Togoder security

npm package security report

hono npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 4.10.7 Files reviewed 362 Size 808.2 KB Scanned

Summary

Togoder Security scanned the npm package hono@4.10.7 on Oct 4, 2026. An AI review of 362 source files produced 2 high, 16 medium, 24 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
2
high
16
medium
24
low

Findings 42

high

Insecure JWT Verification Algorithm Selection

NPS-AC55BD7C6EF4

In verifyWithJwks, the algorithm used for verification is taken from the matched JWK's 'alg' property (matchingKey.alg) or falls back to the token header's 'alg' (header.alg) rather than being explicitly constrained by the caller. If a JWKS endpoint provides keys with weak or attacker-influenced 'alg' values (or if the token header algorithm is trusted), this can lead to algorithm confusion or acceptance of tokens signed with unintended algorithms. While not direct malicious code, this is a significant security weakness in a JWT library.

dist/utils/jwt/jwt.js
high

Potential Algorithm Confusion via Header alg Fallback

NPS-3656CE2B0003

In verifyWithJwks, when a matching key is found, the verification algorithm is set to matchingKey.alg || header.alg. If matchingKey.alg is undefined, the algorithm from the untrusted token header is used, which could enable algorithm confusion attacks (e.g., forcing 'none' or asymmetric-to-symmetric confusion) if the key type mismatches. The isTokenHeader check only ensures 'alg' is one of the known AlgorithmTypes, but does not enforce that the key type matches the algorithm.

dist/utils/jwt/jwt.js
medium

dangerouslySetInnerHTML usage

NPS-285723FCC548

The applyProps function directly assigns untrusted __html content to container.innerHTML when the 'dangerouslySetInnerHTML' prop is used. This is standard React-like behavior but constitutes an XSS sink if untrusted data flows into __html.

dist/cjs/jsx/dom/render.js
medium

Unvalidated HTTP method override

NPS-1521774BDF3F

The middleware accepts an arbitrary method string from user-controlled input (form field, header, or query parameter) and passes it directly as the method of a new Request. There is no allowlist validation, so an attacker can set the method to any value (e.g., CONNECT, TRACE, or custom verbs), potentially bypassing upstream security controls that only inspect c.req.method before this middleware runs.

dist/cjs/middleware/method-override/index.js:36
medium

Header/body confusion in method override

NPS-6B4A1D23E36A

When overriding via header, the original body (c.req.raw.body) is forwarded to the internally dispatched request while the method changes (e.g., GET to POST/DELETE). This breaks the typical assumption that GET has no body and may cause downstream handlers or proxies to misinterpret or smuggle requests.

dist/cjs/middleware/method-override/index.js:63
medium

Query-based method override bypass

NPS-C08D95106E13

The query-string override path copies the original request body and headers unchanged into a request with an attacker-specified method. Because the method can be arbitrary and no validation is performed, this can be abused to reach handlers that should not be reachable for the original method, and the override is not removed by intermediaries that do their own parsing.

dist/cjs/middleware/method-override/index.js:75
medium

Network Request with External Input

NPS-354FBEB208D3

The verifyWithJwks function performs an unvalidated fetch to options.jwks_uri. If this URI originates from untrusted input, it could enable SSRF or trigger unexpected network requests. However, the URI is typically configured by the developer, not derived from the token itself.

dist/cjs/utils/jwt/jwt.js:130
medium

Algorithm Confusion Risk

NPS-9001BB599EA4

In verifyWithJwks, the algorithm is taken from the JWKS key (matchingKey.alg) falling back to the token header's alg. If the JWKS key does not specify alg, an attacker-controlled token header could dictate the algorithm used for verification, potentially enabling algorithm-confusion attacks. The verify function itself accepts an alg parameter that is trusted from the caller, but verifyWithJwks derives it partly from token data.

dist/cjs/utils/jwt/jwt.js:152
medium

Dynamic code generation via string interpolation

NPS-2E75825485A9

The code builds an inline <script> tag string: <script${nonce ? nonce="${nonce}" : ""}>document.querySelector('#${id}').textContent+=${JSON.stringify(stylesStr)}</script>. While this pattern is part of the intended SSR CSS helper behavior (injecting styles at runtime), it dynamically constructs JavaScript that is executed in the browser. If the id or nonce values are attacker-controlled, this could lead to DOM-based XSS or script injection. In practice, id is defined by the library author (DEFAULT_STYLE_ID) and nonce comes from the developer, so exploitability is limited, but the pattern of generating inline scripts is a notable security-relevant behavior.

dist/helper/css/index.js
medium

Dynamic code execution via inline script generation

NPS-EB92C9EC82CE

The code generates inline <script> tags containing JavaScript that manipulates the DOM. While this is intended for streaming SSR error boundaries, it introduces XSS-like behavior by embedding dynamically generated script content. If the scriptNonce is not properly enforced or if user-controlled data reaches the template IDs or content, it could lead to arbitrary script execution.

dist/jsx/components.js
medium

Use of eval-like behavior through new Function or similar

NPS-0D74190124D8

Although no explicit eval/new Function is present, the code constructs and injects JavaScript strings that are executed in the browser. This dynamic script generation can be abused if inputs are not sanitized, potentially leading to code injection.

dist/jsx/components.js
medium

Potential XSS via unsanitized content injection

NPS-F0A1C8B2B138

The ErrorBoundary component injects fallback HTML and children content directly into templates and script blocks without explicit sanitization in this file. If the content originates from untrusted sources, it could lead to cross-site scripting (XSS).

dist/jsx/components.js
medium

Dynamic attribute/property assignment via user-controlled keys

NPS-69F289CDC8EA

applyProps iterates over all keys in attributes and assigns to DOM properties (e.g., container.value, container[key]) or attributes. While this is typical for a renderer, if attributes originate from untrusted sources, it could allow property clobbering or prototype pollution (e.g., setting '__proto__' or 'constructor' through attributes). No explicit sanitization of keys is performed before using them in bracket notation or setAttribute.

dist/jsx/dom/render.js:50
medium

Dynamic code execution via innerHTML

NPS-E759052B5802

The 'dangerouslySetInnerHTML' prop is honored by directly assigning to container.innerHTML, which can lead to XSS if used with untrusted data. This is a known React-like API but remains a potential security risk if developers pass unsanitized content.

dist/jsx/dom/render.js:81
medium

Setting element attributes from untrusted values

NPS-BF8C652F7CF5

Attributes are set via setAttribute after being stringified. If attribute names or values come from untrusted input, this could set event handlers or dangerous attributes (e.g., 'srcdoc', 'href:javascript:...'). No allowlist is present.

dist/jsx/dom/render.js:148
medium

Permissive CORS configuration

NPS-401E31729A63

The default origin is set to '*', which allows any origin to access the resource. If credentials are enabled (opts.credentials), this can lead to unauthorized access. However, this is a common default and not inherently malicious.

dist/middleware/cors/index.js:5
medium

Weak cryptographic algorithms exposed

NPS-B461796E505E

The module exports md5 and sha1 helpers that use MD5 and SHA-1, which are cryptographically broken for collision resistance and unsuitable for security-sensitive hashing. While not inherently malicious, exposing them as general-purpose crypto utilities can lead to insecure usage in downstream applications.

dist/utils/crypto.js:8
medium

Remote JWKS Fetch Without Origin Validation

NPS-2F4646A43299

verifyWithJwks performs a fetch to options.jwks_uri without validating the URI scheme/host against an allowlist. A caller passing attacker-controlled jwks_uri could cause the process to make arbitrary outbound requests (SSRF). This is a design-level risk rather than injected malicious code.

dist/utils/jwt/jwt.js
low

File system write

NPS-346323E955AA

The code defines a writeFile function that writes files to disk using Bun's write API. This is standard SSG (static site generation) functionality for persisting generated output and is scoped to the generator's output paths, not arbitrary file system manipulation.

dist/adapter/bun/ssg.js:7
low

No-op mkdir

NPS-EA3027E273D7

The mkdir function is a no-op stub that does nothing. This could cause failures if the base SSG helper expects directory creation, but it is not a malicious pattern—just potentially incomplete implementation.

dist/adapter/bun/ssg.js:10
low

global crypto polyfill

NPS-B8D351493005

The line globalThis.crypto ??= crypto; assigns Node's crypto module to the global crypto object if it is not already defined. This is a common pattern in edge runtimes that lack a Web Crypto implementation and is not inherently malicious, but it does modify global state at import time.

dist/adapter/lambda-edge/handler.js:4
low

environment variable and credential harvesting

NPS-3D5874EA5AF4

The client automatically includes cookies in requests via args.cookie and also merges headers from user-provided options. While not directly reading files, this is a common pattern used to exfiltrate session cookies or credentials if the client is used with attacker-controlled URLs.

dist/cjs/client/client.js
low

dynamic code execution via Proxy

NPS-E7FE4499FC47

The code uses a Proxy to intercept property access and function calls, dynamically building request paths and methods. This obfuscates control flow and could hide malicious behavior if the callback were modified, but currently only constructs HTTP requests.

dist/cjs/client/client.js
low

suspicious network requests

NPS-E64BC3BDED5A

The client can create WebSocket connections and arbitrary HTTP requests to any URL provided by the caller. This is expected for an HTTP client library, but could be abused for data exfiltration if the library is used in a malicious context.

dist/cjs/client/client.js
low

Environment Variable Access

NPS-7D37317E0741

The code accesses process.env and Deno.env.toObject() to provide environment variables based on runtime. This is a common pattern in runtime-adapter libraries and does not exfiltrate or harvest credentials; it only returns environment variables to the caller within the same process.

dist/cjs/helper/adapter/index.js:19
low

DOM attribute/element manipulation

NPS-657E6B7DC00A

Extensive direct DOM manipulation including setAttribute, innerHTML, and dynamic element creation. This is expected rendering logic for a JSX/JSX-DOM library but increases attack surface if user-controlled props are not sanitized.

dist/cjs/jsx/dom/render.js
low

Dynamic event handler registration

NPS-27618F770252

Event handlers are attached dynamically via addEventListener based on prop names matching /^on[A-Z]/ patterns. No validation of handler origin, but handlers are expected to be functions provided by the developer.

dist/cjs/jsx/dom/render.js
low

insecure_comparison

NPS-474E9C64AD79

The equal function compares byte-by-byte in a loop that returns early on mismatch, which is not constant-time. It is named 'equal' but is not timing-safe, which could be misleading. However, a separate timingSafeEqual exists. Not malicious.

dist/cjs/utils/buffer.js:28
low

timing_side_channel

NPS-1ADBAE02AEED

The timingSafeEqual function hashes inputs with SHA-256 then compares hashes with ===, which is not constant-time and may leak timing information about the hash comparison. It also checks a === b after hashing, which is redundant and could short-circuit. This is a cryptographic weakness, not a malicious pattern.

dist/cjs/utils/buffer.js:42
low

Mutable Global State / Prototype Pollution Risk

NPS-DB50CDDE6246

verifyWithJwks mutates the caller-supplied options object by pushing into options.keys or assigning options.keys = data.keys. This can cause unintended side effects if the same options object is reused across calls, and in edge cases could be leveraged to pollute shared state.

dist/cjs/utils/jwt/jwt.js:139
low

Use of new RegExp with dynamic template input

NPS-864DD2A284D9

new RegExp((<style id="${id}"(?: nonce="[^"]*")?>.*?)(</style>)) constructs a regex from a template literal containing the id value. If id contains regex metacharacters, it could alter matching behavior. This is a correctness/robustness concern rather than a direct malicious pattern; no exfiltration or execution is performed here.

dist/helper/css/index.js
low

Suspicious network or process activity

NPS-FAB6DCA90CC5

No network requests, file system access, or process spawning are present. The code operates solely on in-memory string manipulation and DOM rendering logic.

dist/jsx/components.js
low

Timing attack mitigation

NPS-FDF50FA1F4B6

The code uses timingSafeEqual for comparing usernames and passwords, which is a good security practice to prevent timing attacks.

dist/middleware/basic-auth/index.js:32
low

Function-based origin validation

NPS-D8E03B61379B

The origin option can be a function, which receives the request origin and context. This allows arbitrary logic, but in the context of a middleware, it is expected. No malicious behavior observed.

dist/middleware/cors/index.js:20
low

Potential origin reflection vulnerability

NPS-473E89A4F9CE

When origin is set to a string (not '*'), the code reflects the request origin if it matches. This is standard, but if the allowed origin list is misconfigured or if a function is provided that returns a user-controlled value, it could lead to security issues. This is a design concern, not malicious.

dist/middleware/cors/index.js:23
low

input validation

NPS-BC191E71795C

The middleware validates the incoming X-Request-Id header using a regex ( /[^\w\-=]/ ) and a length limit to prevent header injection or log injection. This is a positive security control, not a vulnerability.

dist/middleware/request-id/request-id.js:9
low

Environment variable or credential access

NPS-E4897B718EC5

No access to environment variables, credential files, or sensitive system paths detected.

dist/middleware/secure-headers/secure-headers.js
low

Dynamic code execution

NPS-5058844F2BF8

No eval, Function constructor, or similar dynamic code execution mechanisms present.

dist/middleware/secure-headers/secure-headers.js
low

Network exfiltration

NPS-C76AD1399E56

No outbound network requests, external URL communications, or data exfiltration patterns identified.

dist/middleware/secure-headers/secure-headers.js
low

Suspicious file system or process manipulation

NPS-48AB41B9398B

No file system writes outside package scope, child process spawning, or shell command execution found.

dist/middleware/secure-headers/secure-headers.js
low

Nonce generation using crypto

NPS-8D47B4EB4733

Uses crypto.getRandomValues for generating CSP nonces, which is a secure and appropriate use for cryptographic randomness. No malicious intent or external data transmission observed.

dist/middleware/secure-headers/secure-headers.js:29
low

Potential silent failure

NPS-D982E2C47D56

When WebCrypto is unavailable (crypto.subtle is falsy), createHash returns null instead of throwing an error. Callers may inadvertently treat null as a valid hash and proceed insecurely, masking environment issues.

dist/utils/crypto.js:45

Files reviewed

FileVerdictWhat the reviewer saw
dist/cjs/client/client.js medium The code is a standard HTTP/WebSocket client library with no obvious malicious patterns, but its dynamic proxy-based API and automatic cookie/header handling could be misused in a supply-chain attack.
dist/cjs/jsx/dom/render.js medium This is a legitimate JSX DOM rendering implementation for the Hono framework; no malicious patterns such as data exfiltration, credential harvesting, code execution, or network calls were detected, though it contains standard XSS sinks (innerHTML) that require safe usage by callers.
dist/cjs/middleware/method-override/index.js medium The code is a legitimate method-override middleware, but it permits arbitrary, unvalidated HTTP methods from user input, which can enable method-based access-control bypasses and request-smuggling style behavior.
dist/cjs/utils/jwt/jwt.js medium This is a standard JWT implementation without overt malicious patterns, but it contains a few security-relevant weaknesses (SSRF-capable fetch of jwks_uri, mutation of caller-supplied options, and potential algorithm confusion when JWKS keys lack an explicit alg) that warrant a warning rather than a clean bill of health.
dist/helper/css/index.js medium This appears to be a legitimate CSS-in-JS helper library that dynamically generates inline style/script tags for SSR; no data exfiltration, credential harvesting, backdoors, or obfuscated payloads were found, but the inline script generation and dynamic RegExp construction warrant a warning.
dist/jsx/components.js medium The code implements a streaming error boundary for SSR with dynamic inline script generation, which poses a medium risk of XSS if nonce validation or input sanitization is insufficient, but no direct malicious patterns like data exfiltration or backdoors were found.
dist/jsx/dom/render.js medium The code is a legitimate DOM rendering library but contains patterns like innerHTML assignment and dynamic property/attribute setting that could be risky if misused with untrusted data; no malicious behavior is evident.
dist/middleware/cors/index.js medium The code is a standard CORS middleware implementation with permissive default settings but no malicious patterns detected.
dist/utils/crypto.js medium No malicious behavior (exfiltration, backdoors, install-time code, network calls, process spawning) was found; only weak legacy hash algorithms (MD5, SHA-1) and a silent null return are flagged as cryptographic hygiene concerns.
dist/utils/jwt/jwt.js medium The JWT utility code contains no malicious exfiltration, credential harvesting, obfuscation, or backdoor patterns, but it exhibits security weaknesses in JWKS-based verification, particularly trusting key/header-supplied algorithm values.
dist/adapter/aws-lambda/handler.js safe No malicious patterns detected; the code is a standard AWS Lambda adapter for a web framework with no data exfiltration, credential harvesting, obfuscation, or other red flags.
dist/adapter/aws-lambda/index.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/aws-lambda/types.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/bun/conninfo.js safe No malicious patterns detected; the code simply retrieves connection information from the Bun server.
dist/adapter/bun/index.js safe No malicious patterns detected; this is a simple ES module re-exporting Bun adapter utilities (static serving, websocket, SSG, connection info).
dist/adapter/bun/serve-static.js safe No malicious patterns detected; the code is a benign static file serving adapter with no network, filesystem, or process manipulation beyond reading files.
dist/adapter/bun/server.js safe No malicious patterns detected
dist/adapter/bun/ssg.js safe The code is a benign SSG adapter for Bun that writes generated static files to disk; no exfiltration, credential harvesting, obfuscation, or backdoor patterns were detected.
dist/adapter/bun/websocket.js safe No malicious patterns detected; the code is a standard WebSocket adapter for Bun with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/adapter/cloudflare-pages/handler.js safe No malicious patterns detected; the file is a standard Cloudflare Pages adapter handler with no network, filesystem, credential, or code-execution abuse.
dist/adapter/cloudflare-pages/index.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/cloudflare-workers/conninfo.js safe No malicious patterns detected
dist/adapter/cloudflare-workers/index.js safe The file is a simple re-export module for Cloudflare Workers adapter utilities with no malicious patterns detected.
dist/adapter/cloudflare-workers/serve-static-module.js safe No malicious patterns detected; the file is a simple wrapper re-exporting a serveStatic function.
dist/adapter/cloudflare-workers/serve-static.js safe No malicious patterns detected; the code is a straightforward static file serving adapter for Cloudflare Workers.
Show 337 more files
FileVerdictWhat the reviewer saw
dist/adapter/cloudflare-workers/utils.js safe No malicious patterns detected; the code is a benign Cloudflare Workers adapter utility for retrieving assets from KV storage.
dist/adapter/cloudflare-workers/websocket.js safe No malicious patterns detected; the code is a legitimate Cloudflare Workers WebSocket adapter from Hono.
dist/adapter/deno/conninfo.js safe No malicious patterns detected
dist/adapter/deno/deno.d.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/deno/index.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/deno/serve-static.js safe The code is a standard Deno adapter for serving static files without any malicious patterns such as exfiltration, obfuscation, or credential harvesting.
dist/adapter/deno/ssg.js safe No malicious patterns detected; the code is a straightforward Deno static site generation adapter using Deno's file system APIs.
dist/adapter/deno/websocket.js safe No malicious patterns detected; the code is a legitimate Deno WebSocket adapter with no exfiltration, obfuscation, process spawning, or install-time execution.
dist/adapter/lambda-edge/conninfo.js safe This is a simple utility function that extracts the client IP address from AWS Lambda@Edge event records, with no malicious patterns detected.
dist/adapter/lambda-edge/handler.js safe No malicious patterns detected; the code is a legitimate AWS Lambda@Edge adapter that modifies the global crypto object as a polyfill.
dist/adapter/lambda-edge/index.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/netlify/handler.js safe No malicious patterns detected
dist/adapter/netlify/index.js safe No malicious patterns detected
dist/adapter/netlify/mod.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/service-worker/handler.js safe No malicious patterns detected; the code is a legitimate service worker fetch handler with a fallback to network fetch on 404 responses.
dist/adapter/service-worker/index.js safe No malicious patterns detected; the code is a minimal service worker adapter that registers a fetch event listener.
dist/adapter/service-worker/types.js safe Cleared by Jev triage; no further analysis needed
dist/adapter/vercel/conninfo.js safe No malicious patterns detected; the code simply extracts the remote IP address from a request header.
dist/adapter/vercel/handler.js safe No malicious patterns detected
dist/adapter/vercel/index.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/adapter/aws-lambda/handler.js safe No malicious patterns detected; the code is a legitimate AWS Lambda adapter for SvelteKit that processes events and responses without any data exfiltration, credential harvesting, or dynamic code execution.
dist/cjs/adapter/aws-lambda/index.js safe No malicious patterns detected
dist/cjs/adapter/aws-lambda/types.js safe No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
dist/cjs/adapter/bun/conninfo.js safe No malicious patterns detected; the code only retrieves connection info from the Bun server for HTTP request handling.
dist/cjs/adapter/bun/index.js safe No malicious patterns detected; the file is a standard CommonJS transpiled module that re-exports submodules without any dynamic execution, network, or filesystem activity.
dist/cjs/adapter/bun/serve-static.js safe The code is a Bun adapter for a static file serving middleware, using standard filesystem and path utilities with no malicious patterns detected.
dist/cjs/adapter/bun/server.js safe The file contains only standard CommonJS-to-ESM interop helpers and a simple accessor for Bun server context; no malicious patterns, dynamic code execution, network calls, credential access, or filesystem/process manipulation were detected.
dist/cjs/adapter/bun/ssg.js safe No malicious patterns detected; code is a straightforward Bun-specific SSG adapter that writes files via the Bun API. The target path 'dist/cjs/adapter/bun/ssg.js' matches a known Hono framework adapter file, and no exfiltration, obfuscation, or credential harvesting was found.
dist/cjs/adapter/bun/websocket.js safe No malicious patterns detected; the code is a legitimate Bun WebSocket adapter with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/cjs/adapter/cloudflare-pages/handler.js safe No malicious patterns detected; the code is a standard Cloudflare Pages adapter handler with no data exfiltration, credential harvesting, obfuscation, or other red flags.
dist/cjs/adapter/cloudflare-pages/index.js safe No malicious patterns detected
dist/cjs/adapter/cloudflare-workers/conninfo.js safe No malicious patterns detected; the code is a simple Cloudflare Workers adapter that reads the 'cf-connecting-ip' header.
dist/cjs/adapter/cloudflare-workers/index.js safe This is a standard compiled CommonJS module that re-exports functions from local files, with no malicious patterns detected.
dist/cjs/adapter/cloudflare-workers/serve-static-module.js safe This file is standard CJS interop wrapper code for a static file serving module with no suspicious behavior, network calls, process spawning, or obfuscation.
dist/cjs/adapter/cloudflare-workers/serve-static.js safe No malicious patterns detected in the provided JavaScript file.
dist/cjs/adapter/cloudflare-workers/utils.js safe No malicious patterns detected; the code is a standard Cloudflare Workers adapter utility for retrieving static assets from a KV namespace.
dist/cjs/adapter/cloudflare-workers/websocket.js safe The code implements a standard WebSocket upgrade handler for Cloudflare Workers with no malicious patterns detected.
dist/cjs/adapter/deno/conninfo.js safe No malicious patterns detected; the code is a simple connection info adapter with standard module boilerplate.
dist/cjs/adapter/deno/deno.d.js safe No malicious patterns detected
dist/cjs/adapter/deno/index.js safe This is a standard CommonJS module wrapper that re-exports functions from Deno adapter modules without any malicious patterns.
dist/cjs/adapter/deno/serve-static.js safe No malicious patterns detected; the code implements a standard static file serving adapter for Deno using safe filesystem operations.
dist/cjs/adapter/deno/ssg.js safe No malicious patterns detected
dist/cjs/adapter/deno/websocket.js safe Code is a legitimate WebSocket adapter for Deno runtime with no malicious patterns, exfiltration, or backdoors detected.
dist/cjs/adapter/lambda-edge/conninfo.js safe No malicious patterns detected; the code simply reads the client IP from AWS Lambda@Edge CloudFront event records without any exfiltration, dynamic execution, or suspicious behavior.
dist/cjs/adapter/lambda-edge/handler.js safe No malicious patterns detected; the code is a standard Lambda@Edge adapter for an HTTP framework with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/cjs/adapter/lambda-edge/index.js safe This is a standard CommonJS module transpiled from ESM with no suspicious behavior; it only re-exports handler and conninfo functions.
dist/cjs/adapter/netlify/handler.js safe No malicious patterns detected
dist/cjs/adapter/netlify/index.js safe This is a standard CommonJS re-export shim generated by esbuild/rollup; it only re-exports the ./mod module and contains no malicious patterns.
dist/cjs/adapter/netlify/mod.js safe No malicious patterns detected; the file is a standard CommonJS adapter module that re-exports a handler function from a local sibling module without any suspicious behavior.
dist/cjs/adapter/service-worker/handler.js safe The service worker handler is a standard fetch fallback implementation with no malicious patterns, obfuscation, exfiltration, or risky behavior.
dist/cjs/adapter/service-worker/index.js safe No malicious patterns detected; the code is a standard CommonJS bundler output for a service worker adapter that registers a fetch event listener.
dist/cjs/adapter/service-worker/types.js safe No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
dist/cjs/adapter/vercel/conninfo.js safe No malicious patterns detected
dist/cjs/adapter/vercel/handler.js safe No malicious patterns detected
dist/cjs/adapter/vercel/index.js safe No malicious patterns detected
dist/cjs/client/fetch-result-please.js safe No malicious patterns detected; the code is a standard fetch response parsing utility with no exfiltration, credential harvesting, obfuscation, or system-level operations.
dist/cjs/client/index.js safe This is a standard CJS bundle entry point that re-exports named symbols from internal modules with no executable, network, filesystem, or obfuscated behavior.
dist/cjs/client/types.js safe No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
dist/cjs/client/utils.js safe No malicious patterns detected
dist/cjs/compose.js safe No malicious patterns detected; the code implements standard middleware composition similar to Koa-style dispatch with no external calls, file access, or dynamic execution.
dist/cjs/context.js safe The code is a standard Hono framework Context class with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network requests, or filesystem manipulation.
dist/cjs/helper/accepts/accepts.js safe No malicious patterns detected; the code is a standard implementation of HTTP Accept header content negotiation with no network, filesystem, environment, or dynamic execution concerns.
dist/cjs/helper/accepts/index.js safe No malicious patterns detected
dist/cjs/helper/adapter/index.js safe No malicious patterns detected; the code is a standard runtime environment adapter that reads environment variables without exfiltration or other harmful behavior.
dist/cjs/helper/conninfo/index.js safe No malicious patterns detected
dist/cjs/helper/conninfo/types.js safe No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
dist/cjs/helper/cookie/index.js safe No malicious patterns detected
dist/cjs/helper/css/common.js safe No malicious patterns detected; the code is a CSS utility library with no network, filesystem, process, or obfuscated execution behaviors.
dist/cjs/helper/css/index.js safe No malicious patterns detected; the code is a standard CSS-in-JS helper library with no data exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
dist/cjs/helper/dev/index.js safe No malicious patterns detected
dist/cjs/helper/factory/index.js safe No malicious patterns detected; the code is a standard Hono.js helper factory with no network, filesystem, process, or obfuscated activity.
dist/cjs/helper/html/index.js safe No malicious patterns detected; the code is a standard tagged template literal HTML escaping helper with no network, filesystem, process, or dynamic code execution activity.
dist/cjs/helper/proxy/index.js safe No malicious patterns detected; the code implements a standard HTTP proxy helper with header sanitization.
dist/cjs/helper/route/index.js safe No malicious patterns detected; the code is a standard routing utility with no data exfiltration, credential harvesting, obfuscation, or process spawning.
dist/cjs/helper/ssg/index.js safe No malicious patterns detected; the file is a standard CommonJS re-export helper with no suspicious behavior.
dist/cjs/helper/ssg/middleware.js safe No malicious patterns detected
dist/cjs/helper/ssg/ssg.js safe No malicious patterns detected; the code is a legitimate static site generation (SSG) helper for the Hono framework.
dist/cjs/helper/ssg/utils.js safe The code contains only routine path manipulation and route filtering utilities with no malicious patterns, external calls, or dynamic execution.
dist/cjs/helper/streaming/index.js safe No malicious patterns detected; the file is a standard CommonJS re-export module for streaming helpers.
dist/cjs/helper/streaming/sse.js safe No malicious patterns detected; the code implements Server-Sent Events streaming with standard utilities and no exfiltration, obfuscation, or unauthorized system access.
dist/cjs/helper/streaming/stream.js safe No malicious patterns detected; the file contains standard streaming helper utilities with no exfiltration, obfuscation, or suspicious behavior.
dist/cjs/helper/streaming/text.js safe No malicious patterns detected; the file is a benign streaming helper with standard CommonJS bundler boilerplate and security-hardening headers.
dist/cjs/helper/streaming/utils.js safe No malicious patterns detected
dist/cjs/helper/testing/index.js safe No malicious patterns detected; the code is a standard testing helper that creates a client with a custom fetch function.
dist/cjs/helper/websocket/index.js safe No malicious patterns detected; this is a WebSocket context helper with no network, filesystem, process, or dynamic code execution behavior.
dist/cjs/hono-base.js safe No malicious patterns detected in the provided HonoBase source code.
dist/cjs/hono.js safe No malicious patterns detected; this is a standard Hono framework entry point with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/cjs/http-exception.js safe No malicious patterns detected; the file is a standard HTTPException class definition using Web Fetch API Response objects.
dist/cjs/index.js safe The file contains only standard CommonJS module bundling boilerplate and re-exports Hono from a local import; no malicious patterns, obfuscation, network calls, or process execution were detected.
dist/cjs/jsx/base.js safe No malicious patterns detected; the code is a legitimate JSX runtime implementation for the Hono framework with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
dist/cjs/jsx/children.js safe No malicious patterns detected
dist/cjs/jsx/components.js safe No malicious patterns detected; the code implements server-side JSX error boundary rendering with template replacement and inline script nonce handling typical of the Hono framework.
dist/cjs/jsx/constants.js safe No malicious patterns detected; the file only defines and exports Symbol constants using standard CommonJS interop helpers.
dist/cjs/jsx/context.js safe No malicious patterns detected; the file contains standard context management code for a JSX rendering library with no network, filesystem, process execution, or obfuscation concerns.
dist/cjs/jsx/dom/client.js safe No malicious patterns detected; the file contains standard CommonJS boilerplate for exporting React-like DOM client functions with no network, filesystem, process execution, or obfuscated code.
dist/cjs/jsx/dom/components.js safe No malicious patterns detected in the analyzed JavaScript file; it contains standard error boundary and suspense component implementations without any obfuscation, network activity, or system-level operations.
dist/cjs/jsx/dom/context.js safe No malicious patterns detected; the file contains standard React-like context creation logic with no network, filesystem, process, or obfuscation concerns.
dist/cjs/jsx/dom/css.js safe No malicious patterns detected; the file is a legitimate CSS-in-JS runtime without exfiltration, credential access, dynamic execution, or network activity.
dist/cjs/jsx/dom/hooks/index.js safe No malicious patterns detected; the file contains standard React-like hook implementations for form status, optimistic updates, and action state management.
dist/cjs/jsx/dom/index.js safe No malicious patterns detected
dist/cjs/jsx/dom/intrinsic-element/components.js safe No malicious patterns detected
dist/cjs/jsx/dom/jsx-dev-runtime.js safe No malicious patterns detected; this is a normal JSX dev runtime helper file with standard CJS/ESM interop boilerplate.
dist/cjs/jsx/dom/jsx-runtime.js safe No malicious patterns detected
dist/cjs/jsx/dom/server.js safe No malicious patterns detected; the code is standard compiled output for server-side JSX rendering with no network, filesystem, or process manipulation.
dist/cjs/jsx/dom/utils.js safe No malicious patterns detected; the code is a standard CommonJS wrapper for exporting a utility function.
dist/cjs/jsx/hooks/index.js safe No malicious patterns detected; the code implements standard React-like hooks with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity.
dist/cjs/jsx/index.js safe No malicious patterns detected; the file is a standard compiled JSX runtime barrel export with no suspicious network, filesystem, or process activity.
dist/cjs/jsx/intrinsic-element/common.js safe No malicious patterns detected; the code is a standard CommonJS module with helper functions and constant exports.
dist/cjs/jsx/intrinsic-element/components.js safe No malicious patterns detected; the code is a JSX intrinsic-element component library implementing head tag deduplication and metadata handling without any exfiltration, obfuscation, or process execution.
dist/cjs/jsx/intrinsic-elements.js safe No malicious patterns detected; the file contains only CommonJS module boilerplate for exporting an empty object.
dist/cjs/jsx/jsx-dev-runtime.js safe This is a standard JSX dev runtime helper module with no suspicious behavior, network activity, credential access, or dynamic code execution.
dist/cjs/jsx/jsx-runtime.js safe No malicious patterns detected; this appears to be a standard JSX runtime helper module for server-side rendering with attribute escaping.
dist/cjs/jsx/streaming.js safe No malicious patterns detected; the code implements JSX streaming/Suspense rendering with standard internal callbacks and no suspicious network, filesystem, or process activity.
dist/cjs/jsx/types.js safe No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
dist/cjs/jsx/utils.js safe No malicious patterns detected
dist/cjs/middleware/basic-auth/index.js safe No malicious patterns detected; the code is a standard basic authentication middleware with no data exfiltration, process spawning, or dynamic code execution.
dist/cjs/middleware/bearer-auth/index.js safe No malicious patterns detected; this is a standard bearer authentication middleware with no network exfiltration, credential harvesting, dynamic execution, or install-time hooks.
dist/cjs/middleware/body-limit/index.js safe No malicious patterns detected; the code implements a body size limiting middleware with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/cjs/middleware/cache/index.js safe No malicious patterns detected; the code implements a standard HTTP cache middleware using the Web Cache API without exfiltration, credential harvesting, obfuscation, or any suspicious behavior.
dist/cjs/middleware/combine/index.js safe No malicious patterns detected; the code is a standard middleware composition utility with no network, filesystem, process, or obfuscated behavior.
dist/cjs/middleware/compress/index.js safe No malicious patterns detected; the code is a standard response compression middleware with no network, filesystem, process, or obfuscation concerns.
dist/cjs/middleware/context-storage/index.js safe No malicious patterns detected; the code is a standard AsyncLocalStorage-based context storage middleware with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/cjs/middleware/cors/index.js safe No malicious patterns detected
dist/cjs/middleware/csrf/index.js safe No malicious patterns detected; the code implements a standard CSRF protection middleware for web frameworks.
dist/cjs/middleware/etag/digest.js safe No malicious patterns detected; the code implements a standard streaming digest utility with no network, filesystem, or dynamic execution capabilities.
dist/cjs/middleware/etag/index.js safe No malicious patterns detected in the ETag middleware implementation.
dist/cjs/middleware/ip-restriction/index.js safe No malicious patterns detected; the code implements IP restriction middleware with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/file/process activity.
dist/cjs/middleware/jsx-renderer/index.js safe No malicious patterns detected; the code is a standard JSX renderer middleware with no network, filesystem, process, or dynamic execution concerns.
dist/cjs/middleware/jwk/index.js safe No malicious patterns detected
dist/cjs/middleware/jwk/jwk.js safe No malicious patterns detected; the code implements standard JWK/JWT authentication middleware without exfiltration, credential harvesting, obfuscation, or suspicious dynamic behavior.
dist/cjs/middleware/jwt/index.js safe The code is a standard CommonJS re-export module for JWT functionality with no malicious patterns detected.
dist/cjs/middleware/jwt/jwt.js safe No malicious patterns detected; the code is a standard JWT middleware implementation with proper cryptographic verification and no exfiltration, obfuscation, or unauthorized system access.
dist/cjs/middleware/language/index.js safe No malicious patterns detected
dist/cjs/middleware/language/language.js safe Language detection middleware contains only standard localization logic with no malicious patterns, network activity, or dynamic code execution.
dist/cjs/middleware/logger/index.js safe No malicious patterns detected; the code is a benign HTTP request logger middleware.
dist/cjs/middleware/powered-by/index.js safe No malicious patterns detected; the file is a standard middleware helper that only sets the X-Powered-By response header.
dist/cjs/middleware/pretty-json/index.js safe No malicious patterns detected; the code is a standard middleware for pretty-printing JSON responses.
dist/cjs/middleware/request-id/index.js safe No malicious patterns detected; the file is a standard CommonJS re-export wrapper for the request-id middleware.
dist/cjs/middleware/request-id/request-id.js safe No malicious patterns detected; the code is a benign request-ID middleware that reads a header, validates it, and sets a response header.
dist/cjs/middleware/secure-headers/index.js safe No malicious patterns detected
dist/cjs/middleware/secure-headers/permissions-policy.js safe No malicious patterns detected; the file contains only standard CommonJS module boilerplate and an empty exports object with no executable logic.
dist/cjs/middleware/secure-headers/secure-headers.js safe No malicious patterns detected; the code is a legitimate secure headers middleware for setting HTTP security headers.
dist/cjs/middleware/serve-static/index.js safe The code is a static file serving middleware with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
dist/cjs/middleware/serve-static/path.js safe The code implements a safe, pure path-joining utility with no malicious patterns, external calls, or dangerous operations.
dist/cjs/middleware/timeout/index.js safe No malicious patterns detected; the code is a legitimate timeout middleware implementation.
dist/cjs/middleware/timing/index.js safe No malicious patterns detected; this is a standard TypeScript-compiled CommonJS re-export shim for a timing middleware module.
dist/cjs/middleware/timing/timing.js safe No malicious patterns detected; the code implements a standard Server-Timing middleware with no data exfiltration, obfuscation, or system-level access.
dist/cjs/middleware/trailing-slash/index.js safe No malicious patterns detected; the code implements standard trailing slash middleware with no exfiltration, obfuscation, or dangerous operations.
dist/cjs/preset/quick.js safe No malicious patterns detected
dist/cjs/preset/tiny.js safe No malicious patterns detected
dist/cjs/request.js safe No malicious patterns detected; the code is a standard Hono framework request wrapper with benign request parsing and cloning utilities.
dist/cjs/request/constants.js safe No malicious patterns detected
dist/cjs/router.js safe No malicious patterns detected.
dist/cjs/router/linear-router/index.js safe No malicious patterns detected; the file only contains standard CommonJS transpilation helper code for exporting a router class.
dist/cjs/router/linear-router/router.js safe No malicious patterns detected; the code is a legitimate linear router implementation with standard module exports and path matching logic.
dist/cjs/router/pattern-router/index.js safe This is a standard TypeScript/CommonJS build artifact re-exporting PatternRouter with no malicious patterns, dynamic execution, network activity, or filesystem access.
dist/cjs/router/pattern-router/router.js safe No malicious patterns detected; the code implements a URL pattern router with no network, filesystem, process spawning, or dynamic code execution.
dist/cjs/router/reg-exp-router/index.js safe No malicious patterns detected; the file only contains standard CommonJS module bundling boilerplate and re-exports from local router files.
dist/cjs/router/reg-exp-router/matcher.js safe No malicious patterns detected
dist/cjs/router/reg-exp-router/node.js safe This is a benign routing library implementation (reg-exp-router) that builds regular expressions from path tokens, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network activity, or process spawning.
dist/cjs/router/reg-exp-router/prepared-router.js safe No malicious patterns detected in the provided JavaScript router implementation.
dist/cjs/router/reg-exp-router/router.js safe No malicious patterns detected
dist/cjs/router/reg-exp-router/trie.js safe No malicious patterns detected; the code implements a trie for router path parsing using standard string manipulation and regex, with no network, filesystem, process, or dynamic execution activity.
dist/cjs/router/smart-router/index.js safe The file contains only standard CommonJS/ESM interop boilerplate and a clean re-export of SmartRouter with no malicious patterns detected.
dist/cjs/router/smart-router/router.js safe No malicious patterns detected in this SmartRouter implementation, which only performs in-memory route registration and matching without any network, filesystem, process, or dynamic code execution activity.
dist/cjs/router/trie-router/index.js safe No malicious patterns detected; the file is a standard CommonJS transpilation of a trie router module with no suspicious behavior.
dist/cjs/router/trie-router/node.js safe No malicious patterns detected; the code is a standard routing trie implementation with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
dist/cjs/router/trie-router/router.js safe No malicious patterns detected
dist/cjs/types.js safe No malicious patterns detected
dist/cjs/utils/accept.js safe No malicious patterns detected; the code only parses HTTP Accept headers with no network, filesystem, or dynamic execution behavior.
dist/cjs/utils/basic-auth.js safe No malicious patterns detected; the code is a straightforward Basic Authentication header parser.
dist/cjs/utils/body.js safe No malicious patterns detected in the body parsing utility; it only processes form data from incoming requests.
dist/cjs/utils/buffer.js safe No malicious patterns detected; the code contains standard buffer utility functions with minor cryptographic timing weaknesses.
dist/cjs/utils/color.js safe No malicious patterns detected; the code only checks standard environment variables and performs a guarded dynamic import for Cloudflare Workers compatibility.
dist/cjs/utils/compress.js safe No malicious patterns detected; the file only exports a regular expression for compressible content types.
dist/cjs/utils/concurrent.js safe No malicious patterns detected
dist/cjs/utils/constants.js safe No malicious patterns detected; the file only contains standard CommonJS/ESM interop helpers and exports a single string constant.
dist/cjs/utils/cookie.js safe No malicious patterns detected; the code implements standard cookie parsing and signing utilities without exfiltration, credential harvesting, obfuscation, or network access.
dist/cjs/utils/crypto.js safe The code is a standard cryptographic hashing utility with no malicious patterns, external calls, or suspicious behavior.
dist/cjs/utils/encode.js safe The code is a straightforward Base64/Base64URL encoding and decoding utility with no malicious patterns, external calls, or obfuscation.
dist/cjs/utils/filepath.js safe No malicious patterns detected; the file contains only path resolution utilities with standard path traversal sanitization.
dist/cjs/utils/handler.js safe No malicious patterns detected; the file contains only standard CommonJS module utilities and handler helper functions.
dist/cjs/utils/headers.js safe No malicious patterns detected; the file contains only standard TypeScript/CommonJS interop boilerplate with no executable logic or external interactions.
dist/cjs/utils/html.js safe This is a standard HTML escaping utility from the Hono framework; no malicious patterns such as exfiltration, credential harvesting, code execution, or network activity were detected.
dist/cjs/utils/http-status.js safe No malicious patterns detected
dist/cjs/utils/ipaddr.js safe No malicious patterns detected; the code only implements IPv4/IPv6 parsing and conversion utilities with no network, filesystem, process, or dynamic code execution behavior.
dist/cjs/utils/jwt/index.js safe No malicious patterns detected
dist/cjs/utils/jwt/jwa.js safe No malicious patterns detected; the file only defines JWT algorithm type constants and uses standard TypeScript/CommonJS export helpers.
dist/cjs/utils/jwt/jws.js safe No malicious patterns detected; the code implements standard JWT signing and verification using WebCrypto.
dist/cjs/utils/jwt/types.js safe No malicious patterns detected; the file only defines JWT-related error classes and a CryptoKeyUsage enum with no network, filesystem, process, or dynamic execution behavior.
dist/cjs/utils/jwt/utf8.js safe No malicious patterns detected; the file only provides simple UTF-8 TextEncoder/TextDecoder exports with standard CommonJS interop helpers.
dist/cjs/utils/mime.js safe No malicious patterns detected; the file only provides MIME type lookup utilities with no network, filesystem, or dynamic execution behavior.
dist/cjs/utils/stream.js safe No malicious patterns detected; the file implements a standard streaming API with no network, filesystem, or process manipulation.
dist/cjs/utils/types.js safe No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
dist/cjs/utils/url.js safe The code is a standard URL parsing utility with no malicious patterns, network activity, file system access, or dynamic code execution.
dist/cjs/validator/index.js safe No malicious patterns detected; the file is a standard CommonJS re-export shim generated by a bundler.
dist/cjs/validator/validator.js safe No malicious patterns detected; the code is a standard request validator for JSON, form, query, param, header, and cookie data without any exfiltration, obfuscation, or dynamic execution.
dist/client/client.js safe No malicious patterns detected; the file implements a standard HTTP client proxy without exfiltration, obfuscation, or system-level operations.
dist/client/fetch-result-please.js safe No malicious patterns detected; the code is a straightforward fetch wrapper with error handling and response type detection.
dist/client/index.js safe No malicious patterns detected
dist/client/types.js safe Cleared by Jev triage; no further analysis needed
dist/client/utils.js safe No malicious patterns detected. The code contains only utility functions for URL and object manipulation, with no suspicious network, filesystem, or execution behavior.
dist/compose.js safe No malicious patterns detected
dist/context.js safe No malicious patterns detected; the code is a legitimate HTTP context implementation for the Hono web framework.
dist/helper/accepts/accepts.js safe No malicious patterns detected; the code is a simple HTTP Accept header parser with no network, filesystem, or execution behavior.
dist/helper/accepts/index.js safe Cleared by Jev triage; no further analysis needed
dist/helper/adapter/index.js safe No malicious patterns detected; the code only reads environment variables for legitimate runtime detection purposes.
dist/helper/conninfo/index.js safe Cleared by Jev triage; no further analysis needed
dist/helper/conninfo/types.js safe Cleared by Jev triage; no further analysis needed
dist/helper/cookie/index.js safe Cookie helper module with no malicious patterns; only performs expected cookie parsing, signing, and serialization operations.
dist/helper/css/common.js safe This is a CSS-in-JS utility library with no network, filesystem, process, or dynamic execution behavior; all operations are pure string manipulation and hashing, so no malicious patterns are present.
dist/helper/dev/index.js safe No malicious patterns detected; the code only inspects and prints route information for debugging purposes.
dist/helper/factory/index.js safe No malicious patterns detected; the code is a benign factory helper for the Hono web framework with no network, filesystem, or process manipulation.
dist/helper/html/index.js safe No malicious patterns detected
dist/helper/proxy/index.js safe No malicious patterns detected; the code implements a standard HTTP proxy helper with header filtering and no suspicious behavior.
dist/helper/route/index.js safe No malicious patterns detected; the code appears to be a legitimate routing helper with no network, file system, or dynamic execution concerns.
dist/helper/ssg/index.js safe No malicious patterns detected
dist/helper/ssg/middleware.js safe The code implements standard static site generation (SSG) middleware for the Hono framework with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning.
dist/helper/ssg/ssg.js safe No malicious patterns detected; the code is a legitimate static site generation utility for the Hono framework.
dist/helper/ssg/utils.js safe No malicious patterns detected; the code contains only utility functions for path manipulation and route filtering with no network, filesystem, process, or credential access.
dist/helper/streaming/index.js safe Cleared by Jev triage; no further analysis needed
dist/helper/streaming/sse.js safe The code implements an SSE streaming helper for a web framework with no malicious patterns, external network calls, credential access, or dynamic code execution.
dist/helper/streaming/stream.js safe No malicious patterns detected; the code is a standard streaming helper with no external data exfiltration, credential harvesting, dynamic execution, or process spawning.
dist/helper/streaming/text.js safe No malicious patterns detected; the code is a simple HTTP streaming helper that sets content-type and security headers.
dist/helper/streaming/utils.js safe The code only checks the Bun runtime version string and contains no malicious patterns.
dist/helper/testing/index.js safe No malicious patterns detected; the code is a simple test client helper for a web framework.
dist/helper/websocket/index.js safe No malicious patterns detected
dist/hono-base.js safe This is the legitimate Hono web framework base class containing only routing, request handling, and error dispatch logic; no malicious patterns, data exfiltration, process spawning, or dynamic code execution were found.
dist/hono.js safe The file contains only benign Hono framework class definition code with no malicious patterns, data exfiltration, dynamic execution, or install-time behavior.
dist/http-exception.js safe No malicious patterns detected; the code is a standard HTTPException class with no external data access or dangerous operations.
dist/index.js safe Cleared by Jev triage; no further analysis needed
dist/jsx/base.js safe This is a legitimate JSX runtime implementation (Hono's JSX) with no malicious patterns, no network calls, no filesystem access, no process spawning, and no dynamic code execution.
dist/jsx/children.js safe Cleared by Jev triage; no further analysis needed
dist/jsx/constants.js safe No malicious patterns detected
dist/jsx/context.js safe No malicious patterns detected; the code is a legitimate JSX context implementation with no network, filesystem, or process activity.
dist/jsx/dom/client.js safe Cleared by Jev triage; no further analysis needed
dist/jsx/dom/components.js safe No malicious patterns detected
dist/jsx/dom/context.js safe No malicious patterns detected; the code implements a standard JSX context provider for a UI library without any data exfiltration, credential harvesting, obfuscation, or process execution.
dist/jsx/dom/css.js safe This is a CSS-in-JS utility module for Hono's JSX DOM renderer; it contains no network, filesystem, process, credential, obfuscation, or dynamic execution patterns and is safe.
dist/jsx/dom/hooks/index.js safe No malicious patterns detected; the code is a legitimate React-like hooks implementation for form status and optimistic state management.
dist/jsx/dom/index.js safe No malicious patterns detected; the file is a standard JSX/React-compatible DOM rendering entry point with imports and exports only.
dist/jsx/dom/intrinsic-element/components.js safe The code implements DOM intrinsic element handling for a JSX library with no malicious patterns detected.
dist/jsx/dom/jsx-dev-runtime.js safe No malicious patterns detected
dist/jsx/dom/jsx-runtime.js safe No malicious patterns detected
dist/jsx/dom/server.js safe No malicious patterns detected; the code is a straightforward server-side rendering utility with no network, filesystem, process, or dynamic code execution concerns.
dist/jsx/dom/utils.js safe No malicious patterns detected
dist/jsx/hooks/index.js safe No malicious patterns detected; the code implements standard JSX hooks for a UI framework with no network, filesystem, process, or obfuscation concerns.
dist/jsx/index.js safe No malicious patterns detected; the file is a standard JSX runtime re-export module with only static imports and exports.
dist/jsx/intrinsic-element/common.js safe No malicious patterns detected; the file only defines static configuration maps and exports them without any dynamic execution, network, filesystem, or process activity.
dist/jsx/intrinsic-element/components.js safe No malicious patterns detected; the code appears to be a legitimate JSX intrinsic element handler for document metadata with no security concerns.
dist/jsx/intrinsic-elements.js safe Cleared by Jev triage; no further analysis needed
dist/jsx/jsx-dev-runtime.js safe No malicious patterns detected
dist/jsx/jsx-runtime.js safe No malicious patterns detected; this is a standard JSX runtime implementation for Hono that performs safe HTML attribute escaping and rendering without any network, filesystem, or process execution activity.
dist/jsx/streaming.js safe No malicious patterns detected; the code appears to be a legitimate JSX streaming renderer with Suspense support, containing no obfuscation, data exfiltration, credential harvesting, or backdoor behavior.
dist/jsx/types.js safe Cleared by Jev triage; no further analysis needed
dist/jsx/utils.js safe No malicious patterns detected; the code is a benign JSX utility for key normalization and style object iteration.
dist/middleware/basic-auth/index.js safe The code implements a basic authentication middleware with proper timing-safe comparisons and no malicious patterns detected.
dist/middleware/bearer-auth/index.js safe No malicious patterns detected
dist/middleware/body-limit/index.js safe The code implements a standard request body size limiting middleware with no malicious patterns, network exfiltration, credential harvesting, obfuscation, or process execution.
dist/middleware/cache/index.js safe No malicious patterns detected; the code implements a standard HTTP cache middleware using the Cache API without any exfiltration, credential harvesting, obfuscation, or process execution.
dist/middleware/combine/index.js safe No malicious patterns detected; the file contains only legitimate routing middleware logic for combining handlers.
dist/middleware/compress/index.js safe No malicious patterns detected; the code implements a benign compression middleware using standard Web APIs without any suspicious activity.
dist/middleware/context-storage/index.js safe No malicious patterns detected
dist/middleware/csrf/index.js safe No malicious patterns detected; the code implements CSRF protection without exfiltration, obfuscation, or install-time execution.
dist/middleware/etag/digest.js safe The code only computes a hash digest from a stream using a provided generator, with no network, filesystem, environment, or process-related activity.
dist/middleware/etag/index.js safe No malicious patterns detected in the ETag middleware code; it only implements standard HTTP caching behavior.
dist/middleware/ip-restriction/index.js safe The code implements IP restriction middleware using allow/deny lists with CIDR support and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
dist/middleware/jsx-renderer/index.js safe This is legitimate Hono JSX renderer middleware code with no malicious patterns detected.
dist/middleware/jwk/index.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/jwk/jwk.js safe No malicious patterns detected; the code is a legitimate JWK/JWT authentication middleware from Hono.
dist/middleware/jwt/index.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/jwt/jwt.js safe No malicious patterns detected; the code is a standard JWT authentication middleware for the Hono web framework.
dist/middleware/language/index.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/language/language.js safe No malicious patterns detected; the code is a standard language detection middleware with no exfiltration, credential harvesting, dynamic execution, or suspicious network/file system activity.
dist/middleware/logger/index.js safe No malicious patterns detected; the code is a standard HTTP request logger middleware with only benign logging and color utility logic.
dist/middleware/method-override/index.js safe No malicious patterns detected; the code implements standard HTTP method override middleware without exfiltration, credential harvesting, obfuscation, or dangerous operations.
dist/middleware/powered-by/index.js safe No malicious patterns detected
dist/middleware/pretty-json/index.js safe No malicious patterns detected; the middleware only conditionally pretty-prints JSON responses based on a query parameter.
dist/middleware/request-id/index.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/request-id/request-id.js safe No malicious patterns detected; the code is a benign request ID middleware with proper input validation.
dist/middleware/secure-headers/index.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/secure-headers/permissions-policy.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/secure-headers/secure-headers.js safe The code implements standard secure HTTP header middleware using safe cryptographic nonce generation and configuration handling, with no apparent malicious patterns.
dist/middleware/serve-static/index.js safe No malicious patterns detected; the code is a standard static file-serving middleware with path traversal protection and no suspicious network, filesystem, or execution behavior.
dist/middleware/serve-static/path.js safe The provided path-joining utility contains only pure string manipulation logic with no network, file system, process, or code execution capabilities, and displays no malicious patterns.
dist/middleware/timeout/index.js safe No malicious patterns detected
dist/middleware/timing/index.js safe Cleared by Jev triage; no further analysis needed
dist/middleware/timing/timing.js safe No malicious patterns detected; this is a standard Hono middleware for Server-Timing headers.
dist/middleware/trailing-slash/index.js safe No malicious patterns detected
dist/preset/quick.js safe No malicious patterns detected; the code is a standard Hono web framework preset with no security concerns.
dist/preset/tiny.js safe No malicious patterns detected
dist/request.js safe This is a legitimate part of the Hono web framework request handling code with no malicious patterns detected.
dist/request/constants.js safe No malicious patterns detected
dist/router.js safe No malicious patterns detected
dist/router/linear-router/index.js safe Cleared by Jev triage; no further analysis needed
dist/router/linear-router/router.js safe This is a benign linear router implementation for the Hono web framework with no malicious patterns, no network activity, no filesystem access, no process spawning, and no dynamic code execution.
dist/router/pattern-router/index.js safe Cleared by Jev triage; no further analysis needed
dist/router/pattern-router/router.js safe No malicious patterns detected in the pattern router implementation; it is a benign URL routing component with no network, file system, or process execution activity.
dist/router/reg-exp-router/index.js safe Cleared by Jev triage; no further analysis needed
dist/router/reg-exp-router/matcher.js safe No malicious patterns detected; the code is a benign routing matcher with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/router/reg-exp-router/node.js safe No malicious patterns detected; the code is a benign routing tree implementation with no network, filesystem, process, or dynamic execution behavior.
dist/router/reg-exp-router/prepared-router.js safe No malicious patterns detected; the code is a legitimate router implementation with no exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/router/reg-exp-router/router.js safe No malicious patterns detected in the provided router implementation; it is a standard regex-based route matcher from the Hono framework with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
dist/router/reg-exp-router/trie.js safe The code implements a trie data structure for route path parsing with regex-based tokenization; no malicious patterns, network calls, environment access, or dynamic execution were detected.
dist/router/smart-router/index.js safe Cleared by Jev triage; no further analysis needed
dist/router/smart-router/router.js safe No malicious patterns detected
dist/router/trie-router/index.js safe Cleared by Jev triage; no further analysis needed
dist/router/trie-router/node.js safe No malicious patterns detected; this is a legitimate trie-based router implementation for a web framework with no network, file system, process, or credential access.
dist/router/trie-router/router.js safe No malicious patterns detected
dist/types.js safe No malicious patterns detected
dist/utils/accept.js safe No malicious patterns detected; the code is a straightforward Accept header parser with no network, filesystem, process, or dynamic execution behavior.
dist/utils/basic-auth.js safe No malicious patterns detected; the code is a standard basic authentication header parser with no exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/utils/body.js safe No malicious patterns detected in this form-parsing utility; it only processes request bodies without network, filesystem, or process manipulation.
dist/utils/buffer.js safe No malicious patterns detected; the code contains standard buffer utility functions without any security concerns.
dist/utils/color.js safe The color utility code only checks environment variables for color settings and dynamically imports Cloudflare Workers module; no malicious patterns detected.
dist/utils/compress.js safe No malicious patterns detected
dist/utils/concurrent.js safe No malicious patterns detected; the file implements a generic concurrency pool without network, filesystem, process, or obfuscated code.
dist/utils/constants.js safe No malicious patterns detected
dist/utils/cookie.js safe The code implements cookie parsing and signing using Web Crypto API with no network, filesystem, process, or obfuscation patterns detected.
dist/utils/encode.js safe No malicious patterns detected; the file only provides standard Base64 and Base64URL encoding/decoding utilities using btoa/atob.
dist/utils/filepath.js safe No malicious patterns detected; the code performs path normalization and traversal prevention without any suspicious behavior.
dist/utils/handler.js safe No malicious patterns detected
dist/utils/headers.js safe Cleared by Jev triage; no further analysis needed
dist/utils/html.js safe No malicious patterns detected; the code is a benign HTML escaping and callback resolution utility with no network, filesystem, process, or dynamic code execution activity.
dist/utils/http-status.js safe Cleared by Jev triage; no further analysis needed
dist/utils/ipaddr.js safe Pure IPv4/IPv6 address manipulation utilities with no malicious patterns, network calls, or filesystem access.
dist/utils/jwt/index.js safe No malicious patterns detected
dist/utils/jwt/jwa.js safe No malicious patterns detected
dist/utils/jwt/jws.js safe No malicious patterns detected; the code is a standard JWT signing/verification utility using Web Crypto API.
dist/utils/jwt/types.js safe No malicious patterns detected; the file only defines JWT-related error classes and an enum for cryptographic key usage.
dist/utils/jwt/utf8.js safe No malicious patterns detected
dist/utils/mime.js safe No malicious patterns detected; the file is a simple MIME type lookup utility with no network, filesystem, process, or dynamic code execution activity.
dist/utils/stream.js safe No malicious patterns detected
dist/utils/types.js safe Cleared by Jev triage; no further analysis needed
dist/utils/url.js safe No malicious patterns detected
dist/validator/index.js safe Cleared by Jev triage; no further analysis needed
dist/validator/validator.js safe No malicious patterns detected; the code is a standard request body validation middleware for a web framework.

Scanned versions of hono

VersionVerdictFilesScanned
4.10.7 Needs review 362 Oct 4, 2026

Frequently asked questions

Is hono safe to use?

No confirmed malware was found in hono@4.10.7, but the review flagged 2 high, 16 medium, 24 low severity findings for risky patterns worth checking before you rely on it.

Does hono contain malware?

No malware was identified in hono@4.10.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was hono checked?

Togoder Security downloaded the published npm package and had an AI model read its 362 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan hono together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in hono@4.10.7, cost nothing.

Related security reports