Home / npm packages / zod
Every file of zod@4.6.5 as published on npm: 840 files, 6.1 MB. Search them by exact text or regex, in milliseconds.
It uses: new Function(), the fs module, crypto.
| API | In zod | |
|---|---|---|
| eval() runs a string as JavaScript | No | Who does |
| new Function() builds a function from a string, like eval (with or without new) | Yes: 1 file e.g. src/v4/classic/tests/jitless-allows-eval.test.ts | See the lines |
| child_process starts other programs | No | Who does |
| process.env reads environment variables | No | Who does |
| the fs module reads and writes files | Yes: 1 file e.g. src/v4/core/tests/locales/parity.test.ts | See the lines |
| http / https makes or serves HTTP requests with Node's own modules | No | Who does |
| fetch() makes HTTP requests | No | Who does |
| XMLHttpRequest makes HTTP requests the old browser way | No | Who does |
| crypto hashes, encrypts or makes random numbers | Yes: 1 file e.g. src/v4/classic/tests/string.test.ts | See the lines |
| WebAssembly loads WebAssembly code | No | Who does |
| document.cookie reads or writes browser cookies | No | Who does |
| install scripts runs a script when it's installed | No | Who does |
Exact matches in the published files, so a mention in a comment counts too: open the lines to check.
Version 4.6.5 of zod publishes 840 files of source, 6.1 MB in all, not counting images, fonts and source maps.
No: zod doesn't call eval() anywhere in its published files.
No: zod doesn't use child_process anywhere in its published files.
No: zod has no preinstall, install or postinstall script in its package.json.
The same engine answers over your documents and repositories: exact text and regex, every match counted, from your code or your AI agent.