# flatted@3.4.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:39.000Z
- Files reviewed: 6
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/flatted
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package flatted@3.4.4 on Oct 6, 2026. An AI review of 6 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Obfuscated code

Finding ID: `NPS-40F846DC8655`

File: `esm.js:1`

The entire file is minified and heavily obfuscated with single-letter variable names, making it difficult to understand. This is a common technique used to hide malicious behavior. While it appears to implement a custom JSON stringify/parse (likely for circular references), the obfuscation obscures the actual functionality.

### [medium] Lack of clarity

Finding ID: `NPS-8C3C0AAD7E30`

File: `esm.js:1`

The code is a minified version of what appears to be the 'flatted' library, which serializes cyclic JSON. Without proper documentation or source maps, it is impossible to fully audit. This could be a supply chain risk if the package is not from a trusted source.

### [low] Dynamic code execution

Finding ID: `NPS-237B738EBC16`

File: `esm.js`

The code uses JSON.parse and JSON.stringify indirectly via destructuring, but there is no explicit eval or new Function. However, the custom parsing logic could be exploited if the input is untrusted, but it does not execute arbitrary code.

## Files reviewed

- `esm.js` (medium): The code is heavily obfuscated and likely implements a JSON cyclic reference serializer, but the obfuscation raises concerns about potential hidden behavior, though no explicit malicious patterns were detected.
- `cjs/index.js` (safe): No malicious patterns detected; the code is a legitimate JSON recursion serialization utility with no network, filesystem, process, or dynamic execution behavior.
- `es.js` (safe): No malicious patterns detected
- `esm/index.js` (safe): No malicious patterns detected; the code is a legitimate JSON serialization library (flatted) that only parses/stringifies values in-memory without network, filesystem, or process access.
- `index.js` (safe): No malicious patterns detected; the code is a legitimate JSON serialization library with no network, filesystem, or process access.
- `min.js` (safe): No malicious patterns detected; this is a legitimate minified JSON.stringify wrapper (flatted) with no network, filesystem, process, or dynamic code execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
