Togoder security

npm package security report

victory-vendor npm package: is it safe?

No malicious code found.

No issues Version 37.3.6 Files reviewed 276 Size 363.7 KB Scanned

Summary

Togoder Security scanned the npm package victory-vendor@37.3.6 on Oct 6, 2026. An AI review of 276 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
d3-array.js safe Cleared by Jev triage; no further analysis needed
d3-ease.js safe Cleared by Jev triage; no further analysis needed
d3-interpolate.js safe Cleared by Jev triage; no further analysis needed
d3-scale.js safe Cleared by Jev triage; no further analysis needed
d3-shape.js safe Cleared by Jev triage; no further analysis needed
d3-time.js safe Cleared by Jev triage; no further analysis needed
d3-timer.js safe Cleared by Jev triage; no further analysis needed
es/d3-array.js safe Cleared by Jev triage; no further analysis needed
es/d3-color.js safe Cleared by Jev triage; no further analysis needed
es/d3-ease.js safe Cleared by Jev triage; no further analysis needed
es/d3-format.js safe Cleared by Jev triage; no further analysis needed
es/d3-interpolate.js safe Cleared by Jev triage; no further analysis needed
es/d3-path.js safe Cleared by Jev triage; no further analysis needed
es/d3-scale.js safe Cleared by Jev triage; no further analysis needed
es/d3-shape.js safe Cleared by Jev triage; no further analysis needed
es/d3-time-format.js safe Cleared by Jev triage; no further analysis needed
es/d3-time.js safe Cleared by Jev triage; no further analysis needed
es/d3-timer.js safe Cleared by Jev triage; no further analysis needed
es/d3-voronoi.js safe Cleared by Jev triage; no further analysis needed
es/internmap.js safe Cleared by Jev triage; no further analysis needed
lib-vendor/d3-array/src/array.js safe No malicious patterns detected
lib-vendor/d3-array/src/ascending.js safe No malicious patterns detected
lib-vendor/d3-array/src/bin.js safe No malicious patterns detected; the file is a legitimate D3.js histogram binning implementation with standard module imports and no suspicious behavior.
lib-vendor/d3-array/src/bisect.js safe No malicious patterns detected; this is a standard D3.js array bisect utility module with only static imports and exports.
lib-vendor/d3-array/src/bisector.js safe No malicious patterns detected; the file contains standard d3-array bisector logic with no network, filesystem, process, or dynamic execution concerns.
Show 251 more files
FileVerdictWhat the reviewer saw
lib-vendor/d3-array/src/constant.js safe No malicious patterns detected
lib-vendor/d3-array/src/count.js safe No malicious patterns detected; the file is a simple count utility function with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-array/src/cross.js safe No malicious patterns detected
lib-vendor/d3-array/src/cumsum.js safe The code is a simple cumulative sum implementation using Float64Array with no malicious patterns detected.
lib-vendor/d3-array/src/descending.js safe No malicious patterns found; this is a simple descending comparator function with no external calls or side effects.
lib-vendor/d3-array/src/deviation.js safe No malicious patterns detected; the file contains a simple mathematical deviation calculation with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-array/src/difference.js safe No malicious patterns detected
lib-vendor/d3-array/src/disjoint.js safe No malicious patterns detected
lib-vendor/d3-array/src/every.js safe No malicious patterns detected; the code is a simple array iteration utility with no network, filesystem, process, or dynamic code execution activity.
lib-vendor/d3-array/src/extent.js safe No malicious patterns detected
lib-vendor/d3-array/src/filter.js safe No malicious patterns detected; the code is a simple array filter utility with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-array/src/fsum.js safe No malicious patterns detected; the code implements a floating-point sum algorithm with no network, file, process, or dynamic execution behavior.
lib-vendor/d3-array/src/greatest.js safe The code is a standard implementation of a greatest/argmax utility function from the d3-array library with no malicious patterns detected.
lib-vendor/d3-array/src/greatestIndex.js safe No malicious patterns detected
lib-vendor/d3-array/src/group.js safe No malicious patterns detected
lib-vendor/d3-array/src/groupSort.js safe No malicious patterns detected; the file contains standard d3-array groupSort implementation with Babel interop helpers, performing only local data grouping and sorting.
lib-vendor/d3-array/src/identity.js safe No malicious patterns detected
lib-vendor/d3-array/src/index.js safe This is a standard ES module re-export index file for the d3-array library, containing only static require() and Object.defineProperty() calls to expose known internal utilities with no dynamic or suspicious behavior.
lib-vendor/d3-array/src/intersection.js safe No malicious patterns detected
lib-vendor/d3-array/src/least.js safe No malicious patterns detected
lib-vendor/d3-array/src/leastIndex.js safe No malicious patterns detected
lib-vendor/d3-array/src/map.js safe No malicious patterns detected; the code is a simple iterable mapping utility with input validation and no side effects or external calls.
lib-vendor/d3-array/src/max.js safe No malicious patterns detected
lib-vendor/d3-array/src/maxIndex.js safe No malicious patterns detected; this is a standard d3-array maxIndex utility function with no network, filesystem, process, or dynamic code execution activity.
lib-vendor/d3-array/src/mean.js safe No malicious patterns detected; the code is a standard statistical mean calculation function with no security concerns.
lib-vendor/d3-array/src/median.js safe No malicious patterns detected; the code is a simple statistical median utility with no network, filesystem, or dynamic code execution behavior.
lib-vendor/d3-array/src/merge.js safe No malicious patterns detected; the file contains a benign implementation of an array merge utility using a generator.
lib-vendor/d3-array/src/min.js safe No malicious patterns detected; this is a benign min() utility function from d3-array.
lib-vendor/d3-array/src/minIndex.js safe No malicious patterns detected; the code is a benign utility function mimicking d3-array's minIndex with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-array/src/mode.js safe No malicious patterns detected
lib-vendor/d3-array/src/nice.js safe No malicious patterns detected; the code is a standard d3-array utility for computing nice axis tick boundaries.
lib-vendor/d3-array/src/number.js safe No malicious patterns detected
lib-vendor/d3-array/src/pairs.js safe No malicious patterns detected; the code is a benign utility for creating pairs from an iterable.
lib-vendor/d3-array/src/permute.js safe No malicious patterns detected
lib-vendor/d3-array/src/quantile.js safe No malicious patterns detected
lib-vendor/d3-array/src/quickselect.js safe No malicious patterns detected
lib-vendor/d3-array/src/range.js safe No malicious patterns detected
lib-vendor/d3-array/src/rank.js safe No malicious patterns detected; the code is a legitimate implementation of the rank function from d3-array.
lib-vendor/d3-array/src/reduce.js safe The code implements a standard reduce function for iterables with no malicious patterns, external calls, or suspicious behavior.
lib-vendor/d3-array/src/reverse.js safe The code is a benign utility function that reverses an iterable, with no malicious patterns detected.
lib-vendor/d3-array/src/scan.js safe The code is a simple utility function for finding the index of the minimum value, with no malicious patterns, external calls, or unsafe operations.
lib-vendor/d3-array/src/shuffle.js safe The code is a straightforward Fisher-Yates shuffle implementation with no malicious patterns, external calls, or suspicious behavior.
lib-vendor/d3-array/src/some.js safe No malicious patterns detected
lib-vendor/d3-array/src/sort.js safe No malicious patterns detected
lib-vendor/d3-array/src/subset.js safe No malicious patterns detected
lib-vendor/d3-array/src/sum.js safe No malicious patterns detected
lib-vendor/d3-array/src/superset.js safe No malicious patterns detected; the code implements a benign superset-checking algorithm from d3-array.
lib-vendor/d3-array/src/threshold/freedmanDiaconis.js safe No malicious patterns detected; the code is a simple statistical threshold calculation using D3 utility functions.
lib-vendor/d3-array/src/threshold/scott.js safe No malicious patterns detected
lib-vendor/d3-array/src/threshold/sturges.js safe The file implements a simple Sturges' formula threshold function using Math.log and a relative import of a local count utility, with no malicious patterns detected.
lib-vendor/d3-array/src/ticks.js safe No malicious patterns detected; the code is a legitimate mathematical utility for computing tick values.
lib-vendor/d3-array/src/transpose.js safe No malicious patterns detected; the file is a benign matrix transposition utility from d3-array.
lib-vendor/d3-array/src/union.js safe No malicious patterns detected; the code is a simple utility function implementing a set union using InternSet with no external I/O, dynamic execution, or suspicious behavior.
lib-vendor/d3-array/src/variance.js safe No malicious patterns detected; the file contains a standard statistical variance implementation with no network, filesystem, process, or dynamic execution activity.
lib-vendor/d3-array/src/zip.js safe No malicious patterns detected; this is a benign utility module that re-exports the transpose function as zip.
lib-vendor/d3-color/src/color.js safe No malicious patterns detected in the d3-color utility module.
lib-vendor/d3-color/src/cubehelix.js safe No malicious patterns detected; this is a legitimate D3 color conversion module performing only mathematical color space transformations.
lib-vendor/d3-color/src/define.js safe No malicious patterns detected; the file contains only standard prototype inheritance helper functions with no network, filesystem, process, or dynamic execution capabilities.
lib-vendor/d3-color/src/index.js safe This is a standard Babel-compiled CommonJS entry point for the d3-color library that only re-exports functions from local sibling modules, with no network, filesystem, process, or dynamic code execution patterns.
lib-vendor/d3-color/src/lab.js safe This file implements standard D3 color space conversion (Lab/HCL) with no malicious patterns, network activity, file system access, or dynamic code execution.
lib-vendor/d3-color/src/math.js safe No malicious patterns detected
lib-vendor/d3-ease/src/back.js safe No malicious patterns detected; this is a standard, benign easing function implementation from the d3-ease library.
lib-vendor/d3-ease/src/bounce.js safe No malicious patterns detected
lib-vendor/d3-ease/src/circle.js safe No malicious patterns detected
lib-vendor/d3-ease/src/cubic.js safe No malicious patterns detected; this is a standard implementation of cubic easing functions with no external I/O, environment access, dynamic execution, or network activity.
lib-vendor/d3-ease/src/elastic.js safe No malicious patterns detected
lib-vendor/d3-ease/src/exp.js safe No malicious patterns detected
lib-vendor/d3-ease/src/index.js safe No malicious patterns detected
lib-vendor/d3-ease/src/linear.js safe No malicious patterns detected
lib-vendor/d3-ease/src/math.js safe No malicious patterns detected
lib-vendor/d3-ease/src/poly.js safe No malicious patterns detected
lib-vendor/d3-ease/src/quad.js safe No malicious patterns detected
lib-vendor/d3-ease/src/sin.js safe No malicious patterns detected; the file contains only pure mathematical easing functions with no I/O, network, or dynamic code execution.
lib-vendor/d3-format/src/defaultLocale.js safe This file is a benign locale configuration module from the d3-format library with no malicious patterns, network calls, obfuscation, or process execution.
lib-vendor/d3-format/src/exponent.js safe No malicious patterns detected
lib-vendor/d3-format/src/formatDecimal.js safe No malicious patterns detected
lib-vendor/d3-format/src/formatGroup.js safe The code is a benign number formatting utility from the d3-format library with no malicious patterns detected.
lib-vendor/d3-format/src/formatNumerals.js safe No malicious patterns detected
lib-vendor/d3-format/src/formatPrefixAuto.js safe No malicious patterns detected; the code is a benign number formatting utility from the d3-format library.
lib-vendor/d3-format/src/formatRounded.js safe No malicious patterns detected
lib-vendor/d3-format/src/formatSpecifier.js safe No malicious patterns detected; the file only implements safe format specifier parsing for d3-format.
lib-vendor/d3-format/src/formatTrim.js safe No malicious patterns detected; the file contains only a pure string-trimming utility with no I/O, network, or dynamic execution.
lib-vendor/d3-format/src/formatTypes.js safe No malicious patterns detected
lib-vendor/d3-format/src/identity.js safe No malicious patterns detected; the file contains a trivial identity function with no side effects, network activity, or dynamic execution.
lib-vendor/d3-format/src/index.js safe No malicious patterns detected; the file is a standard Babel-compiled ES module index that only re-exports functions from local d3-format modules.
lib-vendor/d3-format/src/locale.js safe This is a standard d3-format locale implementation with no malicious patterns detected.
lib-vendor/d3-format/src/precisionFixed.js safe No malicious patterns detected
lib-vendor/d3-format/src/precisionPrefix.js safe No malicious patterns detected
lib-vendor/d3-format/src/precisionRound.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/array.js safe No malicious patterns detected; the code is a standard D3 array interpolation utility with only benign module imports and no data exfiltration, credential harvesting, dynamic execution, or process spawning.
lib-vendor/d3-interpolate/src/basis.js safe This is a standard, non-obfuscated mathematical interpolation function from d3-interpolate with no network, filesystem, process, or dynamic code execution activity.
lib-vendor/d3-interpolate/src/basisClosed.js safe No malicious patterns detected; the file is a legitimate mathematical interpolation utility from the d3-interpolate package with no network, filesystem, process, or dynamic execution activity.
lib-vendor/d3-interpolate/src/color.js safe No malicious patterns detected; the file contains standard color interpolation logic from the d3-interpolate library with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-interpolate/src/constant.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/cubehelix.js safe No malicious patterns detected; the file is a standard d3-interpolate cubehelix color interpolation module with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-interpolate/src/date.js safe No malicious patterns detected; this is a legitimate d3-interpolate date interpolation function.
lib-vendor/d3-interpolate/src/discrete.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/hcl.js safe No malicious patterns detected; this is a standard D3 color interpolation module with no network, file system, process execution, or obfuscated code.
lib-vendor/d3-interpolate/src/hsl.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/hue.js safe No malicious patterns detected; this is a legitimate color hue interpolation utility from the d3-interpolate library.
lib-vendor/d3-interpolate/src/index.js safe This is a standard Babel-compiled ES module index file for the d3-interpolate library that only re-exports interpolation functions with no malicious patterns.
lib-vendor/d3-interpolate/src/lab.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/number.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/numberArray.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/object.js safe No malicious patterns detected; this is a standard d3-interpolate object interpolation utility with no network, filesystem, or dynamic execution activity.
lib-vendor/d3-interpolate/src/piecewise.js safe No malicious patterns detected; this is a legitimate d3-interpolate utility for piecewise interpolation with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-interpolate/src/quantize.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/rgb.js safe The code is a legitimate D3.js color interpolation module with no malicious patterns, network activity, or execution of untrusted input.
lib-vendor/d3-interpolate/src/round.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/string.js safe No malicious patterns detected; this is a legitimate d3-interpolate string interpolation module.
lib-vendor/d3-interpolate/src/transform/decompose.js safe No malicious patterns detected
lib-vendor/d3-interpolate/src/transform/index.js safe No malicious patterns detected; this is a legitimate d3-interpolate transform interpolation module with only internal requires and pure math/string manipulation.
lib-vendor/d3-interpolate/src/transform/parse.js safe No malicious patterns detected; this is a legitimate d3-interpolate transform parsing module with no exfiltration, code execution, or filesystem abuse.
lib-vendor/d3-interpolate/src/value.js safe This is a standard d3-interpolate value selection module with no malicious patterns, network calls, file system access, or dynamic code execution.
lib-vendor/d3-interpolate/src/zoom.js safe No malicious patterns detected; the code is a legitimate d3-interpolate zoom interpolation implementation using only pure math functions.
lib-vendor/d3-path/src/index.js safe No malicious patterns detected
lib-vendor/d3-path/src/path.js safe No malicious patterns detected
lib-vendor/d3-scale/src/band.js safe No malicious patterns detected
lib-vendor/d3-scale/src/colors.js safe No malicious patterns detected; the function only performs simple string parsing and formatting for color conversion.
lib-vendor/d3-scale/src/constant.js safe No malicious patterns detected
lib-vendor/d3-scale/src/continuous.js safe No malicious patterns detected; the file contains standard D3 scale interpolation logic with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-scale/src/diverging.js safe This is a legitimate vendored copy of d3-scale's diverging scale module with no malicious patterns, network calls, credential access, or dynamic code execution.
lib-vendor/d3-scale/src/identity.js safe No malicious patterns detected; the code is a standard d3-scale identity scale implementation with no network, filesystem, process, or dynamic execution activity.
lib-vendor/d3-scale/src/index.js safe No malicious patterns detected
lib-vendor/d3-scale/src/init.js safe No malicious patterns detected; the file contains only benign d3-scale initialization helper functions.
lib-vendor/d3-scale/src/linear.js safe No malicious patterns detected
lib-vendor/d3-scale/src/log.js safe No malicious patterns detected
lib-vendor/d3-scale/src/nice.js safe No malicious patterns detected
lib-vendor/d3-scale/src/number.js safe No malicious patterns detected
lib-vendor/d3-scale/src/ordinal.js safe No malicious patterns detected; the code is a standard D3 ordinal scale implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
lib-vendor/d3-scale/src/pow.js safe No malicious patterns detected; the file contains pure math/scale functions with no network, filesystem, process, or dynamic code execution.
lib-vendor/d3-scale/src/quantile.js safe No malicious patterns detected; this is a legitimate d3-scale quantile scale implementation with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-scale/src/quantize.js safe No malicious patterns detected; this is a standard D3 quantize scale implementation with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-scale/src/radial.js safe No malicious patterns detected; this is a standard D3 scale implementation with no network, filesystem, process, or dynamic-code-execution behavior.
lib-vendor/d3-scale/src/sequential.js safe No malicious patterns detected; this is a standard d3-scale sequential scale implementation with only mathematical/interpolation logic and local module imports.
lib-vendor/d3-scale/src/sequentialQuantile.js safe No malicious patterns detected
lib-vendor/d3-scale/src/symlog.js safe No malicious patterns detected
lib-vendor/d3-scale/src/threshold.js safe No malicious patterns detected; this is a standard d3-scale threshold scale implementation with no network, filesystem, process, or dynamic code execution activity.
lib-vendor/d3-scale/src/tickFormat.js safe No malicious patterns detected; the code is a standard d3-scale tick formatting utility with only internal module imports and no network, file, process, or dynamic execution behavior.
lib-vendor/d3-scale/src/time.js safe No malicious patterns detected
lib-vendor/d3-scale/src/utcTime.js safe No malicious patterns detected; this is a standard D3.js UTC time scale utility module with legitimate imports and no suspicious behavior.
lib-vendor/d3-shape/src/arc.js safe This is a legitimate vendored copy of the d3-shape arc module containing only pure geometry/math code with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-shape/src/area.js safe No malicious patterns detected; the file is a standard vendored d3-shape area generator with only relative imports and no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-shape/src/areaRadial.js safe This is a standard D3.js areaRadial module with only local module imports and no malicious patterns.
lib-vendor/d3-shape/src/array.js safe No malicious patterns detected; the file is a benign utility from the d3-shape library that normalizes array-like inputs.
lib-vendor/d3-shape/src/constant.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/basis.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/basisClosed.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/basisOpen.js safe No malicious patterns detected; this is a benign D3.js curve implementation with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-shape/src/curve/bump.js safe No malicious patterns detected; the code is a legitimate D3 shape curve implementation with no network, filesystem, process, or dynamic execution activity.
lib-vendor/d3-shape/src/curve/bundle.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/cardinal.js safe No malicious patterns detected; the code is a standard D3 shape curve implementation with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-shape/src/curve/cardinalClosed.js safe No malicious patterns detected in this D3.js curve implementation; the code contains only benign geometric path calculations.
lib-vendor/d3-shape/src/curve/cardinalOpen.js safe No malicious patterns detected; this is a benign d3-shape curve implementation with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-shape/src/curve/catmullRom.js safe No malicious patterns detected; this is a legitimate D3.js shape curve implementation.
lib-vendor/d3-shape/src/curve/catmullRomClosed.js safe No malicious patterns detected; the code is a legitimate implementation of the Catmull-Rom closed curve from the d3-shape library.
lib-vendor/d3-shape/src/curve/catmullRomOpen.js safe This is a legitimate D3.js curve interpolation module with no malicious patterns, network activity, or code execution.
lib-vendor/d3-shape/src/curve/linear.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/linearClosed.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/monotone.js safe No malicious patterns detected; the file is a legitimate D3 shape curve implementation with no network, file system, process, dynamic code, or credential access.
lib-vendor/d3-shape/src/curve/natural.js safe No malicious patterns detected; this is a standard d3-shape natural cubic spline curve implementation.
lib-vendor/d3-shape/src/curve/radial.js safe No malicious patterns detected
lib-vendor/d3-shape/src/curve/step.js safe No malicious patterns detected; the code is a legitimate d3-shape step curve implementation with no network, filesystem, process, or dynamic execution activity.
lib-vendor/d3-shape/src/descending.js safe No malicious patterns detected
lib-vendor/d3-shape/src/identity.js safe No malicious patterns detected
lib-vendor/d3-shape/src/index.js safe No malicious patterns detected; this is a standard Babel-compiled ES module index file for the d3-shape library that only re-exports its own local modules.
lib-vendor/d3-shape/src/line.js safe No malicious patterns detected
lib-vendor/d3-shape/src/lineRadial.js safe No malicious patterns detected; the code is a standard d3-shape module for radial line generation with only safe import/export and property manipulation logic.
lib-vendor/d3-shape/src/link.js safe The code is a legitimate D3.js link shape generator module with no malicious patterns detected.
lib-vendor/d3-shape/src/math.js safe No malicious patterns detected
lib-vendor/d3-shape/src/noop.js safe No malicious patterns detected
lib-vendor/d3-shape/src/offset/diverging.js safe No malicious patterns detected; the code is a standard D3 shape offset implementation with no network, file system, process, or dynamic code execution activity.
lib-vendor/d3-shape/src/offset/expand.js safe No malicious patterns detected; the code is a benign d3-shape stack offset implementation with only internal module imports and no dynamic execution, network, filesystem, or process activity.
lib-vendor/d3-shape/src/offset/none.js safe No malicious patterns detected; the file contains a benign d3-shape offset implementation with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-shape/src/offset/silhouette.js safe No malicious patterns detected
lib-vendor/d3-shape/src/offset/wiggle.js safe No malicious patterns detected
lib-vendor/d3-shape/src/order/appearance.js safe No malicious patterns detected
lib-vendor/d3-shape/src/order/ascending.js safe No malicious patterns detected; the code is a standard d3-shape ordering utility that computes sums and sorts series without network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-shape/src/order/descending.js safe No malicious patterns detected
lib-vendor/d3-shape/src/order/insideOut.js safe No malicious patterns detected; the code is a standard d3-shape ordering utility with only local module imports and pure computation.
lib-vendor/d3-shape/src/order/none.js safe No malicious patterns detected
lib-vendor/d3-shape/src/order/reverse.js safe No malicious patterns detected
lib-vendor/d3-shape/src/pie.js safe This is a legitimate, unmodified d3-shape pie chart generation module with no malicious patterns detected.
lib-vendor/d3-shape/src/point.js safe No malicious patterns detected
lib-vendor/d3-shape/src/pointRadial.js safe No malicious patterns detected
lib-vendor/d3-shape/src/stack.js safe No malicious patterns detected; this is a legitimate d3-shape stack layout utility with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-shape/src/symbol.js safe No malicious patterns detected; the file is a standard, minified d3-shape symbol module with only static imports and no dynamic code execution, network or filesystem access, or credential harvesting.
lib-vendor/d3-shape/src/symbol/asterisk.js safe No malicious patterns detected
lib-vendor/d3-shape/src/symbol/circle.js safe No malicious patterns detected; the code is a simple circle drawing utility from the d3-shape library.
lib-vendor/d3-shape/src/symbol/cross.js safe This file contains only a pure geometric drawing function for a cross symbol with no network, filesystem, process, or dynamic execution activity.
lib-vendor/d3-shape/src/symbol/diamond.js safe No malicious patterns detected; the file only defines a geometric diamond symbol drawing function using simple math and canvas context calls.
lib-vendor/d3-shape/src/symbol/diamond2.js safe No malicious patterns detected; this is a benign D3.js diamond symbol renderer with no network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-shape/src/symbol/plus.js safe No malicious patterns detected; the file only defines a D3 shape symbol drawing function with no network, filesystem, process, or code execution behavior.
lib-vendor/d3-shape/src/symbol/square.js safe No malicious patterns detected
lib-vendor/d3-shape/src/symbol/square2.js safe No malicious patterns detected
lib-vendor/d3-shape/src/symbol/star.js safe No malicious patterns detected
lib-vendor/d3-shape/src/symbol/triangle.js safe No malicious patterns detected; the file contains a standard geometric drawing function for a triangle symbol in the d3-shape library.
lib-vendor/d3-shape/src/symbol/triangle2.js safe No malicious patterns detected
lib-vendor/d3-shape/src/symbol/wye.js safe The file contains only benign mathematical geometry code for drawing a 'wye' symbol in the d3-shape library, with no malicious patterns detected.
lib-vendor/d3-shape/src/symbol/x.js safe No malicious patterns detected
lib-vendor/d3-time-format/src/defaultLocale.js safe No malicious patterns detected
lib-vendor/d3-time-format/src/index.js safe No malicious patterns detected
lib-vendor/d3-time-format/src/isoFormat.js safe No malicious patterns detected; the file contains standard ISO date formatting logic using Date.prototype.toISOString or utcFormat fallback.
lib-vendor/d3-time-format/src/isoParse.js safe No malicious patterns detected; this is a legitimate ISO date parsing module from d3-time-format.
lib-vendor/d3-time-format/src/locale.js safe No malicious patterns detected; the code is a standard date/time formatting and parsing implementation from d3-time-format.
lib-vendor/d3-time/src/day.js safe No malicious patterns detected; this is a benign d3-time interval utility.
lib-vendor/d3-time/src/duration.js safe No malicious patterns detected
lib-vendor/d3-time/src/hour.js safe No malicious patterns detected; this is a standard d3-time interval module for hour-based date manipulation with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-time/src/index.js safe No malicious patterns detected; this is a standard ES module re-export file for d3-time with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-time/src/interval.js safe No malicious patterns detected; the code is a legitimate date interval utility from d3-time with no network, filesystem, process execution, or obfuscation concerns.
lib-vendor/d3-time/src/millisecond.js safe No malicious patterns detected; this is a standard d3-time interval implementation for millisecond manipulation.
lib-vendor/d3-time/src/minute.js safe No malicious patterns detected
lib-vendor/d3-time/src/month.js safe No malicious patterns detected
lib-vendor/d3-time/src/second.js safe No malicious patterns detected; the file contains standard d3-time interval logic for second-based time intervals.
lib-vendor/d3-time/src/ticks.js safe No malicious patterns detected in the d3-time ticks module; the code contains only standard date/time tick generation logic with no network, filesystem, process execution, or obfuscation concerns.
lib-vendor/d3-time/src/utcDay.js safe No malicious patterns detected; this is standard d3-time utcDay interval utility code.
lib-vendor/d3-time/src/utcHour.js safe No malicious patterns detected; this is a standard D3 time interval utility for UTC hours with no network, filesystem, process, or dynamic execution behavior.
lib-vendor/d3-time/src/utcMinute.js safe No malicious patterns detected
lib-vendor/d3-time/src/utcMonth.js safe No malicious patterns detected
lib-vendor/d3-time/src/utcWeek.js safe No malicious patterns detected
lib-vendor/d3-time/src/utcYear.js safe No malicious patterns detected; the file contains standard d3-time UTC year interval logic with no exfiltration, obfuscation, or dynamic execution.
lib-vendor/d3-time/src/week.js safe No malicious patterns detected
lib-vendor/d3-time/src/year.js safe No malicious patterns detected; the code is a standard d3-time year interval implementation with no network, filesystem, or dynamic code execution behavior.
lib-vendor/d3-timer/src/index.js safe No malicious patterns detected
lib-vendor/d3-timer/src/interval.js safe No malicious patterns detected
lib-vendor/d3-timer/src/timeout.js safe No malicious patterns detected
lib-vendor/d3-timer/src/timer.js safe The code is a standard implementation of d3-timer with no malicious patterns, explicitly avoiding dynamic code execution, network requests, or filesystem access.
lib-vendor/d3-voronoi/src/Beach.js safe This is a standard implementation of the Beachline data structure for Fortune's algorithm in d3-voronoi, with no malicious patterns, network activity, file system access, or dynamic code execution.
lib-vendor/d3-voronoi/src/Cell.js safe No malicious patterns detected; the code is a legitimate implementation of Voronoi cell clipping from the d3-voronoi library.
lib-vendor/d3-voronoi/src/Circle.js safe No malicious patterns detected; this is a legitimate computational geometry implementation for Voronoi diagram circle attachment with no network, filesystem, process, or dynamic code execution activity.
lib-vendor/d3-voronoi/src/Diagram.js safe No malicious patterns detected; the code is a legitimate Voronoi diagram implementation from d3-voronoi with no network, filesystem, process execution, or obfuscation concerns.
lib-vendor/d3-voronoi/src/Edge.js safe No malicious patterns detected; the file implements standard computational geometry algorithms for Voronoi diagram edge clipping without any network, filesystem, process, or dynamic code execution behavior.
lib-vendor/d3-voronoi/src/RedBlackTree.js safe No malicious patterns detected
lib-vendor/d3-voronoi/src/constant.js safe This is a trivial constant function generator with no malicious patterns, network activity, file system access, or dynamic code execution.
lib-vendor/d3-voronoi/src/index.js safe No malicious patterns detected; the file is a standard Babel-compiled CommonJS re-export module for d3-voronoi.
lib-vendor/d3-voronoi/src/point.js safe No malicious patterns detected
lib-vendor/d3-voronoi/src/voronoi.js safe No malicious patterns detected; the code is a standard d3-voronoi module implementation with only internal module imports and no external network, filesystem, or process access.
lib-vendor/internmap/src/index.js safe No malicious patterns detected; the code is a benign implementation of an interning Map/Set data structure with no network, filesystem, process, or dynamic execution behavior.
lib/d3-array.js safe Cleared by Jev triage; no further analysis needed
lib/d3-color.js safe Cleared by Jev triage; no further analysis needed
lib/d3-ease.js safe Cleared by Jev triage; no further analysis needed
lib/d3-format.js safe Cleared by Jev triage; no further analysis needed
lib/d3-interpolate.js safe Cleared by Jev triage; no further analysis needed
lib/d3-path.js safe Cleared by Jev triage; no further analysis needed
lib/d3-scale.js safe Cleared by Jev triage; no further analysis needed
lib/d3-shape.js safe Cleared by Jev triage; no further analysis needed
lib/d3-time-format.js safe Cleared by Jev triage; no further analysis needed
lib/d3-time.js safe Cleared by Jev triage; no further analysis needed
lib/d3-timer.js safe Cleared by Jev triage; no further analysis needed
lib/d3-voronoi.js safe Cleared by Jev triage; no further analysis needed
lib/internmap.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of victory-vendor

VersionVerdictFilesScanned
37.3.6 No issues 276 Oct 6, 2026

Frequently asked questions

Is victory-vendor safe to use?

Our AI source review of victory-vendor@37.3.6 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does victory-vendor contain malware?

No malware was identified in victory-vendor@37.3.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was victory-vendor checked?

Togoder Security downloaded the published npm package and had an AI model read its 276 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan victory-vendor together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in victory-vendor@37.3.6, cost nothing.

Related security reports