# tapable@2.3.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:39.000Z
- Files reviewed: 16
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/tapable
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tapable@2.3.3 on Oct 6, 2026. An AI review of 16 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-931286E45F41`

File: `lib/HookCodeFactory.js:17`

The code uses `new Function(...)` to construct executable JavaScript functions from generated strings. This is a legitimate pattern in webpack's HookCodeFactory for building optimized tap/hook dispatch functions, but it is inherently a dynamic code execution primitive. If the generated string were influenced by untrusted input (e.g., tap names, argument names, interceptor names), this could become a code injection vector.

### [low] dynamic code generation

Finding ID: `NPS-85EEBCCFDE8E`

File: `lib/AsyncParallelBailHook.js:13`

The file builds JavaScript source strings using template literals and passes them to a hook code factory (HookCodeFactory.create) for compilation. This is standard for webpack's Tapable hook code generation and is not eval/Function-based on untrusted input; the generated code comes from a fixed template plus tap metadata. No external or user-controlled input flows into the generated code.

### [low] String-based code generation

Finding ID: `NPS-2FB68C87AF06`

File: `lib/HookCodeFactory.js`

Throughout the file, code strings are assembled via template literals and string concatenation using values derived from `options.args`, tap indices, and interceptor positions. The values are interpolated directly into generated source (e.g., `_x[${idx}]`, `_taps[${idx}]`, `_interceptors[${idx}]`). Indices come from loop counters and are numeric, which limits injection risk, but any non-numeric interpolated input would be dangerous.

## Files reviewed

- `lib/HookCodeFactory.js` (medium): This is a legitimate webpack HookCodeFactory module that uses dynamic `new Function` code generation for hook dispatch; no malicious exfiltration, credential harvesting, process spawning, or network activity is present, but the dynamic code construction pattern warrants awareness.
- `lib/AsyncParallelBailHook.js` (safe): This is a legitimate Tapable AsyncParallelBailHook implementation from webpack with no data exfiltration, credential harvesting, shell execution, or other malicious patterns.
- `lib/AsyncParallelHook.js` (safe): No malicious patterns detected; the code appears to be a standard part of the Tapable library for async parallel hook execution.
- `lib/AsyncSeriesBailHook.js` (safe): No malicious patterns detected; this is a standard webpack/tapable hook implementation with no network, filesystem, process, or obfuscated code.
- `lib/AsyncSeriesHook.js` (safe): No malicious patterns detected
- `lib/AsyncSeriesLoopHook.js` (safe): No malicious patterns detected; this is a standard webpack tapable hook implementation with no network, filesystem, process, or dynamic code execution concerns.
- `lib/AsyncSeriesWaterfallHook.js` (safe): This is a standard implementation of an AsyncSeriesWaterfallHook from the tapable library; no malicious patterns, network activity, credential harvesting, or dynamic code execution were detected.
- `lib/Hook.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/HookMap.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/MultiHook.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/SyncBailHook.js` (safe): No malicious patterns detected
- `lib/SyncHook.js` (safe): No malicious patterns detected
- `lib/SyncLoopHook.js` (safe): No malicious patterns detected
- `lib/SyncWaterfallHook.js` (safe): This is a standard webpack hook implementation with no malicious patterns, network activity, credential access, or dynamic code execution beyond intended hook compilation.
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/util-browser.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
