# zod@3.22.4 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:54:43.000Z
- Files reviewed: 18
- Findings: no findings
- Report: https://security.togoder.click/npm/zod@3.22.4
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package zod@3.22.4 on Oct 4, 2026. An AI review of 18 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `lib/ZodError.js` (safe): No malicious patterns detected; the file is a standard ZodError implementation with no data exfiltration, credential harvesting, obfuscated code, or other suspicious behavior.
- `lib/benchmarks/discriminatedUnion.js` (safe): No malicious patterns detected
- `lib/benchmarks/index.js` (safe): No malicious patterns detected; the code is a legitimate benchmark runner that loads local benchmark suites and executes them based on command-line arguments.
- `lib/benchmarks/object.js` (safe): No malicious patterns detected
- `lib/benchmarks/primitives.js` (safe): No malicious patterns detected; the file is a legitimate benchmark script using the 'benchmark' and 'zod' libraries with no network, filesystem, process, or dynamic code execution activity.
- `lib/benchmarks/realworld.js` (safe): No malicious patterns detected; the code is a standard benchmark suite using the benchmark and zod libraries.
- `lib/benchmarks/string.js` (safe): No malicious patterns detected
- `lib/benchmarks/union.js` (safe): The code is a standard benchmark suite for the zod library with no malicious patterns detected.
- `lib/errors.js` (safe): No malicious patterns detected; the file only defines error map getter/setter utilities with no external calls, filesystem access, or dynamic execution.
- `lib/external.js` (safe): No malicious patterns detected
- `lib/helpers/enumUtil.js` (safe): No malicious patterns detected
- `lib/helpers/errorUtil.js` (safe): The errorUtil.js file contains only simple, pure utility functions for converting error messages to objects/strings with no malicious patterns, external calls, or side effects.
- `lib/helpers/parseUtil.js` (safe): The code is a standard part of the Zod validation library and contains no malicious patterns; it handles parsing and error aggregation without network, filesystem, or process operations.
- `lib/helpers/partialUtil.js` (safe): No malicious patterns detected
- `lib/helpers/typeAliases.js` (safe): No malicious patterns detected
- `lib/helpers/util.js` (safe): No malicious patterns detected; the code is a standard utility module (likely from Zod) with no network, filesystem, process, or dynamic execution behavior.
- `lib/index.js` (safe): This is standard TypeScript/CommonJS helper code that re-exports from a local './external' module, with no malicious patterns detected.
- `lib/locales/en.js` (safe): No malicious patterns detected

## Version ranges

1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 4.6.5 (`4.6.5`): critical (Dynamic code execution +4 more)
- 3.25.76 – 4.1.13 (`>=3.25.76 <=4.1.13`): medium (Dynamic code execution +2 more)
- 3.23.8 (`3.23.8`): not scanned
- 3.22.4 (`3.22.4`): clean
- Flagged file `v4/core/checks.cjs` (critical) present in 4.6.5
- Flagged file `v4/core/doc.cjs` (critical) present in 4.6.5; finding IDs `NPS-9534A8F558A8`, `NPS-22B097E9EAFF`, `NPS-ADAE75B39B3B`

## Scanned versions

- [4.6.5](https://security.togoder.click/npm/zod@4.6.5): critical, 2026-10-06T14:25:39.000Z
- [4.1.13](https://security.togoder.click/npm/zod@4.1.13): medium, 2026-10-04T16:54:46.000Z
- [3.25.76](https://security.togoder.click/npm/zod@3.25.76): medium, 2026-10-04T16:54:47.000Z
- [3.22.4](https://security.togoder.click/npm/zod@3.22.4): safe, 2026-10-04T16:54:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
