# pretty-format@27.5.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:51.000Z
- Files reviewed: 12
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/pretty-format
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package pretty-format@27.5.1 on Oct 6, 2026. An AI review of 12 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution via Function constructor

Finding ID: `NPS-14D7E22260C0`

File: `build/plugins/AsymmetricMatcher.js:18`

The IIFE used to determine the global object falls back to `Function('return this')()` when neither `globalThis`, `global`, `self`, nor `window` are defined. This constructs and executes code dynamically at module load time. While this is a known pattern used by Jest and similar libraries to obtain the global object, the use of the `Function` constructor is a code-evaluation primitive that could be abused or flagged by security scanners, and its presence in a serialization plugin is unnecessary for the stated functionality.

### [low] Global object tampering / non-standard property access

Finding ID: `NPS-E5B1B0232020`

File: `build/plugins/AsymmetricMatcher.js:24`

The code reads `global['jest-symbol-do-not-touch']` before falling back to `global.Symbol`. This accesses a non-standard global property. Although the name suggests this is intentional (to allow Jest to inject a shared symbol), reading arbitrary global properties from a plugin is a pattern that could be exploited in a compromised environment and may indicate hidden backdoor hooks if the property were writable by an attacker.

### [low] top-level side effect

Finding ID: `NPS-66405B45FD0E`

File: `build/plugins/ReactTestComponent.js:14`

The module performs top-level global object resolution on import, accessing jest-symbol-do-not-touch and Symbol on the global object. This runs at import time but only reads symbols and does not exfiltrate data or execute external code.

### [low] dynamic code execution

Finding ID: `NPS-72E81A600A1D`

File: `build/plugins/ReactTestComponent.js:20`

The global object detection fallback uses Function('return this')(), which is a form of dynamic code execution via the Function constructor. While this is a common safe pattern for obtaining the global object when globalThis/global/self/window are all unavailable, it is still a code-injection-adjacent construct that warrants review.

## Files reviewed

- `build/plugins/AsymmetricMatcher.js` (medium): The file is a legitimate Jest pretty-format plugin for asymmetric matchers, but it uses the Function constructor as a global-object fallback (medium-risk dynamic code execution pattern) and reads a non-standard global property; no exfiltration, credential harvesting, obfuscation, or network/process activity was found.
- `build/plugins/ReactTestComponent.js` (medium): No malicious behavior detected; the only notable pattern is the standard Function('return this')() global resolution fallback, which is a benign but dynamic code execution idiom.
- `build/collections.js` (safe): No malicious patterns detected
- `build/index.js` (safe): No malicious patterns detected in this Jest pretty-format build file; it contains only standard serialization and plugin-loading logic with no network, credential, process, or dynamic execution activity.
- `build/plugins/ConvertAnsi.js` (safe): The code is a Jest plugin that converts ANSI escape codes to human-readable strings using only ansi-regex and ansi-styles, with no suspicious behavior.
- `build/plugins/DOMCollection.js` (safe): No malicious patterns detected; the code is a standard Jest DOM collection serializer plugin with no network, filesystem, process execution, or obfuscated behavior.
- `build/plugins/DOMElement.js` (safe): No malicious patterns detected
- `build/plugins/Immutable.js` (safe): This appears to be a legitimate Jest pretty-format plugin for serializing Immutable.js data structures, with no malicious patterns detected.
- `build/plugins/ReactElement.js` (safe): No malicious patterns detected; this is legitimate Jest React element serialization plugin code from Facebook.
- `build/plugins/lib/escapeHTML.js` (safe): No malicious patterns detected
- `build/plugins/lib/markup.js` (safe): No malicious patterns detected; the code is a benign React element serialization module from Jest with proper HTML escaping and no network, filesystem, or process operations.
- `build/types.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of pretty-format are flagged high or critical. The latest scanned version, 30.4.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 29.7.0 – 30.4.1 (`>=29.7.0 <=30.4.1`): not scanned
- 27.5.1 (`27.5.1`): medium (Dynamic code execution via Function constructor)
- 3.8.0 (`3.8.0`): clean

## Scanned versions

- [27.5.1](https://security.togoder.click/npm/pretty-format@27.5.1): medium, 2026-10-06T14:12:51.000Z
- [3.8.0](https://security.togoder.click/npm/pretty-format@3.8.0): safe, 2026-10-06T14:23:47.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
