# hono@4.10.7 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:32:59.000Z
- Files reviewed: 362
- Findings: 2 high, 16 medium, 24 low severity findings
- Report: https://security.togoder.click/npm/hono
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package hono@4.10.7 on Oct 4, 2026. An AI review of 362 source files produced 2 high, 16 medium, 24 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Insecure JWT Verification Algorithm Selection

Finding ID: `NPS-AC55BD7C6EF4`

File: `dist/utils/jwt/jwt.js`

In verifyWithJwks, the algorithm used for verification is taken from the matched JWK's 'alg' property (matchingKey.alg) or falls back to the token header's 'alg' (header.alg) rather than being explicitly constrained by the caller. If a JWKS endpoint provides keys with weak or attacker-influenced 'alg' values (or if the token header algorithm is trusted), this can lead to algorithm confusion or acceptance of tokens signed with unintended algorithms. While not direct malicious code, this is a significant security weakness in a JWT library.

### [high] Potential Algorithm Confusion via Header alg Fallback

Finding ID: `NPS-3656CE2B0003`

File: `dist/utils/jwt/jwt.js`

In verifyWithJwks, when a matching key is found, the verification algorithm is set to matchingKey.alg || header.alg. If matchingKey.alg is undefined, the algorithm from the untrusted token header is used, which could enable algorithm confusion attacks (e.g., forcing 'none' or asymmetric-to-symmetric confusion) if the key type mismatches. The isTokenHeader check only ensures 'alg' is one of the known AlgorithmTypes, but does not enforce that the key type matches the algorithm.

### [medium] dangerouslySetInnerHTML usage

Finding ID: `NPS-285723FCC548`

File: `dist/cjs/jsx/dom/render.js`

The applyProps function directly assigns untrusted __html content to container.innerHTML when the 'dangerouslySetInnerHTML' prop is used. This is standard React-like behavior but constitutes an XSS sink if untrusted data flows into __html.

### [medium] Unvalidated HTTP method override

Finding ID: `NPS-1521774BDF3F`

File: `dist/cjs/middleware/method-override/index.js:36`

The middleware accepts an arbitrary method string from user-controlled input (form field, header, or query parameter) and passes it directly as the `method` of a new Request. There is no allowlist validation, so an attacker can set the method to any value (e.g., CONNECT, TRACE, or custom verbs), potentially bypassing upstream security controls that only inspect c.req.method before this middleware runs.

### [medium] Header/body confusion in method override

Finding ID: `NPS-6B4A1D23E36A`

File: `dist/cjs/middleware/method-override/index.js:63`

When overriding via header, the original body (c.req.raw.body) is forwarded to the internally dispatched request while the method changes (e.g., GET to POST/DELETE). This breaks the typical assumption that GET has no body and may cause downstream handlers or proxies to misinterpret or smuggle requests.

### [medium] Query-based method override bypass

Finding ID: `NPS-C08D95106E13`

File: `dist/cjs/middleware/method-override/index.js:75`

The query-string override path copies the original request body and headers unchanged into a request with an attacker-specified method. Because the method can be arbitrary and no validation is performed, this can be abused to reach handlers that should not be reachable for the original method, and the override is not removed by intermediaries that do their own parsing.

### [medium] Network Request with External Input

Finding ID: `NPS-354FBEB208D3`

File: `dist/cjs/utils/jwt/jwt.js:130`

The verifyWithJwks function performs an unvalidated fetch to options.jwks_uri. If this URI originates from untrusted input, it could enable SSRF or trigger unexpected network requests. However, the URI is typically configured by the developer, not derived from the token itself.

### [medium] Algorithm Confusion Risk

Finding ID: `NPS-9001BB599EA4`

File: `dist/cjs/utils/jwt/jwt.js:152`

In verifyWithJwks, the algorithm is taken from the JWKS key (matchingKey.alg) falling back to the token header's alg. If the JWKS key does not specify alg, an attacker-controlled token header could dictate the algorithm used for verification, potentially enabling algorithm-confusion attacks. The verify function itself accepts an alg parameter that is trusted from the caller, but verifyWithJwks derives it partly from token data.

### [medium] Dynamic code generation via string interpolation

Finding ID: `NPS-2E75825485A9`

File: `dist/helper/css/index.js`

The code builds an inline <script> tag string: `<script${nonce ? ` nonce="${nonce}"` : ""}>document.querySelector('#${id}').textContent+=${JSON.stringify(stylesStr)}</script>`. While this pattern is part of the intended SSR CSS helper behavior (injecting styles at runtime), it dynamically constructs JavaScript that is executed in the browser. If the `id` or `nonce` values are attacker-controlled, this could lead to DOM-based XSS or script injection. In practice, `id` is defined by the library author (DEFAULT_STYLE_ID) and `nonce` comes from the developer, so exploitability is limited, but the pattern of generating inline scripts is a notable security-relevant behavior.

### [medium] Dynamic code execution via inline script generation

Finding ID: `NPS-EB92C9EC82CE`

File: `dist/jsx/components.js`

The code generates inline <script> tags containing JavaScript that manipulates the DOM. While this is intended for streaming SSR error boundaries, it introduces XSS-like behavior by embedding dynamically generated script content. If the scriptNonce is not properly enforced or if user-controlled data reaches the template IDs or content, it could lead to arbitrary script execution.

### [medium] Use of eval-like behavior through new Function or similar

Finding ID: `NPS-0D74190124D8`

File: `dist/jsx/components.js`

Although no explicit eval/new Function is present, the code constructs and injects JavaScript strings that are executed in the browser. This dynamic script generation can be abused if inputs are not sanitized, potentially leading to code injection.

### [medium] Potential XSS via unsanitized content injection

Finding ID: `NPS-F0A1C8B2B138`

File: `dist/jsx/components.js`

The ErrorBoundary component injects fallback HTML and children content directly into templates and script blocks without explicit sanitization in this file. If the content originates from untrusted sources, it could lead to cross-site scripting (XSS).

### [medium] Dynamic attribute/property assignment via user-controlled keys

Finding ID: `NPS-69F289CDC8EA`

File: `dist/jsx/dom/render.js:50`

applyProps iterates over all keys in attributes and assigns to DOM properties (e.g., container.value, container[key]) or attributes. While this is typical for a renderer, if attributes originate from untrusted sources, it could allow property clobbering or prototype pollution (e.g., setting '__proto__' or 'constructor' through attributes). No explicit sanitization of keys is performed before using them in bracket notation or setAttribute.

### [medium] Dynamic code execution via innerHTML

Finding ID: `NPS-E759052B5802`

File: `dist/jsx/dom/render.js:81`

The 'dangerouslySetInnerHTML' prop is honored by directly assigning to container.innerHTML, which can lead to XSS if used with untrusted data. This is a known React-like API but remains a potential security risk if developers pass unsanitized content.

### [medium] Setting element attributes from untrusted values

Finding ID: `NPS-BF8C652F7CF5`

File: `dist/jsx/dom/render.js:148`

Attributes are set via setAttribute after being stringified. If attribute names or values come from untrusted input, this could set event handlers or dangerous attributes (e.g., 'srcdoc', 'href:javascript:...'). No allowlist is present.

### [medium] Permissive CORS configuration

Finding ID: `NPS-401E31729A63`

File: `dist/middleware/cors/index.js:5`

The default origin is set to '*', which allows any origin to access the resource. If credentials are enabled (opts.credentials), this can lead to unauthorized access. However, this is a common default and not inherently malicious.

### [medium] Weak cryptographic algorithms exposed

Finding ID: `NPS-B461796E505E`

File: `dist/utils/crypto.js:8`

The module exports md5 and sha1 helpers that use MD5 and SHA-1, which are cryptographically broken for collision resistance and unsuitable for security-sensitive hashing. While not inherently malicious, exposing them as general-purpose crypto utilities can lead to insecure usage in downstream applications.

### [medium] Remote JWKS Fetch Without Origin Validation

Finding ID: `NPS-2F4646A43299`

File: `dist/utils/jwt/jwt.js`

verifyWithJwks performs a fetch to options.jwks_uri without validating the URI scheme/host against an allowlist. A caller passing attacker-controlled jwks_uri could cause the process to make arbitrary outbound requests (SSRF). This is a design-level risk rather than injected malicious code.

### [low] File system write

Finding ID: `NPS-346323E955AA`

File: `dist/adapter/bun/ssg.js:7`

The code defines a writeFile function that writes files to disk using Bun's write API. This is standard SSG (static site generation) functionality for persisting generated output and is scoped to the generator's output paths, not arbitrary file system manipulation.

### [low] No-op mkdir

Finding ID: `NPS-EA3027E273D7`

File: `dist/adapter/bun/ssg.js:10`

The mkdir function is a no-op stub that does nothing. This could cause failures if the base SSG helper expects directory creation, but it is not a malicious pattern—just potentially incomplete implementation.

### [low] global crypto polyfill

Finding ID: `NPS-B8D351493005`

File: `dist/adapter/lambda-edge/handler.js:4`

The line `globalThis.crypto ??= crypto;` assigns Node's crypto module to the global crypto object if it is not already defined. This is a common pattern in edge runtimes that lack a Web Crypto implementation and is not inherently malicious, but it does modify global state at import time.

### [low] environment variable and credential harvesting

Finding ID: `NPS-3D5874EA5AF4`

File: `dist/cjs/client/client.js`

The client automatically includes cookies in requests via args.cookie and also merges headers from user-provided options. While not directly reading files, this is a common pattern used to exfiltrate session cookies or credentials if the client is used with attacker-controlled URLs.

### [low] dynamic code execution via Proxy

Finding ID: `NPS-E7FE4499FC47`

File: `dist/cjs/client/client.js`

The code uses a Proxy to intercept property access and function calls, dynamically building request paths and methods. This obfuscates control flow and could hide malicious behavior if the callback were modified, but currently only constructs HTTP requests.

### [low] suspicious network requests

Finding ID: `NPS-E64BC3BDED5A`

File: `dist/cjs/client/client.js`

The client can create WebSocket connections and arbitrary HTTP requests to any URL provided by the caller. This is expected for an HTTP client library, but could be abused for data exfiltration if the library is used in a malicious context.

### [low] Environment Variable Access

Finding ID: `NPS-7D37317E0741`

File: `dist/cjs/helper/adapter/index.js:19`

The code accesses process.env and Deno.env.toObject() to provide environment variables based on runtime. This is a common pattern in runtime-adapter libraries and does not exfiltrate or harvest credentials; it only returns environment variables to the caller within the same process.

### [low] DOM attribute/element manipulation

Finding ID: `NPS-657E6B7DC00A`

File: `dist/cjs/jsx/dom/render.js`

Extensive direct DOM manipulation including setAttribute, innerHTML, and dynamic element creation. This is expected rendering logic for a JSX/JSX-DOM library but increases attack surface if user-controlled props are not sanitized.

### [low] Dynamic event handler registration

Finding ID: `NPS-27618F770252`

File: `dist/cjs/jsx/dom/render.js`

Event handlers are attached dynamically via addEventListener based on prop names matching /^on[A-Z]/ patterns. No validation of handler origin, but handlers are expected to be functions provided by the developer.

### [low] insecure_comparison

Finding ID: `NPS-474E9C64AD79`

File: `dist/cjs/utils/buffer.js:28`

The equal function compares byte-by-byte in a loop that returns early on mismatch, which is not constant-time. It is named 'equal' but is not timing-safe, which could be misleading. However, a separate timingSafeEqual exists. Not malicious.

### [low] timing_side_channel

Finding ID: `NPS-1ADBAE02AEED`

File: `dist/cjs/utils/buffer.js:42`

The timingSafeEqual function hashes inputs with SHA-256 then compares hashes with ===, which is not constant-time and may leak timing information about the hash comparison. It also checks a === b after hashing, which is redundant and could short-circuit. This is a cryptographic weakness, not a malicious pattern.

### [low] Mutable Global State / Prototype Pollution Risk

Finding ID: `NPS-DB50CDDE6246`

File: `dist/cjs/utils/jwt/jwt.js:139`

verifyWithJwks mutates the caller-supplied options object by pushing into options.keys or assigning options.keys = data.keys. This can cause unintended side effects if the same options object is reused across calls, and in edge cases could be leveraged to pollute shared state.

### [low] Use of new RegExp with dynamic template input

Finding ID: `NPS-864DD2A284D9`

File: `dist/helper/css/index.js`

`new RegExp(`(<style id="${id}"(?: nonce="[^"]*")?>.*?)(</style>)`)` constructs a regex from a template literal containing the `id` value. If `id` contains regex metacharacters, it could alter matching behavior. This is a correctness/robustness concern rather than a direct malicious pattern; no exfiltration or execution is performed here.

### [low] Suspicious network or process activity

Finding ID: `NPS-FAB6DCA90CC5`

File: `dist/jsx/components.js`

No network requests, file system access, or process spawning are present. The code operates solely on in-memory string manipulation and DOM rendering logic.

### [low] Timing attack mitigation

Finding ID: `NPS-FDF50FA1F4B6`

File: `dist/middleware/basic-auth/index.js:32`

The code uses timingSafeEqual for comparing usernames and passwords, which is a good security practice to prevent timing attacks.

### [low] Function-based origin validation

Finding ID: `NPS-D8E03B61379B`

File: `dist/middleware/cors/index.js:20`

The origin option can be a function, which receives the request origin and context. This allows arbitrary logic, but in the context of a middleware, it is expected. No malicious behavior observed.

### [low] Potential origin reflection vulnerability

Finding ID: `NPS-473E89A4F9CE`

File: `dist/middleware/cors/index.js:23`

When origin is set to a string (not '*'), the code reflects the request origin if it matches. This is standard, but if the allowed origin list is misconfigured or if a function is provided that returns a user-controlled value, it could lead to security issues. This is a design concern, not malicious.

### [low] input validation

Finding ID: `NPS-BC191E71795C`

File: `dist/middleware/request-id/request-id.js:9`

The middleware validates the incoming X-Request-Id header using a regex ( /[^\w\-=]/ ) and a length limit to prevent header injection or log injection. This is a positive security control, not a vulnerability.

### [low] Environment variable or credential access

Finding ID: `NPS-E4897B718EC5`

File: `dist/middleware/secure-headers/secure-headers.js`

No access to environment variables, credential files, or sensitive system paths detected.

### [low] Dynamic code execution

Finding ID: `NPS-5058844F2BF8`

File: `dist/middleware/secure-headers/secure-headers.js`

No eval, Function constructor, or similar dynamic code execution mechanisms present.

### [low] Network exfiltration

Finding ID: `NPS-C76AD1399E56`

File: `dist/middleware/secure-headers/secure-headers.js`

No outbound network requests, external URL communications, or data exfiltration patterns identified.

### [low] Suspicious file system or process manipulation

Finding ID: `NPS-48AB41B9398B`

File: `dist/middleware/secure-headers/secure-headers.js`

No file system writes outside package scope, child process spawning, or shell command execution found.

### [low] Nonce generation using crypto

Finding ID: `NPS-8D47B4EB4733`

File: `dist/middleware/secure-headers/secure-headers.js:29`

Uses crypto.getRandomValues for generating CSP nonces, which is a secure and appropriate use for cryptographic randomness. No malicious intent or external data transmission observed.

### [low] Potential silent failure

Finding ID: `NPS-D982E2C47D56`

File: `dist/utils/crypto.js:45`

When WebCrypto is unavailable (crypto.subtle is falsy), createHash returns null instead of throwing an error. Callers may inadvertently treat null as a valid hash and proceed insecurely, masking environment issues.

## Files reviewed

- `dist/cjs/client/client.js` (medium): The code is a standard HTTP/WebSocket client library with no obvious malicious patterns, but its dynamic proxy-based API and automatic cookie/header handling could be misused in a supply-chain attack.
- `dist/cjs/jsx/dom/render.js` (medium): This is a legitimate JSX DOM rendering implementation for the Hono framework; no malicious patterns such as data exfiltration, credential harvesting, code execution, or network calls were detected, though it contains standard XSS sinks (innerHTML) that require safe usage by callers.
- `dist/cjs/middleware/method-override/index.js` (medium): The code is a legitimate method-override middleware, but it permits arbitrary, unvalidated HTTP methods from user input, which can enable method-based access-control bypasses and request-smuggling style behavior.
- `dist/cjs/utils/jwt/jwt.js` (medium): This is a standard JWT implementation without overt malicious patterns, but it contains a few security-relevant weaknesses (SSRF-capable fetch of jwks_uri, mutation of caller-supplied options, and potential algorithm confusion when JWKS keys lack an explicit alg) that warrant a warning rather than a clean bill of health.
- `dist/helper/css/index.js` (medium): This appears to be a legitimate CSS-in-JS helper library that dynamically generates inline style/script tags for SSR; no data exfiltration, credential harvesting, backdoors, or obfuscated payloads were found, but the inline script generation and dynamic RegExp construction warrant a warning.
- `dist/jsx/components.js` (medium): The code implements a streaming error boundary for SSR with dynamic inline script generation, which poses a medium risk of XSS if nonce validation or input sanitization is insufficient, but no direct malicious patterns like data exfiltration or backdoors were found.
- `dist/jsx/dom/render.js` (medium): The code is a legitimate DOM rendering library but contains patterns like innerHTML assignment and dynamic property/attribute setting that could be risky if misused with untrusted data; no malicious behavior is evident.
- `dist/middleware/cors/index.js` (medium): The code is a standard CORS middleware implementation with permissive default settings but no malicious patterns detected.
- `dist/utils/crypto.js` (medium): No malicious behavior (exfiltration, backdoors, install-time code, network calls, process spawning) was found; only weak legacy hash algorithms (MD5, SHA-1) and a silent null return are flagged as cryptographic hygiene concerns.
- `dist/utils/jwt/jwt.js` (medium): The JWT utility code contains no malicious exfiltration, credential harvesting, obfuscation, or backdoor patterns, but it exhibits security weaknesses in JWKS-based verification, particularly trusting key/header-supplied algorithm values.
- `dist/adapter/aws-lambda/handler.js` (safe): No malicious patterns detected; the code is a standard AWS Lambda adapter for a web framework with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `dist/adapter/aws-lambda/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/aws-lambda/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/bun/conninfo.js` (safe): No malicious patterns detected; the code simply retrieves connection information from the Bun server.
- `dist/adapter/bun/index.js` (safe): No malicious patterns detected; this is a simple ES module re-exporting Bun adapter utilities (static serving, websocket, SSG, connection info).
- `dist/adapter/bun/serve-static.js` (safe): No malicious patterns detected; the code is a benign static file serving adapter with no network, filesystem, or process manipulation beyond reading files.
- `dist/adapter/bun/server.js` (safe): No malicious patterns detected
- `dist/adapter/bun/ssg.js` (safe): The code is a benign SSG adapter for Bun that writes generated static files to disk; no exfiltration, credential harvesting, obfuscation, or backdoor patterns were detected.
- `dist/adapter/bun/websocket.js` (safe): No malicious patterns detected; the code is a standard WebSocket adapter for Bun with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `dist/adapter/cloudflare-pages/handler.js` (safe): No malicious patterns detected; the file is a standard Cloudflare Pages adapter handler with no network, filesystem, credential, or code-execution abuse.
- `dist/adapter/cloudflare-pages/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/cloudflare-workers/conninfo.js` (safe): No malicious patterns detected
- `dist/adapter/cloudflare-workers/index.js` (safe): The file is a simple re-export module for Cloudflare Workers adapter utilities with no malicious patterns detected.
- `dist/adapter/cloudflare-workers/serve-static-module.js` (safe): No malicious patterns detected; the file is a simple wrapper re-exporting a serveStatic function.
- `dist/adapter/cloudflare-workers/serve-static.js` (safe): No malicious patterns detected; the code is a straightforward static file serving adapter for Cloudflare Workers.
- `dist/adapter/cloudflare-workers/utils.js` (safe): No malicious patterns detected; the code is a benign Cloudflare Workers adapter utility for retrieving assets from KV storage.
- `dist/adapter/cloudflare-workers/websocket.js` (safe): No malicious patterns detected; the code is a legitimate Cloudflare Workers WebSocket adapter from Hono.
- `dist/adapter/deno/conninfo.js` (safe): No malicious patterns detected
- `dist/adapter/deno/deno.d.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/deno/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/deno/serve-static.js` (safe): The code is a standard Deno adapter for serving static files without any malicious patterns such as exfiltration, obfuscation, or credential harvesting.
- `dist/adapter/deno/ssg.js` (safe): No malicious patterns detected; the code is a straightforward Deno static site generation adapter using Deno's file system APIs.
- `dist/adapter/deno/websocket.js` (safe): No malicious patterns detected; the code is a legitimate Deno WebSocket adapter with no exfiltration, obfuscation, process spawning, or install-time execution.
- `dist/adapter/lambda-edge/conninfo.js` (safe): This is a simple utility function that extracts the client IP address from AWS Lambda@Edge event records, with no malicious patterns detected.
- `dist/adapter/lambda-edge/handler.js` (safe): No malicious patterns detected; the code is a legitimate AWS Lambda@Edge adapter that modifies the global crypto object as a polyfill.
- `dist/adapter/lambda-edge/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/netlify/handler.js` (safe): No malicious patterns detected
- `dist/adapter/netlify/index.js` (safe): No malicious patterns detected
- `dist/adapter/netlify/mod.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/service-worker/handler.js` (safe): No malicious patterns detected; the code is a legitimate service worker fetch handler with a fallback to network fetch on 404 responses.
- `dist/adapter/service-worker/index.js` (safe): No malicious patterns detected; the code is a minimal service worker adapter that registers a fetch event listener.
- `dist/adapter/service-worker/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/adapter/vercel/conninfo.js` (safe): No malicious patterns detected; the code simply extracts the remote IP address from a request header.
- `dist/adapter/vercel/handler.js` (safe): No malicious patterns detected
- `dist/adapter/vercel/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/cjs/adapter/aws-lambda/handler.js` (safe): No malicious patterns detected; the code is a legitimate AWS Lambda adapter for SvelteKit that processes events and responses without any data exfiltration, credential harvesting, or dynamic code execution.
- `dist/cjs/adapter/aws-lambda/index.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/aws-lambda/types.js` (safe): No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
- `dist/cjs/adapter/bun/conninfo.js` (safe): No malicious patterns detected; the code only retrieves connection info from the Bun server for HTTP request handling.
- `dist/cjs/adapter/bun/index.js` (safe): No malicious patterns detected; the file is a standard CommonJS transpiled module that re-exports submodules without any dynamic execution, network, or filesystem activity.
- `dist/cjs/adapter/bun/serve-static.js` (safe): The code is a Bun adapter for a static file serving middleware, using standard filesystem and path utilities with no malicious patterns detected.
- `dist/cjs/adapter/bun/server.js` (safe): The file contains only standard CommonJS-to-ESM interop helpers and a simple accessor for Bun server context; no malicious patterns, dynamic code execution, network calls, credential access, or filesystem/process manipulation were detected.
- `dist/cjs/adapter/bun/ssg.js` (safe): No malicious patterns detected; code is a straightforward Bun-specific SSG adapter that writes files via the Bun API. The target path 'dist/cjs/adapter/bun/ssg.js' matches a known Hono framework adapter file, and no exfiltration, obfuscation, or credential harvesting was found.
- `dist/cjs/adapter/bun/websocket.js` (safe): No malicious patterns detected; the code is a legitimate Bun WebSocket adapter with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/cjs/adapter/cloudflare-pages/handler.js` (safe): No malicious patterns detected; the code is a standard Cloudflare Pages adapter handler with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `dist/cjs/adapter/cloudflare-pages/index.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/cloudflare-workers/conninfo.js` (safe): No malicious patterns detected; the code is a simple Cloudflare Workers adapter that reads the 'cf-connecting-ip' header.
- `dist/cjs/adapter/cloudflare-workers/index.js` (safe): This is a standard compiled CommonJS module that re-exports functions from local files, with no malicious patterns detected.
- `dist/cjs/adapter/cloudflare-workers/serve-static-module.js` (safe): This file is standard CJS interop wrapper code for a static file serving module with no suspicious behavior, network calls, process spawning, or obfuscation.
- `dist/cjs/adapter/cloudflare-workers/serve-static.js` (safe): No malicious patterns detected in the provided JavaScript file.
- `dist/cjs/adapter/cloudflare-workers/utils.js` (safe): No malicious patterns detected; the code is a standard Cloudflare Workers adapter utility for retrieving static assets from a KV namespace.
- `dist/cjs/adapter/cloudflare-workers/websocket.js` (safe): The code implements a standard WebSocket upgrade handler for Cloudflare Workers with no malicious patterns detected.
- `dist/cjs/adapter/deno/conninfo.js` (safe): No malicious patterns detected; the code is a simple connection info adapter with standard module boilerplate.
- `dist/cjs/adapter/deno/deno.d.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/deno/index.js` (safe): This is a standard CommonJS module wrapper that re-exports functions from Deno adapter modules without any malicious patterns.
- `dist/cjs/adapter/deno/serve-static.js` (safe): No malicious patterns detected; the code implements a standard static file serving adapter for Deno using safe filesystem operations.
- `dist/cjs/adapter/deno/ssg.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/deno/websocket.js` (safe): Code is a legitimate WebSocket adapter for Deno runtime with no malicious patterns, exfiltration, or backdoors detected.
- `dist/cjs/adapter/lambda-edge/conninfo.js` (safe): No malicious patterns detected; the code simply reads the client IP from AWS Lambda@Edge CloudFront event records without any exfiltration, dynamic execution, or suspicious behavior.
- `dist/cjs/adapter/lambda-edge/handler.js` (safe): No malicious patterns detected; the code is a standard Lambda@Edge adapter for an HTTP framework with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/cjs/adapter/lambda-edge/index.js` (safe): This is a standard CommonJS module transpiled from ESM with no suspicious behavior; it only re-exports handler and conninfo functions.
- `dist/cjs/adapter/netlify/handler.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/netlify/index.js` (safe): This is a standard CommonJS re-export shim generated by esbuild/rollup; it only re-exports the ./mod module and contains no malicious patterns.
- `dist/cjs/adapter/netlify/mod.js` (safe): No malicious patterns detected; the file is a standard CommonJS adapter module that re-exports a handler function from a local sibling module without any suspicious behavior.
- `dist/cjs/adapter/service-worker/handler.js` (safe): The service worker handler is a standard fetch fallback implementation with no malicious patterns, obfuscation, exfiltration, or risky behavior.
- `dist/cjs/adapter/service-worker/index.js` (safe): No malicious patterns detected; the code is a standard CommonJS bundler output for a service worker adapter that registers a fetch event listener.
- `dist/cjs/adapter/service-worker/types.js` (safe): No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
- `dist/cjs/adapter/vercel/conninfo.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/vercel/handler.js` (safe): No malicious patterns detected
- `dist/cjs/adapter/vercel/index.js` (safe): No malicious patterns detected
- `dist/cjs/client/fetch-result-please.js` (safe): No malicious patterns detected; the code is a standard fetch response parsing utility with no exfiltration, credential harvesting, obfuscation, or system-level operations.
- `dist/cjs/client/index.js` (safe): This is a standard CJS bundle entry point that re-exports named symbols from internal modules with no executable, network, filesystem, or obfuscated behavior.
- `dist/cjs/client/types.js` (safe): No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
- `dist/cjs/client/utils.js` (safe): No malicious patterns detected
- `dist/cjs/compose.js` (safe): No malicious patterns detected; the code implements standard middleware composition similar to Koa-style dispatch with no external calls, file access, or dynamic execution.
- `dist/cjs/context.js` (safe): The code is a standard Hono framework Context class with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network requests, or filesystem manipulation.
- `dist/cjs/helper/accepts/accepts.js` (safe): No malicious patterns detected; the code is a standard implementation of HTTP Accept header content negotiation with no network, filesystem, environment, or dynamic execution concerns.
- `dist/cjs/helper/accepts/index.js` (safe): No malicious patterns detected
- `dist/cjs/helper/adapter/index.js` (safe): No malicious patterns detected; the code is a standard runtime environment adapter that reads environment variables without exfiltration or other harmful behavior.
- `dist/cjs/helper/conninfo/index.js` (safe): No malicious patterns detected
- `dist/cjs/helper/conninfo/types.js` (safe): No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
- `dist/cjs/helper/cookie/index.js` (safe): No malicious patterns detected
- `dist/cjs/helper/css/common.js` (safe): No malicious patterns detected; the code is a CSS utility library with no network, filesystem, process, or obfuscated execution behaviors.
- `dist/cjs/helper/css/index.js` (safe): No malicious patterns detected; the code is a standard CSS-in-JS helper library with no data exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
- `dist/cjs/helper/dev/index.js` (safe): No malicious patterns detected
- `dist/cjs/helper/factory/index.js` (safe): No malicious patterns detected; the code is a standard Hono.js helper factory with no network, filesystem, process, or obfuscated activity.
- `dist/cjs/helper/html/index.js` (safe): No malicious patterns detected; the code is a standard tagged template literal HTML escaping helper with no network, filesystem, process, or dynamic code execution activity.
- `dist/cjs/helper/proxy/index.js` (safe): No malicious patterns detected; the code implements a standard HTTP proxy helper with header sanitization.
- `dist/cjs/helper/route/index.js` (safe): No malicious patterns detected; the code is a standard routing utility with no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `dist/cjs/helper/ssg/index.js` (safe): No malicious patterns detected; the file is a standard CommonJS re-export helper with no suspicious behavior.
- `dist/cjs/helper/ssg/middleware.js` (safe): No malicious patterns detected
- `dist/cjs/helper/ssg/ssg.js` (safe): No malicious patterns detected; the code is a legitimate static site generation (SSG) helper for the Hono framework.
- `dist/cjs/helper/ssg/utils.js` (safe): The code contains only routine path manipulation and route filtering utilities with no malicious patterns, external calls, or dynamic execution.
- `dist/cjs/helper/streaming/index.js` (safe): No malicious patterns detected; the file is a standard CommonJS re-export module for streaming helpers.
- `dist/cjs/helper/streaming/sse.js` (safe): No malicious patterns detected; the code implements Server-Sent Events streaming with standard utilities and no exfiltration, obfuscation, or unauthorized system access.
- `dist/cjs/helper/streaming/stream.js` (safe): No malicious patterns detected; the file contains standard streaming helper utilities with no exfiltration, obfuscation, or suspicious behavior.
- `dist/cjs/helper/streaming/text.js` (safe): No malicious patterns detected; the file is a benign streaming helper with standard CommonJS bundler boilerplate and security-hardening headers.
- `dist/cjs/helper/streaming/utils.js` (safe): No malicious patterns detected
- `dist/cjs/helper/testing/index.js` (safe): No malicious patterns detected; the code is a standard testing helper that creates a client with a custom fetch function.
- `dist/cjs/helper/websocket/index.js` (safe): No malicious patterns detected; this is a WebSocket context helper with no network, filesystem, process, or dynamic code execution behavior.
- `dist/cjs/hono-base.js` (safe): No malicious patterns detected in the provided HonoBase source code.
- `dist/cjs/hono.js` (safe): No malicious patterns detected; this is a standard Hono framework entry point with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/cjs/http-exception.js` (safe): No malicious patterns detected; the file is a standard HTTPException class definition using Web Fetch API Response objects.
- `dist/cjs/index.js` (safe): The file contains only standard CommonJS module bundling boilerplate and re-exports Hono from a local import; no malicious patterns, obfuscation, network calls, or process execution were detected.
- `dist/cjs/jsx/base.js` (safe): No malicious patterns detected; the code is a legitimate JSX runtime implementation for the Hono framework with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
- `dist/cjs/jsx/children.js` (safe): No malicious patterns detected
- `dist/cjs/jsx/components.js` (safe): No malicious patterns detected; the code implements server-side JSX error boundary rendering with template replacement and inline script nonce handling typical of the Hono framework.
- `dist/cjs/jsx/constants.js` (safe): No malicious patterns detected; the file only defines and exports Symbol constants using standard CommonJS interop helpers.
- `dist/cjs/jsx/context.js` (safe): No malicious patterns detected; the file contains standard context management code for a JSX rendering library with no network, filesystem, process execution, or obfuscation concerns.
- `dist/cjs/jsx/dom/client.js` (safe): No malicious patterns detected; the file contains standard CommonJS boilerplate for exporting React-like DOM client functions with no network, filesystem, process execution, or obfuscated code.
- `dist/cjs/jsx/dom/components.js` (safe): No malicious patterns detected in the analyzed JavaScript file; it contains standard error boundary and suspense component implementations without any obfuscation, network activity, or system-level operations.
- `dist/cjs/jsx/dom/context.js` (safe): No malicious patterns detected; the file contains standard React-like context creation logic with no network, filesystem, process, or obfuscation concerns.
- `dist/cjs/jsx/dom/css.js` (safe): No malicious patterns detected; the file is a legitimate CSS-in-JS runtime without exfiltration, credential access, dynamic execution, or network activity.
- `dist/cjs/jsx/dom/hooks/index.js` (safe): No malicious patterns detected; the file contains standard React-like hook implementations for form status, optimistic updates, and action state management.
- `dist/cjs/jsx/dom/index.js` (safe): No malicious patterns detected
- `dist/cjs/jsx/dom/intrinsic-element/components.js` (safe): No malicious patterns detected
- `dist/cjs/jsx/dom/jsx-dev-runtime.js` (safe): No malicious patterns detected; this is a normal JSX dev runtime helper file with standard CJS/ESM interop boilerplate.
- `dist/cjs/jsx/dom/jsx-runtime.js` (safe): No malicious patterns detected
- `dist/cjs/jsx/dom/server.js` (safe): No malicious patterns detected; the code is standard compiled output for server-side JSX rendering with no network, filesystem, or process manipulation.
- `dist/cjs/jsx/dom/utils.js` (safe): No malicious patterns detected; the code is a standard CommonJS wrapper for exporting a utility function.
- `dist/cjs/jsx/hooks/index.js` (safe): No malicious patterns detected; the code implements standard React-like hooks with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity.
- `dist/cjs/jsx/index.js` (safe): No malicious patterns detected; the file is a standard compiled JSX runtime barrel export with no suspicious network, filesystem, or process activity.
- `dist/cjs/jsx/intrinsic-element/common.js` (safe): No malicious patterns detected; the code is a standard CommonJS module with helper functions and constant exports.
- `dist/cjs/jsx/intrinsic-element/components.js` (safe): No malicious patterns detected; the code is a JSX intrinsic-element component library implementing head tag deduplication and metadata handling without any exfiltration, obfuscation, or process execution.
- `dist/cjs/jsx/intrinsic-elements.js` (safe): No malicious patterns detected; the file contains only CommonJS module boilerplate for exporting an empty object.
- `dist/cjs/jsx/jsx-dev-runtime.js` (safe): This is a standard JSX dev runtime helper module with no suspicious behavior, network activity, credential access, or dynamic code execution.
- `dist/cjs/jsx/jsx-runtime.js` (safe): No malicious patterns detected; this appears to be a standard JSX runtime helper module for server-side rendering with attribute escaping.
- `dist/cjs/jsx/streaming.js` (safe): No malicious patterns detected; the code implements JSX streaming/Suspense rendering with standard internal callbacks and no suspicious network, filesystem, or process activity.
- `dist/cjs/jsx/types.js` (safe): No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities.
- `dist/cjs/jsx/utils.js` (safe): No malicious patterns detected
- `dist/cjs/middleware/basic-auth/index.js` (safe): No malicious patterns detected; the code is a standard basic authentication middleware with no data exfiltration, process spawning, or dynamic code execution.
- `dist/cjs/middleware/bearer-auth/index.js` (safe): No malicious patterns detected; this is a standard bearer authentication middleware with no network exfiltration, credential harvesting, dynamic execution, or install-time hooks.
- `dist/cjs/middleware/body-limit/index.js` (safe): No malicious patterns detected; the code implements a body size limiting middleware with no exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/cjs/middleware/cache/index.js` (safe): No malicious patterns detected; the code implements a standard HTTP cache middleware using the Web Cache API without exfiltration, credential harvesting, obfuscation, or any suspicious behavior.
- `dist/cjs/middleware/combine/index.js` (safe): No malicious patterns detected; the code is a standard middleware composition utility with no network, filesystem, process, or obfuscated behavior.
- `dist/cjs/middleware/compress/index.js` (safe): No malicious patterns detected; the code is a standard response compression middleware with no network, filesystem, process, or obfuscation concerns.
- `dist/cjs/middleware/context-storage/index.js` (safe): No malicious patterns detected; the code is a standard AsyncLocalStorage-based context storage middleware with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `dist/cjs/middleware/cors/index.js` (safe): No malicious patterns detected
- `dist/cjs/middleware/csrf/index.js` (safe): No malicious patterns detected; the code implements a standard CSRF protection middleware for web frameworks.
- `dist/cjs/middleware/etag/digest.js` (safe): No malicious patterns detected; the code implements a standard streaming digest utility with no network, filesystem, or dynamic execution capabilities.
- `dist/cjs/middleware/etag/index.js` (safe): No malicious patterns detected in the ETag middleware implementation.
- `dist/cjs/middleware/ip-restriction/index.js` (safe): No malicious patterns detected; the code implements IP restriction middleware with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/file/process activity.
- `dist/cjs/middleware/jsx-renderer/index.js` (safe): No malicious patterns detected; the code is a standard JSX renderer middleware with no network, filesystem, process, or dynamic execution concerns.
- `dist/cjs/middleware/jwk/index.js` (safe): No malicious patterns detected
- `dist/cjs/middleware/jwk/jwk.js` (safe): No malicious patterns detected; the code implements standard JWK/JWT authentication middleware without exfiltration, credential harvesting, obfuscation, or suspicious dynamic behavior.
- `dist/cjs/middleware/jwt/index.js` (safe): The code is a standard CommonJS re-export module for JWT functionality with no malicious patterns detected.
- `dist/cjs/middleware/jwt/jwt.js` (safe): No malicious patterns detected; the code is a standard JWT middleware implementation with proper cryptographic verification and no exfiltration, obfuscation, or unauthorized system access.
- `dist/cjs/middleware/language/index.js` (safe): No malicious patterns detected
- `dist/cjs/middleware/language/language.js` (safe): Language detection middleware contains only standard localization logic with no malicious patterns, network activity, or dynamic code execution.
- `dist/cjs/middleware/logger/index.js` (safe): No malicious patterns detected; the code is a benign HTTP request logger middleware.
- `dist/cjs/middleware/powered-by/index.js` (safe): No malicious patterns detected; the file is a standard middleware helper that only sets the X-Powered-By response header.
- `dist/cjs/middleware/pretty-json/index.js` (safe): No malicious patterns detected; the code is a standard middleware for pretty-printing JSON responses.
- `dist/cjs/middleware/request-id/index.js` (safe): No malicious patterns detected; the file is a standard CommonJS re-export wrapper for the request-id middleware.
- `dist/cjs/middleware/request-id/request-id.js` (safe): No malicious patterns detected; the code is a benign request-ID middleware that reads a header, validates it, and sets a response header.
- `dist/cjs/middleware/secure-headers/index.js` (safe): No malicious patterns detected
- `dist/cjs/middleware/secure-headers/permissions-policy.js` (safe): No malicious patterns detected; the file contains only standard CommonJS module boilerplate and an empty exports object with no executable logic.
- `dist/cjs/middleware/secure-headers/secure-headers.js` (safe): No malicious patterns detected; the code is a legitimate secure headers middleware for setting HTTP security headers.
- `dist/cjs/middleware/serve-static/index.js` (safe): The code is a static file serving middleware with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
- `dist/cjs/middleware/serve-static/path.js` (safe): The code implements a safe, pure path-joining utility with no malicious patterns, external calls, or dangerous operations.
- `dist/cjs/middleware/timeout/index.js` (safe): No malicious patterns detected; the code is a legitimate timeout middleware implementation.
- `dist/cjs/middleware/timing/index.js` (safe): No malicious patterns detected; this is a standard TypeScript-compiled CommonJS re-export shim for a timing middleware module.
- `dist/cjs/middleware/timing/timing.js` (safe): No malicious patterns detected; the code implements a standard Server-Timing middleware with no data exfiltration, obfuscation, or system-level access.
- `dist/cjs/middleware/trailing-slash/index.js` (safe): No malicious patterns detected; the code implements standard trailing slash middleware with no exfiltration, obfuscation, or dangerous operations.
- `dist/cjs/preset/quick.js` (safe): No malicious patterns detected
- `dist/cjs/preset/tiny.js` (safe): No malicious patterns detected
- `dist/cjs/request.js` (safe): No malicious patterns detected; the code is a standard Hono framework request wrapper with benign request parsing and cloning utilities.
- `dist/cjs/request/constants.js` (safe): No malicious patterns detected
- `dist/cjs/router.js` (safe): No malicious patterns detected.
- `dist/cjs/router/linear-router/index.js` (safe): No malicious patterns detected; the file only contains standard CommonJS transpilation helper code for exporting a router class.
- `dist/cjs/router/linear-router/router.js` (safe): No malicious patterns detected; the code is a legitimate linear router implementation with standard module exports and path matching logic.
- `dist/cjs/router/pattern-router/index.js` (safe): This is a standard TypeScript/CommonJS build artifact re-exporting PatternRouter with no malicious patterns, dynamic execution, network activity, or filesystem access.
- `dist/cjs/router/pattern-router/router.js` (safe): No malicious patterns detected; the code implements a URL pattern router with no network, filesystem, process spawning, or dynamic code execution.
- `dist/cjs/router/reg-exp-router/index.js` (safe): No malicious patterns detected; the file only contains standard CommonJS module bundling boilerplate and re-exports from local router files.
- `dist/cjs/router/reg-exp-router/matcher.js` (safe): No malicious patterns detected
- `dist/cjs/router/reg-exp-router/node.js` (safe): This is a benign routing library implementation (reg-exp-router) that builds regular expressions from path tokens, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network activity, or process spawning.
- `dist/cjs/router/reg-exp-router/prepared-router.js` (safe): No malicious patterns detected in the provided JavaScript router implementation.
- `dist/cjs/router/reg-exp-router/router.js` (safe): No malicious patterns detected
- `dist/cjs/router/reg-exp-router/trie.js` (safe): No malicious patterns detected; the code implements a trie for router path parsing using standard string manipulation and regex, with no network, filesystem, process, or dynamic execution activity.
- `dist/cjs/router/smart-router/index.js` (safe): The file contains only standard CommonJS/ESM interop boilerplate and a clean re-export of SmartRouter with no malicious patterns detected.
- `dist/cjs/router/smart-router/router.js` (safe): No malicious patterns detected in this SmartRouter implementation, which only performs in-memory route registration and matching without any network, filesystem, process, or dynamic code execution activity.
- `dist/cjs/router/trie-router/index.js` (safe): No malicious patterns detected; the file is a standard CommonJS transpilation of a trie router module with no suspicious behavior.
- `dist/cjs/router/trie-router/node.js` (safe): No malicious patterns detected; the code is a standard routing trie implementation with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
- `dist/cjs/router/trie-router/router.js` (safe): No malicious patterns detected
- `dist/cjs/types.js` (safe): No malicious patterns detected
- `dist/cjs/utils/accept.js` (safe): No malicious patterns detected; the code only parses HTTP Accept headers with no network, filesystem, or dynamic execution behavior.
- `dist/cjs/utils/basic-auth.js` (safe): No malicious patterns detected; the code is a straightforward Basic Authentication header parser.
- `dist/cjs/utils/body.js` (safe): No malicious patterns detected in the body parsing utility; it only processes form data from incoming requests.
- `dist/cjs/utils/buffer.js` (safe): No malicious patterns detected; the code contains standard buffer utility functions with minor cryptographic timing weaknesses.
- `dist/cjs/utils/color.js` (safe): No malicious patterns detected; the code only checks standard environment variables and performs a guarded dynamic import for Cloudflare Workers compatibility.
- `dist/cjs/utils/compress.js` (safe): No malicious patterns detected; the file only exports a regular expression for compressible content types.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
