# once@1.4.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T14:41:05.000Z
- Files reviewed: 1
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/once
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package once@1.4.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Global prototype pollution

Finding ID: `NPS-A803DEB8E12B`

File: `once.js:5`

The `once.proto()` function modifies `Function.prototype` by adding `once` and `onceStrict` methods. This is a global mutation that can affect all functions in the runtime, potentially interfering with other libraries or applications. While not inherently malicious, it is an intrusive anti-pattern and could be exploited or cause unexpected side effects.

### [low] Non-standard API surface

Finding ID: `NPS-047E9FBB98D9`

File: `once.js:5`

The module exposes an optional `proto()` method that extends global built-ins. This code runs when invoked, not automatically, but it represents an invasive capability that goes beyond the expected behavior of a simple `once` utility.

## Files reviewed

- `once.js` (medium): The package is a legitimate utility for function memoization but includes an optional global prototype augmentation that poses a moderate risk of runtime interference.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
