/transports/polling-xhr.node.js` (safe): No malicious patterns detected; the code is a legitimate XMLHttpRequest-based transport implementation for Socket.IO client using the xmlhttprequest-ssl package.
- `build/esm-debug/transports/polling.js` (safe): This file is a legitimate part of the engine.io-client polling transport implementation and contains no malicious patterns.
- `build/esm-debug/transports/websocket.js` (safe): No malicious patterns detected; the code is a standard engine.io WebSocket transport implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/esm-debug/transports/websocket.node.js` (safe): No malicious patterns detected; the code is a standard WebSocket transport implementation that delegates to the ws library without exfiltration, dynamic execution, or suspicious behavior.
- `build/esm-debug/transports/webtransport.js` (safe): No malicious patterns detected; the code is a standard WebTransport transport implementation for engine.io-client without any exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `build/esm-debug/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/esm/browser-entrypoint.js` (safe): No malicious patterns detected
- `build/esm/contrib/has-cors.js` (safe): No malicious patterns detected; the code is a straightforward feature-detection snippet for CORS support in browsers.
- `build/esm/contrib/parseqs.js` (safe): Cleared by Jev triage; no further analysis needed
- `build/esm/contrib/parseuri.js` (safe): No malicious patterns detected; the code is a standard URI parser with no network, filesystem, process execution, or obfuscation concerns.
- `build/esm/globals.node.js` (safe): No malicious patterns detected; the code implements a standard Node.js cookie jar utility with no network, filesystem, or process manipulation beyond normal HTTP header handling.
- `build/esm/index.js` (safe): No malicious patterns detected; file only contains standard re-exports for the socket.io-client package.
- `build/esm/socket.js` (safe): No malicious patterns detected; this is the legitimate engine.io-client Socket implementation with standard networking, event handling, and timer logic.
- `build/esm/transport.js` (safe): No malicious patterns detected
- `build/esm/transports/index.js` (safe): No malicious patterns detected; the file only imports transport implementations and exports a mapping with no executable or suspicious behavior.
- `build/esm/transports/polling-fetch.js` (safe): No malicious patterns detected; the file implements standard HTTP long-polling using fetch with cookie handling and no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `build/esm/transports/polling-xhr.js` (safe): No malicious patterns detected; this is a legitimate Socket.IO XHR polling transport implementation.
- `build/esm/transports/polling-xhr.node.js` (safe): No malicious patterns detected; the code is a legitimate XMLHttpRequest-based transport implementation for Socket.IO client using the xmlhttprequest-ssl package.
- `build/esm/transports/polling.js` (safe): No malicious patterns detected; this is a standard engine.io WebSocket polling transport implementation with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network activity.
- `build/esm/transports/websocket.js` (safe): The code is a standard engine.io WebSocket transport implementation with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or suspicious network/file system operations.
- `build/esm/transports/websocket.node.js` (safe): No malicious patterns detected; the code is a standard WebSocket transport implementation that delegates to the ws library without exfiltration, dynamic execution, or suspicious behavior.
- `build/esm/transports/webtransport.js` (safe): No malicious patterns detected; the code implements a standard WebTransport client transport using the engine.io-parser library without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
- `build/esm/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/engine.io.js` (safe): No malicious patterns detected; the code is the standard Engine.IO client library with only legitimate networking and utility functions.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
