Summary
Togoder Security scanned the npm package hono@4.10.7 on Oct 4, 2026. An AI review of 362 source files produced 2 high, 16 medium, 24 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 42
Insecure JWT Verification Algorithm Selection
NPS-AC55BD7C6EF4
In verifyWithJwks, the algorithm used for verification is taken from the matched JWK's 'alg' property (matchingKey.alg) or falls back to the token header's 'alg' (header.alg) rather than being explicitly constrained by the caller. If a JWKS endpoint provides keys with weak or attacker-influenced 'alg' values (or if the token header algorithm is trusted), this can lead to algorithm confusion or acceptance of tokens signed with unintended algorithms. While not direct malicious code, this is a significant security weakness in a JWT library.
Potential Algorithm Confusion via Header alg Fallback
NPS-3656CE2B0003
In verifyWithJwks, when a matching key is found, the verification algorithm is set to matchingKey.alg || header.alg. If matchingKey.alg is undefined, the algorithm from the untrusted token header is used, which could enable algorithm confusion attacks (e.g., forcing 'none' or asymmetric-to-symmetric confusion) if the key type mismatches. The isTokenHeader check only ensures 'alg' is one of the known AlgorithmTypes, but does not enforce that the key type matches the algorithm.
dangerouslySetInnerHTML usage
NPS-285723FCC548
The applyProps function directly assigns untrusted __html content to container.innerHTML when the 'dangerouslySetInnerHTML' prop is used. This is standard React-like behavior but constitutes an XSS sink if untrusted data flows into __html.
Unvalidated HTTP method override
NPS-1521774BDF3F
The middleware accepts an arbitrary method string from user-controlled input (form field, header, or query parameter) and passes it directly as the method of a new Request. There is no allowlist validation, so an attacker can set the method to any value (e.g., CONNECT, TRACE, or custom verbs), potentially bypassing upstream security controls that only inspect c.req.method before this middleware runs.
Header/body confusion in method override
NPS-6B4A1D23E36A
When overriding via header, the original body (c.req.raw.body) is forwarded to the internally dispatched request while the method changes (e.g., GET to POST/DELETE). This breaks the typical assumption that GET has no body and may cause downstream handlers or proxies to misinterpret or smuggle requests.
Query-based method override bypass
NPS-C08D95106E13
The query-string override path copies the original request body and headers unchanged into a request with an attacker-specified method. Because the method can be arbitrary and no validation is performed, this can be abused to reach handlers that should not be reachable for the original method, and the override is not removed by intermediaries that do their own parsing.
Network Request with External Input
NPS-354FBEB208D3
The verifyWithJwks function performs an unvalidated fetch to options.jwks_uri. If this URI originates from untrusted input, it could enable SSRF or trigger unexpected network requests. However, the URI is typically configured by the developer, not derived from the token itself.
Algorithm Confusion Risk
NPS-9001BB599EA4
In verifyWithJwks, the algorithm is taken from the JWKS key (matchingKey.alg) falling back to the token header's alg. If the JWKS key does not specify alg, an attacker-controlled token header could dictate the algorithm used for verification, potentially enabling algorithm-confusion attacks. The verify function itself accepts an alg parameter that is trusted from the caller, but verifyWithJwks derives it partly from token data.
Dynamic code generation via string interpolation
NPS-2E75825485A9
The code builds an inline <script> tag string: <script${nonce ? nonce="${nonce}" : ""}>document.querySelector('#${id}').textContent+=${JSON.stringify(stylesStr)}</script>. While this pattern is part of the intended SSR CSS helper behavior (injecting styles at runtime), it dynamically constructs JavaScript that is executed in the browser. If the id or nonce values are attacker-controlled, this could lead to DOM-based XSS or script injection. In practice, id is defined by the library author (DEFAULT_STYLE_ID) and nonce comes from the developer, so exploitability is limited, but the pattern of generating inline scripts is a notable security-relevant behavior.
Dynamic code execution via inline script generation
NPS-EB92C9EC82CE
The code generates inline <script> tags containing JavaScript that manipulates the DOM. While this is intended for streaming SSR error boundaries, it introduces XSS-like behavior by embedding dynamically generated script content. If the scriptNonce is not properly enforced or if user-controlled data reaches the template IDs or content, it could lead to arbitrary script execution.
Use of eval-like behavior through new Function or similar
NPS-0D74190124D8
Although no explicit eval/new Function is present, the code constructs and injects JavaScript strings that are executed in the browser. This dynamic script generation can be abused if inputs are not sanitized, potentially leading to code injection.
Potential XSS via unsanitized content injection
NPS-F0A1C8B2B138
The ErrorBoundary component injects fallback HTML and children content directly into templates and script blocks without explicit sanitization in this file. If the content originates from untrusted sources, it could lead to cross-site scripting (XSS).
Dynamic attribute/property assignment via user-controlled keys
NPS-69F289CDC8EA
applyProps iterates over all keys in attributes and assigns to DOM properties (e.g., container.value, container[key]) or attributes. While this is typical for a renderer, if attributes originate from untrusted sources, it could allow property clobbering or prototype pollution (e.g., setting '__proto__' or 'constructor' through attributes). No explicit sanitization of keys is performed before using them in bracket notation or setAttribute.
Dynamic code execution via innerHTML
NPS-E759052B5802
The 'dangerouslySetInnerHTML' prop is honored by directly assigning to container.innerHTML, which can lead to XSS if used with untrusted data. This is a known React-like API but remains a potential security risk if developers pass unsanitized content.
Setting element attributes from untrusted values
NPS-BF8C652F7CF5
Attributes are set via setAttribute after being stringified. If attribute names or values come from untrusted input, this could set event handlers or dangerous attributes (e.g., 'srcdoc', 'href:javascript:...'). No allowlist is present.
Permissive CORS configuration
NPS-401E31729A63
The default origin is set to '*', which allows any origin to access the resource. If credentials are enabled (opts.credentials), this can lead to unauthorized access. However, this is a common default and not inherently malicious.
Weak cryptographic algorithms exposed
NPS-B461796E505E
The module exports md5 and sha1 helpers that use MD5 and SHA-1, which are cryptographically broken for collision resistance and unsuitable for security-sensitive hashing. While not inherently malicious, exposing them as general-purpose crypto utilities can lead to insecure usage in downstream applications.
Remote JWKS Fetch Without Origin Validation
NPS-2F4646A43299
verifyWithJwks performs a fetch to options.jwks_uri without validating the URI scheme/host against an allowlist. A caller passing attacker-controlled jwks_uri could cause the process to make arbitrary outbound requests (SSRF). This is a design-level risk rather than injected malicious code.
File system write
NPS-346323E955AA
The code defines a writeFile function that writes files to disk using Bun's write API. This is standard SSG (static site generation) functionality for persisting generated output and is scoped to the generator's output paths, not arbitrary file system manipulation.
No-op mkdir
NPS-EA3027E273D7
The mkdir function is a no-op stub that does nothing. This could cause failures if the base SSG helper expects directory creation, but it is not a malicious pattern—just potentially incomplete implementation.
global crypto polyfill
NPS-B8D351493005
The line globalThis.crypto ??= crypto; assigns Node's crypto module to the global crypto object if it is not already defined. This is a common pattern in edge runtimes that lack a Web Crypto implementation and is not inherently malicious, but it does modify global state at import time.
environment variable and credential harvesting
NPS-3D5874EA5AF4
The client automatically includes cookies in requests via args.cookie and also merges headers from user-provided options. While not directly reading files, this is a common pattern used to exfiltrate session cookies or credentials if the client is used with attacker-controlled URLs.
dynamic code execution via Proxy
NPS-E7FE4499FC47
The code uses a Proxy to intercept property access and function calls, dynamically building request paths and methods. This obfuscates control flow and could hide malicious behavior if the callback were modified, but currently only constructs HTTP requests.
suspicious network requests
NPS-E64BC3BDED5A
The client can create WebSocket connections and arbitrary HTTP requests to any URL provided by the caller. This is expected for an HTTP client library, but could be abused for data exfiltration if the library is used in a malicious context.
Environment Variable Access
NPS-7D37317E0741
The code accesses process.env and Deno.env.toObject() to provide environment variables based on runtime. This is a common pattern in runtime-adapter libraries and does not exfiltrate or harvest credentials; it only returns environment variables to the caller within the same process.
DOM attribute/element manipulation
NPS-657E6B7DC00A
Extensive direct DOM manipulation including setAttribute, innerHTML, and dynamic element creation. This is expected rendering logic for a JSX/JSX-DOM library but increases attack surface if user-controlled props are not sanitized.
Dynamic event handler registration
NPS-27618F770252
Event handlers are attached dynamically via addEventListener based on prop names matching /^on[A-Z]/ patterns. No validation of handler origin, but handlers are expected to be functions provided by the developer.
insecure_comparison
NPS-474E9C64AD79
The equal function compares byte-by-byte in a loop that returns early on mismatch, which is not constant-time. It is named 'equal' but is not timing-safe, which could be misleading. However, a separate timingSafeEqual exists. Not malicious.
timing_side_channel
NPS-1ADBAE02AEED
The timingSafeEqual function hashes inputs with SHA-256 then compares hashes with ===, which is not constant-time and may leak timing information about the hash comparison. It also checks a === b after hashing, which is redundant and could short-circuit. This is a cryptographic weakness, not a malicious pattern.
Mutable Global State / Prototype Pollution Risk
NPS-DB50CDDE6246
verifyWithJwks mutates the caller-supplied options object by pushing into options.keys or assigning options.keys = data.keys. This can cause unintended side effects if the same options object is reused across calls, and in edge cases could be leveraged to pollute shared state.
Use of new RegExp with dynamic template input
NPS-864DD2A284D9
new RegExp((<style id="${id}"(?: nonce="[^"]*")?>.*?)(</style>)) constructs a regex from a template literal containing the id value. If id contains regex metacharacters, it could alter matching behavior. This is a correctness/robustness concern rather than a direct malicious pattern; no exfiltration or execution is performed here.
Suspicious network or process activity
NPS-FAB6DCA90CC5
No network requests, file system access, or process spawning are present. The code operates solely on in-memory string manipulation and DOM rendering logic.
Timing attack mitigation
NPS-FDF50FA1F4B6
The code uses timingSafeEqual for comparing usernames and passwords, which is a good security practice to prevent timing attacks.
Function-based origin validation
NPS-D8E03B61379B
The origin option can be a function, which receives the request origin and context. This allows arbitrary logic, but in the context of a middleware, it is expected. No malicious behavior observed.
Potential origin reflection vulnerability
NPS-473E89A4F9CE
When origin is set to a string (not '*'), the code reflects the request origin if it matches. This is standard, but if the allowed origin list is misconfigured or if a function is provided that returns a user-controlled value, it could lead to security issues. This is a design concern, not malicious.
input validation
NPS-BC191E71795C
The middleware validates the incoming X-Request-Id header using a regex ( /[^\w\-=]/ ) and a length limit to prevent header injection or log injection. This is a positive security control, not a vulnerability.
Environment variable or credential access
NPS-E4897B718EC5
No access to environment variables, credential files, or sensitive system paths detected.
Dynamic code execution
NPS-5058844F2BF8
No eval, Function constructor, or similar dynamic code execution mechanisms present.
Network exfiltration
NPS-C76AD1399E56
No outbound network requests, external URL communications, or data exfiltration patterns identified.
Suspicious file system or process manipulation
NPS-48AB41B9398B
No file system writes outside package scope, child process spawning, or shell command execution found.
Nonce generation using crypto
NPS-8D47B4EB4733
Uses crypto.getRandomValues for generating CSP nonces, which is a secure and appropriate use for cryptographic randomness. No malicious intent or external data transmission observed.
Potential silent failure
NPS-D982E2C47D56
When WebCrypto is unavailable (crypto.subtle is falsy), createHash returns null instead of throwing an error. Callers may inadvertently treat null as a valid hash and proceed insecurely, masking environment issues.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/cjs/client/client.js | medium | The code is a standard HTTP/WebSocket client library with no obvious malicious patterns, but its dynamic proxy-based API and automatic cookie/header handling could be misused in a supply-chain attack. |
| dist/cjs/jsx/dom/render.js | medium | This is a legitimate JSX DOM rendering implementation for the Hono framework; no malicious patterns such as data exfiltration, credential harvesting, code execution, or network calls were detected, though it contains standard XSS sinks (innerHTML) that require safe usage by callers. |
| dist/cjs/middleware/method-override/index.js | medium | The code is a legitimate method-override middleware, but it permits arbitrary, unvalidated HTTP methods from user input, which can enable method-based access-control bypasses and request-smuggling style behavior. |
| dist/cjs/utils/jwt/jwt.js | medium | This is a standard JWT implementation without overt malicious patterns, but it contains a few security-relevant weaknesses (SSRF-capable fetch of jwks_uri, mutation of caller-supplied options, and potential algorithm confusion when JWKS keys lack an explicit alg) that warrant a warning rather than a clean bill of health. |
| dist/helper/css/index.js | medium | This appears to be a legitimate CSS-in-JS helper library that dynamically generates inline style/script tags for SSR; no data exfiltration, credential harvesting, backdoors, or obfuscated payloads were found, but the inline script generation and dynamic RegExp construction warrant a warning. |
| dist/jsx/components.js | medium | The code implements a streaming error boundary for SSR with dynamic inline script generation, which poses a medium risk of XSS if nonce validation or input sanitization is insufficient, but no direct malicious patterns like data exfiltration or backdoors were found. |
| dist/jsx/dom/render.js | medium | The code is a legitimate DOM rendering library but contains patterns like innerHTML assignment and dynamic property/attribute setting that could be risky if misused with untrusted data; no malicious behavior is evident. |
| dist/middleware/cors/index.js | medium | The code is a standard CORS middleware implementation with permissive default settings but no malicious patterns detected. |
| dist/utils/crypto.js | medium | No malicious behavior (exfiltration, backdoors, install-time code, network calls, process spawning) was found; only weak legacy hash algorithms (MD5, SHA-1) and a silent null return are flagged as cryptographic hygiene concerns. |
| dist/utils/jwt/jwt.js | medium | The JWT utility code contains no malicious exfiltration, credential harvesting, obfuscation, or backdoor patterns, but it exhibits security weaknesses in JWKS-based verification, particularly trusting key/header-supplied algorithm values. |
| dist/adapter/aws-lambda/handler.js | safe | No malicious patterns detected; the code is a standard AWS Lambda adapter for a web framework with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| dist/adapter/aws-lambda/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/aws-lambda/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/bun/conninfo.js | safe | No malicious patterns detected; the code simply retrieves connection information from the Bun server. |
| dist/adapter/bun/index.js | safe | No malicious patterns detected; this is a simple ES module re-exporting Bun adapter utilities (static serving, websocket, SSG, connection info). |
| dist/adapter/bun/serve-static.js | safe | No malicious patterns detected; the code is a benign static file serving adapter with no network, filesystem, or process manipulation beyond reading files. |
| dist/adapter/bun/server.js | safe | No malicious patterns detected |
| dist/adapter/bun/ssg.js | safe | The code is a benign SSG adapter for Bun that writes generated static files to disk; no exfiltration, credential harvesting, obfuscation, or backdoor patterns were detected. |
| dist/adapter/bun/websocket.js | safe | No malicious patterns detected; the code is a standard WebSocket adapter for Bun with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| dist/adapter/cloudflare-pages/handler.js | safe | No malicious patterns detected; the file is a standard Cloudflare Pages adapter handler with no network, filesystem, credential, or code-execution abuse. |
| dist/adapter/cloudflare-pages/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/cloudflare-workers/conninfo.js | safe | No malicious patterns detected |
| dist/adapter/cloudflare-workers/index.js | safe | The file is a simple re-export module for Cloudflare Workers adapter utilities with no malicious patterns detected. |
| dist/adapter/cloudflare-workers/serve-static-module.js | safe | No malicious patterns detected; the file is a simple wrapper re-exporting a serveStatic function. |
| dist/adapter/cloudflare-workers/serve-static.js | safe | No malicious patterns detected; the code is a straightforward static file serving adapter for Cloudflare Workers. |
Show 337 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/adapter/cloudflare-workers/utils.js | safe | No malicious patterns detected; the code is a benign Cloudflare Workers adapter utility for retrieving assets from KV storage. |
| dist/adapter/cloudflare-workers/websocket.js | safe | No malicious patterns detected; the code is a legitimate Cloudflare Workers WebSocket adapter from Hono. |
| dist/adapter/deno/conninfo.js | safe | No malicious patterns detected |
| dist/adapter/deno/deno.d.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/deno/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/deno/serve-static.js | safe | The code is a standard Deno adapter for serving static files without any malicious patterns such as exfiltration, obfuscation, or credential harvesting. |
| dist/adapter/deno/ssg.js | safe | No malicious patterns detected; the code is a straightforward Deno static site generation adapter using Deno's file system APIs. |
| dist/adapter/deno/websocket.js | safe | No malicious patterns detected; the code is a legitimate Deno WebSocket adapter with no exfiltration, obfuscation, process spawning, or install-time execution. |
| dist/adapter/lambda-edge/conninfo.js | safe | This is a simple utility function that extracts the client IP address from AWS Lambda@Edge event records, with no malicious patterns detected. |
| dist/adapter/lambda-edge/handler.js | safe | No malicious patterns detected; the code is a legitimate AWS Lambda@Edge adapter that modifies the global crypto object as a polyfill. |
| dist/adapter/lambda-edge/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/netlify/handler.js | safe | No malicious patterns detected |
| dist/adapter/netlify/index.js | safe | No malicious patterns detected |
| dist/adapter/netlify/mod.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/service-worker/handler.js | safe | No malicious patterns detected; the code is a legitimate service worker fetch handler with a fallback to network fetch on 404 responses. |
| dist/adapter/service-worker/index.js | safe | No malicious patterns detected; the code is a minimal service worker adapter that registers a fetch event listener. |
| dist/adapter/service-worker/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/adapter/vercel/conninfo.js | safe | No malicious patterns detected; the code simply extracts the remote IP address from a request header. |
| dist/adapter/vercel/handler.js | safe | No malicious patterns detected |
| dist/adapter/vercel/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/cjs/adapter/aws-lambda/handler.js | safe | No malicious patterns detected; the code is a legitimate AWS Lambda adapter for SvelteKit that processes events and responses without any data exfiltration, credential harvesting, or dynamic code execution. |
| dist/cjs/adapter/aws-lambda/index.js | safe | No malicious patterns detected |
| dist/cjs/adapter/aws-lambda/types.js | safe | No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities. |
| dist/cjs/adapter/bun/conninfo.js | safe | No malicious patterns detected; the code only retrieves connection info from the Bun server for HTTP request handling. |
| dist/cjs/adapter/bun/index.js | safe | No malicious patterns detected; the file is a standard CommonJS transpiled module that re-exports submodules without any dynamic execution, network, or filesystem activity. |
| dist/cjs/adapter/bun/serve-static.js | safe | The code is a Bun adapter for a static file serving middleware, using standard filesystem and path utilities with no malicious patterns detected. |
| dist/cjs/adapter/bun/server.js | safe | The file contains only standard CommonJS-to-ESM interop helpers and a simple accessor for Bun server context; no malicious patterns, dynamic code execution, network calls, credential access, or filesystem/process manipulation were detected. |
| dist/cjs/adapter/bun/ssg.js | safe | No malicious patterns detected; code is a straightforward Bun-specific SSG adapter that writes files via the Bun API. The target path 'dist/cjs/adapter/bun/ssg.js' matches a known Hono framework adapter file, and no exfiltration, obfuscation, or credential harvesting was found. |
| dist/cjs/adapter/bun/websocket.js | safe | No malicious patterns detected; the code is a legitimate Bun WebSocket adapter with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/cjs/adapter/cloudflare-pages/handler.js | safe | No malicious patterns detected; the code is a standard Cloudflare Pages adapter handler with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| dist/cjs/adapter/cloudflare-pages/index.js | safe | No malicious patterns detected |
| dist/cjs/adapter/cloudflare-workers/conninfo.js | safe | No malicious patterns detected; the code is a simple Cloudflare Workers adapter that reads the 'cf-connecting-ip' header. |
| dist/cjs/adapter/cloudflare-workers/index.js | safe | This is a standard compiled CommonJS module that re-exports functions from local files, with no malicious patterns detected. |
| dist/cjs/adapter/cloudflare-workers/serve-static-module.js | safe | This file is standard CJS interop wrapper code for a static file serving module with no suspicious behavior, network calls, process spawning, or obfuscation. |
| dist/cjs/adapter/cloudflare-workers/serve-static.js | safe | No malicious patterns detected in the provided JavaScript file. |
| dist/cjs/adapter/cloudflare-workers/utils.js | safe | No malicious patterns detected; the code is a standard Cloudflare Workers adapter utility for retrieving static assets from a KV namespace. |
| dist/cjs/adapter/cloudflare-workers/websocket.js | safe | The code implements a standard WebSocket upgrade handler for Cloudflare Workers with no malicious patterns detected. |
| dist/cjs/adapter/deno/conninfo.js | safe | No malicious patterns detected; the code is a simple connection info adapter with standard module boilerplate. |
| dist/cjs/adapter/deno/deno.d.js | safe | No malicious patterns detected |
| dist/cjs/adapter/deno/index.js | safe | This is a standard CommonJS module wrapper that re-exports functions from Deno adapter modules without any malicious patterns. |
| dist/cjs/adapter/deno/serve-static.js | safe | No malicious patterns detected; the code implements a standard static file serving adapter for Deno using safe filesystem operations. |
| dist/cjs/adapter/deno/ssg.js | safe | No malicious patterns detected |
| dist/cjs/adapter/deno/websocket.js | safe | Code is a legitimate WebSocket adapter for Deno runtime with no malicious patterns, exfiltration, or backdoors detected. |
| dist/cjs/adapter/lambda-edge/conninfo.js | safe | No malicious patterns detected; the code simply reads the client IP from AWS Lambda@Edge CloudFront event records without any exfiltration, dynamic execution, or suspicious behavior. |
| dist/cjs/adapter/lambda-edge/handler.js | safe | No malicious patterns detected; the code is a standard Lambda@Edge adapter for an HTTP framework with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/cjs/adapter/lambda-edge/index.js | safe | This is a standard CommonJS module transpiled from ESM with no suspicious behavior; it only re-exports handler and conninfo functions. |
| dist/cjs/adapter/netlify/handler.js | safe | No malicious patterns detected |
| dist/cjs/adapter/netlify/index.js | safe | This is a standard CommonJS re-export shim generated by esbuild/rollup; it only re-exports the ./mod module and contains no malicious patterns. |
| dist/cjs/adapter/netlify/mod.js | safe | No malicious patterns detected; the file is a standard CommonJS adapter module that re-exports a handler function from a local sibling module without any suspicious behavior. |
| dist/cjs/adapter/service-worker/handler.js | safe | The service worker handler is a standard fetch fallback implementation with no malicious patterns, obfuscation, exfiltration, or risky behavior. |
| dist/cjs/adapter/service-worker/index.js | safe | No malicious patterns detected; the code is a standard CommonJS bundler output for a service worker adapter that registers a fetch event listener. |
| dist/cjs/adapter/service-worker/types.js | safe | No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities. |
| dist/cjs/adapter/vercel/conninfo.js | safe | No malicious patterns detected |
| dist/cjs/adapter/vercel/handler.js | safe | No malicious patterns detected |
| dist/cjs/adapter/vercel/index.js | safe | No malicious patterns detected |
| dist/cjs/client/fetch-result-please.js | safe | No malicious patterns detected; the code is a standard fetch response parsing utility with no exfiltration, credential harvesting, obfuscation, or system-level operations. |
| dist/cjs/client/index.js | safe | This is a standard CJS bundle entry point that re-exports named symbols from internal modules with no executable, network, filesystem, or obfuscated behavior. |
| dist/cjs/client/types.js | safe | No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities. |
| dist/cjs/client/utils.js | safe | No malicious patterns detected |
| dist/cjs/compose.js | safe | No malicious patterns detected; the code implements standard middleware composition similar to Koa-style dispatch with no external calls, file access, or dynamic execution. |
| dist/cjs/context.js | safe | The code is a standard Hono framework Context class with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, network requests, or filesystem manipulation. |
| dist/cjs/helper/accepts/accepts.js | safe | No malicious patterns detected; the code is a standard implementation of HTTP Accept header content negotiation with no network, filesystem, environment, or dynamic execution concerns. |
| dist/cjs/helper/accepts/index.js | safe | No malicious patterns detected |
| dist/cjs/helper/adapter/index.js | safe | No malicious patterns detected; the code is a standard runtime environment adapter that reads environment variables without exfiltration or other harmful behavior. |
| dist/cjs/helper/conninfo/index.js | safe | No malicious patterns detected |
| dist/cjs/helper/conninfo/types.js | safe | No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities. |
| dist/cjs/helper/cookie/index.js | safe | No malicious patterns detected |
| dist/cjs/helper/css/common.js | safe | No malicious patterns detected; the code is a CSS utility library with no network, filesystem, process, or obfuscated execution behaviors. |
| dist/cjs/helper/css/index.js | safe | No malicious patterns detected; the code is a standard CSS-in-JS helper library with no data exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior. |
| dist/cjs/helper/dev/index.js | safe | No malicious patterns detected |
| dist/cjs/helper/factory/index.js | safe | No malicious patterns detected; the code is a standard Hono.js helper factory with no network, filesystem, process, or obfuscated activity. |
| dist/cjs/helper/html/index.js | safe | No malicious patterns detected; the code is a standard tagged template literal HTML escaping helper with no network, filesystem, process, or dynamic code execution activity. |
| dist/cjs/helper/proxy/index.js | safe | No malicious patterns detected; the code implements a standard HTTP proxy helper with header sanitization. |
| dist/cjs/helper/route/index.js | safe | No malicious patterns detected; the code is a standard routing utility with no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/cjs/helper/ssg/index.js | safe | No malicious patterns detected; the file is a standard CommonJS re-export helper with no suspicious behavior. |
| dist/cjs/helper/ssg/middleware.js | safe | No malicious patterns detected |
| dist/cjs/helper/ssg/ssg.js | safe | No malicious patterns detected; the code is a legitimate static site generation (SSG) helper for the Hono framework. |
| dist/cjs/helper/ssg/utils.js | safe | The code contains only routine path manipulation and route filtering utilities with no malicious patterns, external calls, or dynamic execution. |
| dist/cjs/helper/streaming/index.js | safe | No malicious patterns detected; the file is a standard CommonJS re-export module for streaming helpers. |
| dist/cjs/helper/streaming/sse.js | safe | No malicious patterns detected; the code implements Server-Sent Events streaming with standard utilities and no exfiltration, obfuscation, or unauthorized system access. |
| dist/cjs/helper/streaming/stream.js | safe | No malicious patterns detected; the file contains standard streaming helper utilities with no exfiltration, obfuscation, or suspicious behavior. |
| dist/cjs/helper/streaming/text.js | safe | No malicious patterns detected; the file is a benign streaming helper with standard CommonJS bundler boilerplate and security-hardening headers. |
| dist/cjs/helper/streaming/utils.js | safe | No malicious patterns detected |
| dist/cjs/helper/testing/index.js | safe | No malicious patterns detected; the code is a standard testing helper that creates a client with a custom fetch function. |
| dist/cjs/helper/websocket/index.js | safe | No malicious patterns detected; this is a WebSocket context helper with no network, filesystem, process, or dynamic code execution behavior. |
| dist/cjs/hono-base.js | safe | No malicious patterns detected in the provided HonoBase source code. |
| dist/cjs/hono.js | safe | No malicious patterns detected; this is a standard Hono framework entry point with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/cjs/http-exception.js | safe | No malicious patterns detected; the file is a standard HTTPException class definition using Web Fetch API Response objects. |
| dist/cjs/index.js | safe | The file contains only standard CommonJS module bundling boilerplate and re-exports Hono from a local import; no malicious patterns, obfuscation, network calls, or process execution were detected. |
| dist/cjs/jsx/base.js | safe | No malicious patterns detected; the code is a legitimate JSX runtime implementation for the Hono framework with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| dist/cjs/jsx/children.js | safe | No malicious patterns detected |
| dist/cjs/jsx/components.js | safe | No malicious patterns detected; the code implements server-side JSX error boundary rendering with template replacement and inline script nonce handling typical of the Hono framework. |
| dist/cjs/jsx/constants.js | safe | No malicious patterns detected; the file only defines and exports Symbol constants using standard CommonJS interop helpers. |
| dist/cjs/jsx/context.js | safe | No malicious patterns detected; the file contains standard context management code for a JSX rendering library with no network, filesystem, process execution, or obfuscation concerns. |
| dist/cjs/jsx/dom/client.js | safe | No malicious patterns detected; the file contains standard CommonJS boilerplate for exporting React-like DOM client functions with no network, filesystem, process execution, or obfuscated code. |
| dist/cjs/jsx/dom/components.js | safe | No malicious patterns detected in the analyzed JavaScript file; it contains standard error boundary and suspense component implementations without any obfuscation, network activity, or system-level operations. |
| dist/cjs/jsx/dom/context.js | safe | No malicious patterns detected; the file contains standard React-like context creation logic with no network, filesystem, process, or obfuscation concerns. |
| dist/cjs/jsx/dom/css.js | safe | No malicious patterns detected; the file is a legitimate CSS-in-JS runtime without exfiltration, credential access, dynamic execution, or network activity. |
| dist/cjs/jsx/dom/hooks/index.js | safe | No malicious patterns detected; the file contains standard React-like hook implementations for form status, optimistic updates, and action state management. |
| dist/cjs/jsx/dom/index.js | safe | No malicious patterns detected |
| dist/cjs/jsx/dom/intrinsic-element/components.js | safe | No malicious patterns detected |
| dist/cjs/jsx/dom/jsx-dev-runtime.js | safe | No malicious patterns detected; this is a normal JSX dev runtime helper file with standard CJS/ESM interop boilerplate. |
| dist/cjs/jsx/dom/jsx-runtime.js | safe | No malicious patterns detected |
| dist/cjs/jsx/dom/server.js | safe | No malicious patterns detected; the code is standard compiled output for server-side JSX rendering with no network, filesystem, or process manipulation. |
| dist/cjs/jsx/dom/utils.js | safe | No malicious patterns detected; the code is a standard CommonJS wrapper for exporting a utility function. |
| dist/cjs/jsx/hooks/index.js | safe | No malicious patterns detected; the code implements standard React-like hooks with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity. |
| dist/cjs/jsx/index.js | safe | No malicious patterns detected; the file is a standard compiled JSX runtime barrel export with no suspicious network, filesystem, or process activity. |
| dist/cjs/jsx/intrinsic-element/common.js | safe | No malicious patterns detected; the code is a standard CommonJS module with helper functions and constant exports. |
| dist/cjs/jsx/intrinsic-element/components.js | safe | No malicious patterns detected; the code is a JSX intrinsic-element component library implementing head tag deduplication and metadata handling without any exfiltration, obfuscation, or process execution. |
| dist/cjs/jsx/intrinsic-elements.js | safe | No malicious patterns detected; the file contains only CommonJS module boilerplate for exporting an empty object. |
| dist/cjs/jsx/jsx-dev-runtime.js | safe | This is a standard JSX dev runtime helper module with no suspicious behavior, network activity, credential access, or dynamic code execution. |
| dist/cjs/jsx/jsx-runtime.js | safe | No malicious patterns detected; this appears to be a standard JSX runtime helper module for server-side rendering with attribute escaping. |
| dist/cjs/jsx/streaming.js | safe | No malicious patterns detected; the code implements JSX streaming/Suspense rendering with standard internal callbacks and no suspicious network, filesystem, or process activity. |
| dist/cjs/jsx/types.js | safe | No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities. |
| dist/cjs/jsx/utils.js | safe | No malicious patterns detected |
| dist/cjs/middleware/basic-auth/index.js | safe | No malicious patterns detected; the code is a standard basic authentication middleware with no data exfiltration, process spawning, or dynamic code execution. |
| dist/cjs/middleware/bearer-auth/index.js | safe | No malicious patterns detected; this is a standard bearer authentication middleware with no network exfiltration, credential harvesting, dynamic execution, or install-time hooks. |
| dist/cjs/middleware/body-limit/index.js | safe | No malicious patterns detected; the code implements a body size limiting middleware with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/cjs/middleware/cache/index.js | safe | No malicious patterns detected; the code implements a standard HTTP cache middleware using the Web Cache API without exfiltration, credential harvesting, obfuscation, or any suspicious behavior. |
| dist/cjs/middleware/combine/index.js | safe | No malicious patterns detected; the code is a standard middleware composition utility with no network, filesystem, process, or obfuscated behavior. |
| dist/cjs/middleware/compress/index.js | safe | No malicious patterns detected; the code is a standard response compression middleware with no network, filesystem, process, or obfuscation concerns. |
| dist/cjs/middleware/context-storage/index.js | safe | No malicious patterns detected; the code is a standard AsyncLocalStorage-based context storage middleware with no exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| dist/cjs/middleware/cors/index.js | safe | No malicious patterns detected |
| dist/cjs/middleware/csrf/index.js | safe | No malicious patterns detected; the code implements a standard CSRF protection middleware for web frameworks. |
| dist/cjs/middleware/etag/digest.js | safe | No malicious patterns detected; the code implements a standard streaming digest utility with no network, filesystem, or dynamic execution capabilities. |
| dist/cjs/middleware/etag/index.js | safe | No malicious patterns detected in the ETag middleware implementation. |
| dist/cjs/middleware/ip-restriction/index.js | safe | No malicious patterns detected; the code implements IP restriction middleware with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/file/process activity. |
| dist/cjs/middleware/jsx-renderer/index.js | safe | No malicious patterns detected; the code is a standard JSX renderer middleware with no network, filesystem, process, or dynamic execution concerns. |
| dist/cjs/middleware/jwk/index.js | safe | No malicious patterns detected |
| dist/cjs/middleware/jwk/jwk.js | safe | No malicious patterns detected; the code implements standard JWK/JWT authentication middleware without exfiltration, credential harvesting, obfuscation, or suspicious dynamic behavior. |
| dist/cjs/middleware/jwt/index.js | safe | The code is a standard CommonJS re-export module for JWT functionality with no malicious patterns detected. |
| dist/cjs/middleware/jwt/jwt.js | safe | No malicious patterns detected; the code is a standard JWT middleware implementation with proper cryptographic verification and no exfiltration, obfuscation, or unauthorized system access. |
| dist/cjs/middleware/language/index.js | safe | No malicious patterns detected |
| dist/cjs/middleware/language/language.js | safe | Language detection middleware contains only standard localization logic with no malicious patterns, network activity, or dynamic code execution. |
| dist/cjs/middleware/logger/index.js | safe | No malicious patterns detected; the code is a benign HTTP request logger middleware. |
| dist/cjs/middleware/powered-by/index.js | safe | No malicious patterns detected; the file is a standard middleware helper that only sets the X-Powered-By response header. |
| dist/cjs/middleware/pretty-json/index.js | safe | No malicious patterns detected; the code is a standard middleware for pretty-printing JSON responses. |
| dist/cjs/middleware/request-id/index.js | safe | No malicious patterns detected; the file is a standard CommonJS re-export wrapper for the request-id middleware. |
| dist/cjs/middleware/request-id/request-id.js | safe | No malicious patterns detected; the code is a benign request-ID middleware that reads a header, validates it, and sets a response header. |
| dist/cjs/middleware/secure-headers/index.js | safe | No malicious patterns detected |
| dist/cjs/middleware/secure-headers/permissions-policy.js | safe | No malicious patterns detected; the file contains only standard CommonJS module boilerplate and an empty exports object with no executable logic. |
| dist/cjs/middleware/secure-headers/secure-headers.js | safe | No malicious patterns detected; the code is a legitimate secure headers middleware for setting HTTP security headers. |
| dist/cjs/middleware/serve-static/index.js | safe | The code is a static file serving middleware with no malicious patterns, external network calls, credential harvesting, or dynamic code execution. |
| dist/cjs/middleware/serve-static/path.js | safe | The code implements a safe, pure path-joining utility with no malicious patterns, external calls, or dangerous operations. |
| dist/cjs/middleware/timeout/index.js | safe | No malicious patterns detected; the code is a legitimate timeout middleware implementation. |
| dist/cjs/middleware/timing/index.js | safe | No malicious patterns detected; this is a standard TypeScript-compiled CommonJS re-export shim for a timing middleware module. |
| dist/cjs/middleware/timing/timing.js | safe | No malicious patterns detected; the code implements a standard Server-Timing middleware with no data exfiltration, obfuscation, or system-level access. |
| dist/cjs/middleware/trailing-slash/index.js | safe | No malicious patterns detected; the code implements standard trailing slash middleware with no exfiltration, obfuscation, or dangerous operations. |
| dist/cjs/preset/quick.js | safe | No malicious patterns detected |
| dist/cjs/preset/tiny.js | safe | No malicious patterns detected |
| dist/cjs/request.js | safe | No malicious patterns detected; the code is a standard Hono framework request wrapper with benign request parsing and cloning utilities. |
| dist/cjs/request/constants.js | safe | No malicious patterns detected |
| dist/cjs/router.js | safe | No malicious patterns detected. |
| dist/cjs/router/linear-router/index.js | safe | No malicious patterns detected; the file only contains standard CommonJS transpilation helper code for exporting a router class. |
| dist/cjs/router/linear-router/router.js | safe | No malicious patterns detected; the code is a legitimate linear router implementation with standard module exports and path matching logic. |
| dist/cjs/router/pattern-router/index.js | safe | This is a standard TypeScript/CommonJS build artifact re-exporting PatternRouter with no malicious patterns, dynamic execution, network activity, or filesystem access. |
| dist/cjs/router/pattern-router/router.js | safe | No malicious patterns detected; the code implements a URL pattern router with no network, filesystem, process spawning, or dynamic code execution. |
| dist/cjs/router/reg-exp-router/index.js | safe | No malicious patterns detected; the file only contains standard CommonJS module bundling boilerplate and re-exports from local router files. |
| dist/cjs/router/reg-exp-router/matcher.js | safe | No malicious patterns detected |
| dist/cjs/router/reg-exp-router/node.js | safe | This is a benign routing library implementation (reg-exp-router) that builds regular expressions from path tokens, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network activity, or process spawning. |
| dist/cjs/router/reg-exp-router/prepared-router.js | safe | No malicious patterns detected in the provided JavaScript router implementation. |
| dist/cjs/router/reg-exp-router/router.js | safe | No malicious patterns detected |
| dist/cjs/router/reg-exp-router/trie.js | safe | No malicious patterns detected; the code implements a trie for router path parsing using standard string manipulation and regex, with no network, filesystem, process, or dynamic execution activity. |
| dist/cjs/router/smart-router/index.js | safe | The file contains only standard CommonJS/ESM interop boilerplate and a clean re-export of SmartRouter with no malicious patterns detected. |
| dist/cjs/router/smart-router/router.js | safe | No malicious patterns detected in this SmartRouter implementation, which only performs in-memory route registration and matching without any network, filesystem, process, or dynamic code execution activity. |
| dist/cjs/router/trie-router/index.js | safe | No malicious patterns detected; the file is a standard CommonJS transpilation of a trie router module with no suspicious behavior. |
| dist/cjs/router/trie-router/node.js | safe | No malicious patterns detected; the code is a standard routing trie implementation with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior. |
| dist/cjs/router/trie-router/router.js | safe | No malicious patterns detected |
| dist/cjs/types.js | safe | No malicious patterns detected |
| dist/cjs/utils/accept.js | safe | No malicious patterns detected; the code only parses HTTP Accept headers with no network, filesystem, or dynamic execution behavior. |
| dist/cjs/utils/basic-auth.js | safe | No malicious patterns detected; the code is a straightforward Basic Authentication header parser. |
| dist/cjs/utils/body.js | safe | No malicious patterns detected in the body parsing utility; it only processes form data from incoming requests. |
| dist/cjs/utils/buffer.js | safe | No malicious patterns detected; the code contains standard buffer utility functions with minor cryptographic timing weaknesses. |
| dist/cjs/utils/color.js | safe | No malicious patterns detected; the code only checks standard environment variables and performs a guarded dynamic import for Cloudflare Workers compatibility. |
| dist/cjs/utils/compress.js | safe | No malicious patterns detected; the file only exports a regular expression for compressible content types. |
| dist/cjs/utils/concurrent.js | safe | No malicious patterns detected |
| dist/cjs/utils/constants.js | safe | No malicious patterns detected; the file only contains standard CommonJS/ESM interop helpers and exports a single string constant. |
| dist/cjs/utils/cookie.js | safe | No malicious patterns detected; the code implements standard cookie parsing and signing utilities without exfiltration, credential harvesting, obfuscation, or network access. |
| dist/cjs/utils/crypto.js | safe | The code is a standard cryptographic hashing utility with no malicious patterns, external calls, or suspicious behavior. |
| dist/cjs/utils/encode.js | safe | The code is a straightforward Base64/Base64URL encoding and decoding utility with no malicious patterns, external calls, or obfuscation. |
| dist/cjs/utils/filepath.js | safe | No malicious patterns detected; the file contains only path resolution utilities with standard path traversal sanitization. |
| dist/cjs/utils/handler.js | safe | No malicious patterns detected; the file contains only standard CommonJS module utilities and handler helper functions. |
| dist/cjs/utils/headers.js | safe | No malicious patterns detected; the file contains only standard TypeScript/CommonJS interop boilerplate with no executable logic or external interactions. |
| dist/cjs/utils/html.js | safe | This is a standard HTML escaping utility from the Hono framework; no malicious patterns such as exfiltration, credential harvesting, code execution, or network activity were detected. |
| dist/cjs/utils/http-status.js | safe | No malicious patterns detected |
| dist/cjs/utils/ipaddr.js | safe | No malicious patterns detected; the code only implements IPv4/IPv6 parsing and conversion utilities with no network, filesystem, process, or dynamic code execution behavior. |
| dist/cjs/utils/jwt/index.js | safe | No malicious patterns detected |
| dist/cjs/utils/jwt/jwa.js | safe | No malicious patterns detected; the file only defines JWT algorithm type constants and uses standard TypeScript/CommonJS export helpers. |
| dist/cjs/utils/jwt/jws.js | safe | No malicious patterns detected; the code implements standard JWT signing and verification using WebCrypto. |
| dist/cjs/utils/jwt/types.js | safe | No malicious patterns detected; the file only defines JWT-related error classes and a CryptoKeyUsage enum with no network, filesystem, process, or dynamic execution behavior. |
| dist/cjs/utils/jwt/utf8.js | safe | No malicious patterns detected; the file only provides simple UTF-8 TextEncoder/TextDecoder exports with standard CommonJS interop helpers. |
| dist/cjs/utils/mime.js | safe | No malicious patterns detected; the file only provides MIME type lookup utilities with no network, filesystem, or dynamic execution behavior. |
| dist/cjs/utils/stream.js | safe | No malicious patterns detected; the file implements a standard streaming API with no network, filesystem, or process manipulation. |
| dist/cjs/utils/types.js | safe | No malicious patterns detected; the file only contains standard CommonJS module wrapper and property copying utilities. |
| dist/cjs/utils/url.js | safe | The code is a standard URL parsing utility with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist/cjs/validator/index.js | safe | No malicious patterns detected; the file is a standard CommonJS re-export shim generated by a bundler. |
| dist/cjs/validator/validator.js | safe | No malicious patterns detected; the code is a standard request validator for JSON, form, query, param, header, and cookie data without any exfiltration, obfuscation, or dynamic execution. |
| dist/client/client.js | safe | No malicious patterns detected; the file implements a standard HTTP client proxy without exfiltration, obfuscation, or system-level operations. |
| dist/client/fetch-result-please.js | safe | No malicious patterns detected; the code is a straightforward fetch wrapper with error handling and response type detection. |
| dist/client/index.js | safe | No malicious patterns detected |
| dist/client/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/client/utils.js | safe | No malicious patterns detected. The code contains only utility functions for URL and object manipulation, with no suspicious network, filesystem, or execution behavior. |
| dist/compose.js | safe | No malicious patterns detected |
| dist/context.js | safe | No malicious patterns detected; the code is a legitimate HTTP context implementation for the Hono web framework. |
| dist/helper/accepts/accepts.js | safe | No malicious patterns detected; the code is a simple HTTP Accept header parser with no network, filesystem, or execution behavior. |
| dist/helper/accepts/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/helper/adapter/index.js | safe | No malicious patterns detected; the code only reads environment variables for legitimate runtime detection purposes. |
| dist/helper/conninfo/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/helper/conninfo/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/helper/cookie/index.js | safe | Cookie helper module with no malicious patterns; only performs expected cookie parsing, signing, and serialization operations. |
| dist/helper/css/common.js | safe | This is a CSS-in-JS utility library with no network, filesystem, process, or dynamic execution behavior; all operations are pure string manipulation and hashing, so no malicious patterns are present. |
| dist/helper/dev/index.js | safe | No malicious patterns detected; the code only inspects and prints route information for debugging purposes. |
| dist/helper/factory/index.js | safe | No malicious patterns detected; the code is a benign factory helper for the Hono web framework with no network, filesystem, or process manipulation. |
| dist/helper/html/index.js | safe | No malicious patterns detected |
| dist/helper/proxy/index.js | safe | No malicious patterns detected; the code implements a standard HTTP proxy helper with header filtering and no suspicious behavior. |
| dist/helper/route/index.js | safe | No malicious patterns detected; the code appears to be a legitimate routing helper with no network, file system, or dynamic execution concerns. |
| dist/helper/ssg/index.js | safe | No malicious patterns detected |
| dist/helper/ssg/middleware.js | safe | The code implements standard static site generation (SSG) middleware for the Hono framework with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/helper/ssg/ssg.js | safe | No malicious patterns detected; the code is a legitimate static site generation utility for the Hono framework. |
| dist/helper/ssg/utils.js | safe | No malicious patterns detected; the code contains only utility functions for path manipulation and route filtering with no network, filesystem, process, or credential access. |
| dist/helper/streaming/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/helper/streaming/sse.js | safe | The code implements an SSE streaming helper for a web framework with no malicious patterns, external network calls, credential access, or dynamic code execution. |
| dist/helper/streaming/stream.js | safe | No malicious patterns detected; the code is a standard streaming helper with no external data exfiltration, credential harvesting, dynamic execution, or process spawning. |
| dist/helper/streaming/text.js | safe | No malicious patterns detected; the code is a simple HTTP streaming helper that sets content-type and security headers. |
| dist/helper/streaming/utils.js | safe | The code only checks the Bun runtime version string and contains no malicious patterns. |
| dist/helper/testing/index.js | safe | No malicious patterns detected; the code is a simple test client helper for a web framework. |
| dist/helper/websocket/index.js | safe | No malicious patterns detected |
| dist/hono-base.js | safe | This is the legitimate Hono web framework base class containing only routing, request handling, and error dispatch logic; no malicious patterns, data exfiltration, process spawning, or dynamic code execution were found. |
| dist/hono.js | safe | The file contains only benign Hono framework class definition code with no malicious patterns, data exfiltration, dynamic execution, or install-time behavior. |
| dist/http-exception.js | safe | No malicious patterns detected; the code is a standard HTTPException class with no external data access or dangerous operations. |
| dist/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/jsx/base.js | safe | This is a legitimate JSX runtime implementation (Hono's JSX) with no malicious patterns, no network calls, no filesystem access, no process spawning, and no dynamic code execution. |
| dist/jsx/children.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/jsx/constants.js | safe | No malicious patterns detected |
| dist/jsx/context.js | safe | No malicious patterns detected; the code is a legitimate JSX context implementation with no network, filesystem, or process activity. |
| dist/jsx/dom/client.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/jsx/dom/components.js | safe | No malicious patterns detected |
| dist/jsx/dom/context.js | safe | No malicious patterns detected; the code implements a standard JSX context provider for a UI library without any data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/jsx/dom/css.js | safe | This is a CSS-in-JS utility module for Hono's JSX DOM renderer; it contains no network, filesystem, process, credential, obfuscation, or dynamic execution patterns and is safe. |
| dist/jsx/dom/hooks/index.js | safe | No malicious patterns detected; the code is a legitimate React-like hooks implementation for form status and optimistic state management. |
| dist/jsx/dom/index.js | safe | No malicious patterns detected; the file is a standard JSX/React-compatible DOM rendering entry point with imports and exports only. |
| dist/jsx/dom/intrinsic-element/components.js | safe | The code implements DOM intrinsic element handling for a JSX library with no malicious patterns detected. |
| dist/jsx/dom/jsx-dev-runtime.js | safe | No malicious patterns detected |
| dist/jsx/dom/jsx-runtime.js | safe | No malicious patterns detected |
| dist/jsx/dom/server.js | safe | No malicious patterns detected; the code is a straightforward server-side rendering utility with no network, filesystem, process, or dynamic code execution concerns. |
| dist/jsx/dom/utils.js | safe | No malicious patterns detected |
| dist/jsx/hooks/index.js | safe | No malicious patterns detected; the code implements standard JSX hooks for a UI framework with no network, filesystem, process, or obfuscation concerns. |
| dist/jsx/index.js | safe | No malicious patterns detected; the file is a standard JSX runtime re-export module with only static imports and exports. |
| dist/jsx/intrinsic-element/common.js | safe | No malicious patterns detected; the file only defines static configuration maps and exports them without any dynamic execution, network, filesystem, or process activity. |
| dist/jsx/intrinsic-element/components.js | safe | No malicious patterns detected; the code appears to be a legitimate JSX intrinsic element handler for document metadata with no security concerns. |
| dist/jsx/intrinsic-elements.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/jsx/jsx-dev-runtime.js | safe | No malicious patterns detected |
| dist/jsx/jsx-runtime.js | safe | No malicious patterns detected; this is a standard JSX runtime implementation for Hono that performs safe HTML attribute escaping and rendering without any network, filesystem, or process execution activity. |
| dist/jsx/streaming.js | safe | No malicious patterns detected; the code appears to be a legitimate JSX streaming renderer with Suspense support, containing no obfuscation, data exfiltration, credential harvesting, or backdoor behavior. |
| dist/jsx/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/jsx/utils.js | safe | No malicious patterns detected; the code is a benign JSX utility for key normalization and style object iteration. |
| dist/middleware/basic-auth/index.js | safe | The code implements a basic authentication middleware with proper timing-safe comparisons and no malicious patterns detected. |
| dist/middleware/bearer-auth/index.js | safe | No malicious patterns detected |
| dist/middleware/body-limit/index.js | safe | The code implements a standard request body size limiting middleware with no malicious patterns, network exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/middleware/cache/index.js | safe | No malicious patterns detected; the code implements a standard HTTP cache middleware using the Cache API without any exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/middleware/combine/index.js | safe | No malicious patterns detected; the file contains only legitimate routing middleware logic for combining handlers. |
| dist/middleware/compress/index.js | safe | No malicious patterns detected; the code implements a benign compression middleware using standard Web APIs without any suspicious activity. |
| dist/middleware/context-storage/index.js | safe | No malicious patterns detected |
| dist/middleware/csrf/index.js | safe | No malicious patterns detected; the code implements CSRF protection without exfiltration, obfuscation, or install-time execution. |
| dist/middleware/etag/digest.js | safe | The code only computes a hash digest from a stream using a provided generator, with no network, filesystem, environment, or process-related activity. |
| dist/middleware/etag/index.js | safe | No malicious patterns detected in the ETag middleware code; it only implements standard HTTP caching behavior. |
| dist/middleware/ip-restriction/index.js | safe | The code implements IP restriction middleware using allow/deny lists with CIDR support and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/middleware/jsx-renderer/index.js | safe | This is legitimate Hono JSX renderer middleware code with no malicious patterns detected. |
| dist/middleware/jwk/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/jwk/jwk.js | safe | No malicious patterns detected; the code is a legitimate JWK/JWT authentication middleware from Hono. |
| dist/middleware/jwt/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/jwt/jwt.js | safe | No malicious patterns detected; the code is a standard JWT authentication middleware for the Hono web framework. |
| dist/middleware/language/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/language/language.js | safe | No malicious patterns detected; the code is a standard language detection middleware with no exfiltration, credential harvesting, dynamic execution, or suspicious network/file system activity. |
| dist/middleware/logger/index.js | safe | No malicious patterns detected; the code is a standard HTTP request logger middleware with only benign logging and color utility logic. |
| dist/middleware/method-override/index.js | safe | No malicious patterns detected; the code implements standard HTTP method override middleware without exfiltration, credential harvesting, obfuscation, or dangerous operations. |
| dist/middleware/powered-by/index.js | safe | No malicious patterns detected |
| dist/middleware/pretty-json/index.js | safe | No malicious patterns detected; the middleware only conditionally pretty-prints JSON responses based on a query parameter. |
| dist/middleware/request-id/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/request-id/request-id.js | safe | No malicious patterns detected; the code is a benign request ID middleware with proper input validation. |
| dist/middleware/secure-headers/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/secure-headers/permissions-policy.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/secure-headers/secure-headers.js | safe | The code implements standard secure HTTP header middleware using safe cryptographic nonce generation and configuration handling, with no apparent malicious patterns. |
| dist/middleware/serve-static/index.js | safe | No malicious patterns detected; the code is a standard static file-serving middleware with path traversal protection and no suspicious network, filesystem, or execution behavior. |
| dist/middleware/serve-static/path.js | safe | The provided path-joining utility contains only pure string manipulation logic with no network, file system, process, or code execution capabilities, and displays no malicious patterns. |
| dist/middleware/timeout/index.js | safe | No malicious patterns detected |
| dist/middleware/timing/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/middleware/timing/timing.js | safe | No malicious patterns detected; this is a standard Hono middleware for Server-Timing headers. |
| dist/middleware/trailing-slash/index.js | safe | No malicious patterns detected |
| dist/preset/quick.js | safe | No malicious patterns detected; the code is a standard Hono web framework preset with no security concerns. |
| dist/preset/tiny.js | safe | No malicious patterns detected |
| dist/request.js | safe | This is a legitimate part of the Hono web framework request handling code with no malicious patterns detected. |
| dist/request/constants.js | safe | No malicious patterns detected |
| dist/router.js | safe | No malicious patterns detected |
| dist/router/linear-router/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/router/linear-router/router.js | safe | This is a benign linear router implementation for the Hono web framework with no malicious patterns, no network activity, no filesystem access, no process spawning, and no dynamic code execution. |
| dist/router/pattern-router/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/router/pattern-router/router.js | safe | No malicious patterns detected in the pattern router implementation; it is a benign URL routing component with no network, file system, or process execution activity. |
| dist/router/reg-exp-router/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/router/reg-exp-router/matcher.js | safe | No malicious patterns detected; the code is a benign routing matcher with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/router/reg-exp-router/node.js | safe | No malicious patterns detected; the code is a benign routing tree implementation with no network, filesystem, process, or dynamic execution behavior. |
| dist/router/reg-exp-router/prepared-router.js | safe | No malicious patterns detected; the code is a legitimate router implementation with no exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/router/reg-exp-router/router.js | safe | No malicious patterns detected in the provided router implementation; it is a standard regex-based route matcher from the Hono framework with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| dist/router/reg-exp-router/trie.js | safe | The code implements a trie data structure for route path parsing with regex-based tokenization; no malicious patterns, network calls, environment access, or dynamic execution were detected. |
| dist/router/smart-router/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/router/smart-router/router.js | safe | No malicious patterns detected |
| dist/router/trie-router/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/router/trie-router/node.js | safe | No malicious patterns detected; this is a legitimate trie-based router implementation for a web framework with no network, file system, process, or credential access. |
| dist/router/trie-router/router.js | safe | No malicious patterns detected |
| dist/types.js | safe | No malicious patterns detected |
| dist/utils/accept.js | safe | No malicious patterns detected; the code is a straightforward Accept header parser with no network, filesystem, process, or dynamic execution behavior. |
| dist/utils/basic-auth.js | safe | No malicious patterns detected; the code is a standard basic authentication header parser with no exfiltration, credential harvesting, obfuscation, or other security concerns. |
| dist/utils/body.js | safe | No malicious patterns detected in this form-parsing utility; it only processes request bodies without network, filesystem, or process manipulation. |
| dist/utils/buffer.js | safe | No malicious patterns detected; the code contains standard buffer utility functions without any security concerns. |
| dist/utils/color.js | safe | The color utility code only checks environment variables for color settings and dynamically imports Cloudflare Workers module; no malicious patterns detected. |
| dist/utils/compress.js | safe | No malicious patterns detected |
| dist/utils/concurrent.js | safe | No malicious patterns detected; the file implements a generic concurrency pool without network, filesystem, process, or obfuscated code. |
| dist/utils/constants.js | safe | No malicious patterns detected |
| dist/utils/cookie.js | safe | The code implements cookie parsing and signing using Web Crypto API with no network, filesystem, process, or obfuscation patterns detected. |
| dist/utils/encode.js | safe | No malicious patterns detected; the file only provides standard Base64 and Base64URL encoding/decoding utilities using btoa/atob. |
| dist/utils/filepath.js | safe | No malicious patterns detected; the code performs path normalization and traversal prevention without any suspicious behavior. |
| dist/utils/handler.js | safe | No malicious patterns detected |
| dist/utils/headers.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/utils/html.js | safe | No malicious patterns detected; the code is a benign HTML escaping and callback resolution utility with no network, filesystem, process, or dynamic code execution activity. |
| dist/utils/http-status.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/utils/ipaddr.js | safe | Pure IPv4/IPv6 address manipulation utilities with no malicious patterns, network calls, or filesystem access. |
| dist/utils/jwt/index.js | safe | No malicious patterns detected |
| dist/utils/jwt/jwa.js | safe | No malicious patterns detected |
| dist/utils/jwt/jws.js | safe | No malicious patterns detected; the code is a standard JWT signing/verification utility using Web Crypto API. |
| dist/utils/jwt/types.js | safe | No malicious patterns detected; the file only defines JWT-related error classes and an enum for cryptographic key usage. |
| dist/utils/jwt/utf8.js | safe | No malicious patterns detected |
| dist/utils/mime.js | safe | No malicious patterns detected; the file is a simple MIME type lookup utility with no network, filesystem, process, or dynamic code execution activity. |
| dist/utils/stream.js | safe | No malicious patterns detected |
| dist/utils/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/utils/url.js | safe | No malicious patterns detected |
| dist/validator/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/validator/validator.js | safe | No malicious patterns detected; the code is a standard request body validation middleware for a web framework. |
Frequently asked questions
Is hono safe to use?
No confirmed malware was found in hono@4.10.7, but the review flagged 2 high, 16 medium, 24 low severity findings for risky patterns worth checking before you rely on it.
Does hono contain malware?
No malware was identified in hono@4.10.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was hono checked?
Togoder Security downloaded the published npm package and had an AI model read its 362 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan hono together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in hono@4.10.7, cost nothing.