Togoder security

npm package security report

zod@3.22.4 security report

No malicious code found.

No issues Version 3.22.4 Files reviewed 18 Size 449.7 KB Scanned

Summary

Togoder Security scanned the npm package zod@3.22.4 on Oct 4, 2026. An AI review of 18 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
lib/ZodError.js safe No malicious patterns detected; the file is a standard ZodError implementation with no data exfiltration, credential harvesting, obfuscated code, or other suspicious behavior.
lib/benchmarks/discriminatedUnion.js safe No malicious patterns detected
lib/benchmarks/index.js safe No malicious patterns detected; the code is a legitimate benchmark runner that loads local benchmark suites and executes them based on command-line arguments.
lib/benchmarks/object.js safe No malicious patterns detected
lib/benchmarks/primitives.js safe No malicious patterns detected; the file is a legitimate benchmark script using the 'benchmark' and 'zod' libraries with no network, filesystem, process, or dynamic code execution activity.
lib/benchmarks/realworld.js safe No malicious patterns detected; the code is a standard benchmark suite using the benchmark and zod libraries.
lib/benchmarks/string.js safe No malicious patterns detected
lib/benchmarks/union.js safe The code is a standard benchmark suite for the zod library with no malicious patterns detected.
lib/errors.js safe No malicious patterns detected; the file only defines error map getter/setter utilities with no external calls, filesystem access, or dynamic execution.
lib/external.js safe No malicious patterns detected
lib/helpers/enumUtil.js safe No malicious patterns detected
lib/helpers/errorUtil.js safe The errorUtil.js file contains only simple, pure utility functions for converting error messages to objects/strings with no malicious patterns, external calls, or side effects.
lib/helpers/parseUtil.js safe The code is a standard part of the Zod validation library and contains no malicious patterns; it handles parsing and error aggregation without network, filesystem, or process operations.
lib/helpers/partialUtil.js safe No malicious patterns detected
lib/helpers/typeAliases.js safe No malicious patterns detected
lib/helpers/util.js safe No malicious patterns detected; the code is a standard utility module (likely from Zod) with no network, filesystem, process, or dynamic execution behavior.
lib/index.js safe This is standard TypeScript/CommonJS helper code that re-exports from a local './external' module, with no malicious patterns detected.
lib/locales/en.js safe No malicious patterns detected

Affected version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

3.22.44.6.5
VersionsVerdictCountRangeTop findings
4.6.5 Critical 1 4.6.5 Dynamic code execution; Dynamic code execution via new Function
3.25.76 โ€“ 4.1.13 Needs review 2 >=3.25.76 <=4.1.13 Dynamic code execution; Dynamic code execution via Function constructor
3.23.8 Not scanned 1 3.23.8
3.22.4 No issues 1 3.22.4

Flagged files across versions

  • critical v4/core/checks.cjs: present in 4.6.5
  • critical v4/core/doc.cjs (Dynamic code execution) NPS-9534A8F558A8: present in 4.6.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of zod

VersionVerdictFilesScanned
4.6.5 Critical risk 375 Oct 6, 2026
4.1.13 Needs review 298 Oct 4, 2026
3.25.76 Needs review 271 Oct 4, 2026
3.22.4 No issues 18 Oct 4, 2026

Frequently asked questions

Is zod safe to use?

Our AI source review of zod@3.22.4 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does zod contain malware?

No malware was identified in zod@3.22.4 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was zod checked?

Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan zod together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zod@3.22.4, cost nothing.

Related security reports