# es-toolkit@1.33.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:28:51.000Z
- Files reviewed: 427
- Findings: 3 high, 6 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/es-toolkit@1.33.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package es-toolkit@1.33.0 on Oct 4, 2026. An AI review of 427 source files produced 3 high, 6 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Dynamic code execution

Finding ID: `NPS-E951598A6979`

File: `dist/browser.global.js`

The template function uses new Function() to compile a function from a string that includes user-supplied template code. This is a form of dynamic code execution (eval) and can lead to arbitrary code execution if untrusted input is passed to the template function. Additionally, the function uses the 'with(obj)' statement (or direct scope injection) to evaluate the compiled code, which can expose variables from the provided object. While this is an inherent feature of lodash-style templating, it represents a significant security risk if misused.

### [high] code generation from user input

Finding ID: `NPS-F4710B2B1A4E`

File: `dist/compat/string/template.mjs:71`

Template expressions (escape, interpolate, evaluate) are directly concatenated into the generated source without sanitization. While this is the intended functionality of a template engine, it means any untrusted template string allows code execution. This is a known risk in template engines (e.g., Lodash template) and should be documented as a security consideration.

### [high] dynamic code execution

Finding ID: `NPS-C8932C5B150E`

File: `dist/compat/string/template.mjs:105`

The template function compiles and executes a generated string using `new Function(...)`, which is equivalent to `eval`. The generated code includes user-provided template expressions and evaluate blocks. If an attacker can control the template string or options, this can lead to arbitrary code execution (RCE) within the runtime environment.

### [medium] Potential prototype pollution

Finding ID: `NPS-B794F115C22F`

File: `dist/browser.global.js`

Several functions, such as toPlainObject, mergeWith, and assignIn, manipulate object properties without sufficient protection against prototype pollution. For example, toPlainObject explicitly handles '__proto__' by using Object.defineProperty, but other functions like mergeWith may recursively assign properties and could be exploited to pollute Object.prototype if given malicious input. This can lead to advanced attacks such as privilege escalation or denial of service.

### [medium] dynamic code execution

Finding ID: `NPS-94DE832C035B`

File: `dist/compat/index.js:2780`

The `template` function builds a JavaScript function body from user-supplied template strings and executes it via `new Function(...)`. This is a well-known code-injection risk. Although the implementation includes escaping of delimiters and is intended for template rendering, if an application passes untrusted input as the template string or options (e.g. `sourceURL`, `variable`, `imports`), arbitrary code can be executed in the host environment. This pattern is common in utility libraries (e.g. lodash's `template`), but it is still a dangerous capability and should be flagged when reviewing third-party packages.

### [medium] use of with statement

Finding ID: `NPS-73CD5F0A9CBB`

File: `dist/compat/string/template.mjs:101`

The compiled function uses `with(obj) { ... }` to resolve variable references from the template against the provided object. This can lead to scope pollution and unintended variable access, especially if the object contains properties like `__proto__` or constructor, potentially enabling prototype pollution or sandbox escape.

### [medium] Dynamic method invocation via user-controlled path

Finding ID: `NPS-8AAA32A2A023`

File: `dist/compat/util/invoke.mjs:47`

The `invoke` function resolves a method on an object using a caller-supplied `path` and applies it with `args`. If `object` originates from untrusted input or a prototype-polluted object, an attacker could invoke unintended methods (e.g., `__proto__`, `constructor`, or other properties reachable via the path) with attacker-controlled arguments. No sanitization or allowlist restricts which properties can be reached, so this behaves like a generic callable dispatcher. In the context of a utility library this is expected behavior, but it constitutes a dangerous primitive if the object/path is exposed to untrusted sources.

### [medium] Prototype pollution exposure

Finding ID: `NPS-48E2DF7CF596`

File: `dist/compat/util/invoke.mjs:53`

`invokeImpl` uses `get(object, path.slice(0, -1), object)` and `get(parent, lastKey)` to traverse arbitrary property paths. `get` is typically unfiltered for keys like `__proto__`, `constructor`, and `prototype`, meaning paths such as `['__proto__', 'polluted']` can reach prototype members. Combined with `func?.apply(parent, args)`, this can lead to invoking prototype methods (e.g., `constructor.constructor` for Function-based code execution) if an attacker controls the path. This is a latent gadget rather than an obvious exploit in isolation.

### [medium] Arbitrary function invocation

Finding ID: `NPS-9A4F510480FB`

File: `dist/compat/util/invoke.mjs:63`

The final `func?.apply(parent, args)` executes whatever function is located at the resolved path. If the resolved function is `Function`, `eval`, or a similarly powerful constructor obtained via a crafted path, it amounts to dynamic code execution. The code itself does not use `eval`/`new Function`, but it exposes a mechanism that can reach such constructs through prototype traversal (`constructor.constructor`).

### [low] Verbose logging

Finding ID: `NPS-51F607B46218`

File: `dist/browser.global.js`

The functions divide and intersectionWith contain console.log statements that log arguments. This could inadvertently leak sensitive information if these functions are used with sensitive data. While not directly malicious, it is a poor security practice.

### [low] Debug logging in production code

Finding ID: `NPS-DCA16840937D`

File: `dist/compat/array/intersectionWith.mjs:6`

A console.log(firstArr) call was inserted into the intersectionWith function, logging the first argument on every invocation. This is not malicious (no exfiltration or credential harvesting), but it is extraneous debug output that does not match the upstream lodash-es implementation and could leak sensitive data to console logs or pollute application output.

### [low] debug information leakage

Finding ID: `NPS-3FAF89254987`

File: `dist/compat/index.js:1712`

There are stray `console.log` statements inside `intersectionWith` and `divide` that log user-provided arguments (`console.log(firstArr)` and `console.log(value, other)`). While not malicious per se, these leak runtime data to stdout and may expose sensitive values in logs or downstream tooling. They also appear to be accidental debugging artifacts and are a code-quality concern.

### [low] Debug logging of user input

Finding ID: `NPS-8360C7BB9260`

File: `dist/compat/math/divide.mjs:5`

The divide function logs both arguments to the console unconditionally via console.log(value, other). This is unexpected for a pure math utility and could leak sensitive values passed into divide() (e.g., tokens, keys, or personal data) into console output, logs, or browser devtools. While not overtly malicious, it is a privacy/security concern and deviates from the expected behavior of a lodash-like divide utility.

## Files reviewed

- `dist/browser.global.js` (medium): The library is a utility toolkit (es-toolkit) with several security-relevant patterns including dynamic code execution via new Function in template, potential prototype pollution vectors, and verbose logging, but no clear malicious intent such as data exfiltration or backdoors.
- `dist/compat/array/intersectionWith.mjs` (medium): The file contains an unexpected console.log debug statement not present in the original lodash-es source, but no exfiltration, obfuscation, code execution, or other malicious patterns were found.
- `dist/compat/index.js` (medium): The module is a utility library (es-toolkit compat layer) with no data exfiltration, credential harvesting, or backdoor behavior, but it exposes a `template` function that executes dynamically constructed code via `new Function`, and contains stray debug `console.log` calls.
- `dist/compat/math/divide.mjs` (medium): The file contains no exfiltration, credential harvesting, obfuscation, or dynamic execution, but includes an unnecessary and unexpected console.log of function arguments that could leak sensitive data.
- `dist/compat/string/template.mjs` (medium): The code is a template engine that uses dynamic `new Function` compilation and `with` statement, which are inherent security risks when processing untrusted templates, but no malicious exfiltration or backdoor patterns were detected.
- `dist/compat/util/invoke.mjs` (medium): This is a plain utility method-invocation helper with no network, filesystem, or process side effects, but its unrestricted path traversal and generic `apply` call create prototype-pollution / arbitrary-method-invocation primitives if fed untrusted input.
- `dist/_chunk/AbortError-Cg4ZQ1.js` (safe): No malicious patterns detected
- `dist/_chunk/delay-_VMfFa.js` (safe): No malicious patterns detected; the code is a standard delay utility with abort signal support.
- `dist/_chunk/isPlainObject-Xaozpc.js` (safe): No malicious patterns detected
- `dist/_chunk/isWeakSet-TIM260.js` (safe): No malicious patterns detected; the file contains only standard type-checking and deep-equality utility functions with no network, filesystem, process, or dynamic code execution behavior.
- `dist/_chunk/noop-2IwLUk.js` (safe): No malicious patterns detected
- `dist/_chunk/randomInt-CF7bZK.js` (safe): No malicious patterns detected; the code only contains benign random number utility functions.
- `dist/_chunk/range-HnEIT7.js` (safe): No malicious patterns detected; the file contains only standard utility functions for mathematical range and statistics operations.
- `dist/_chunk/toMerged-CwnQF6.js` (safe): No malicious patterns detected; the code is a standard utility library for deep cloning, merging, and object manipulation without any network, filesystem, process execution, or obfuscation concerns.
- `dist/_chunk/unary-c1NFA5.js` (safe): No malicious patterns detected; the file contains standard utility functions (after, ary, debounce, flow, memoize, etc.) with no network, filesystem, process, or dynamic code execution behavior.
- `dist/_chunk/upperFirst-nA5L7X.js` (safe): No malicious patterns detected; this is a standard string utility module with no network, filesystem, process, or dynamic code execution behavior.
- `dist/_chunk/zipWith-Bdyzuy.js` (safe): No malicious patterns detected; the code is a standard utility library with pure array/object functions and only a local relative require.
- `dist/_internal/compareValues.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/at.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/chunk.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/compact.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/countBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/difference.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/differenceBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/differenceWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/drop.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/dropRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/dropRightWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/dropWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/fill.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/flatMap.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/flatMapDeep.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/flatten.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/flattenDeep.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/forEachRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/groupBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/head.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/index.js` (safe): No malicious patterns detected; the code is a standard utility library re-exporting array helpers and implementing orderBy, sortBy, and takeRightWhile with no network, filesystem, process, or dynamic execution activity.
- `dist/array/index.mjs` (safe): No malicious patterns detected in the module re-export file; it only contains static exports of array utility functions.
- `dist/array/initial.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/intersection.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/intersectionBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/intersectionWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/isSubset.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/isSubsetWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/keyBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/last.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/maxBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/minBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/orderBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/partition.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/pull.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/pullAt.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/remove.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/sample.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/sampleSize.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/shuffle.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/sortBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/tail.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/take.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/takeRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/takeRightWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/takeWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/toFilled.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/union.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/unionBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/unionWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/uniq.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/uniqBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/uniqWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/unzip.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/unzipWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/windowed.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/without.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/xor.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/xorBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/xorWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/zip.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/zipObject.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/array/zipWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/MAX_ARRAY_LENGTH.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/MAX_SAFE_INTEGER.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/compareValues.mjs` (safe): No malicious patterns detected
- `dist/compat/_internal/decimalAdjust.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/flattenArrayLike.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/getSymbols.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/getTag.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/isDeepKey.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/isIndex.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/isIterateeCall.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/isKey.mjs` (safe): No malicious patterns detected; the code is a simple utility for checking if a value is a property key.
- `dist/compat/_internal/isPrototype.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/normalizeForCase.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/tags.mjs` (safe): No malicious patterns detected; the file only defines and exports string constants for JavaScript type tags.
- `dist/compat/_internal/toArray.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/_internal/toKey.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/castArray.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/chunk.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/compact.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/concat.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/difference.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/differenceBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/differenceWith.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/drop.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/dropRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/dropRightWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/dropWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/every.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/fill.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/filter.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/find.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/findIndex.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/findLast.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/findLastIndex.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/flatten.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/flattenDeep.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/flattenDepth.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/forEach.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/head.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/includes.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/indexOf.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/intersection.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/intersectionBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/join.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/last.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/lastIndexOf.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/map.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/nth.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/orderBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/pull.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/pullAll.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/pullAllBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/reduce.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/reduceRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/remove.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/reverse.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/sample.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/size.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/slice.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/some.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/sortBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/sortedIndex.mjs` (safe): The code is a standard sortedIndex utility with no malicious patterns, network activity, credential harvesting, or unsafe dynamic execution.
- `dist/compat/array/sortedIndexBy.mjs` (safe): No malicious patterns detected; the code implements a binary search utility with no network, filesystem, process, or dynamic execution behavior.
- `dist/compat/array/tail.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/take.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/takeRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/takeRightWhile.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/union.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/uniq.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/uniqBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/unzip.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/without.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/zip.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/array/zipObjectDeep.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/after.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/ary.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/attempt.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/before.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/bind.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/bindKey.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/curry.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/curryRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/debounce.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/defer.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/delay.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/flip.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/flow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/flowRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/negate.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/nthArg.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/rearg.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/rest.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/spread.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/function/throttle.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/index.mjs` (safe): No malicious patterns detected; the file only re-exports utility functions from other modules.
- `dist/compat/math/add.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/ceil.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/clamp.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/floor.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/inRange.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/max.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/maxBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/min.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/multiply.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/parseInt.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/random.mjs` (safe): No malicious patterns detected; the code is a standard random number generation utility with argument parsing and clamping.
- `dist/compat/math/range.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/rangeRight.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/round.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/subtract.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/sum.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/math/sumBy.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/assignIn.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/cloneDeep.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/cloneDeepWith.mjs` (safe): No malicious patterns detected; the file is a legitimate deep clone utility with standard object handling and no network, filesystem, process, or dynamic code execution behavior.
- `dist/compat/object/defaults.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/findKey.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/fromPairs.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/get.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/compat/object/has.mjs` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of es-toolkit are flagged high or critical. The latest scanned version, 1.52.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.52.0 (`1.52.0`): not scanned
- 1.44.0 – 1.45.1 (`>=1.44.0 <=1.45.1`): medium (Prototype pollution / unsafe prototype copying +4 more)
- 1.43.0 (`1.43.0`): not scanned
- 1.33.0 (`1.33.0`): medium (Dynamic code execution +4 more)

## Scanned versions

- [1.45.1](https://security.togoder.click/npm/es-toolkit@1.45.1): medium, 2026-10-04T21:17:50.000Z
- [1.44.0](https://security.togoder.click/npm/es-toolkit@1.44.0): medium, 2026-10-06T14:16:10.000Z
- [1.33.0](https://security.togoder.click/npm/es-toolkit@1.33.0): medium, 2026-10-04T16:28:51.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
