# notevil

> Evalulate javascript like the built-in eval() method but safely

Latest version **1.3.3** (published 2020-03-04) · MIT license · 0 weekly downloads

> **Deprecated.** This package is deprecated.

## Install

```sh
npm install notevil
pnpm add notevil
yarn add notevil
bun add notevil
```

## Health

**Score 10/100 (F)** — status: deprecated.

Negative: deprecated.

## Facts

| | |
|---|---|
| Version | 1.3.3 |
| Published | 2020-03-04 |
| First published | 2013-11-02 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 2 |
| Unpacked size | 33.3 KB |
| Known vulnerabilities | 1 |
| Install scripts | no |
| GitHub stars | 194 |
| Author | Matt McKegg |
| Maintainers | mmckegg |
| Keywords | eval, sandbox, esprima, safe, expression |

## Links

- npm: https://www.npmjs.com/package/notevil
- Repository: https://github.com/mmckegg/notevil
- Homepage: https://github.com/mmckegg/notevil#readme
- Issues: https://github.com/mmckegg/notevil/issues
- npm.io page: https://npm.io/package/notevil

## Dependencies (2)

- [esprima](https://npm.io/package/esprima.md) ~1.0
- [hoister](https://npm.io/package/hoister.md) ~0.0

## Recent versions

- 1.3.3 (latest) — 2020-03-04
- 1.3.2 — 2019-08-29
- 1.3.1 — 2019-05-08
- 1.3.0 — 2019-05-08
- 1.2.0 — 2019-05-03
- 1.1.0 — 2017-02-05
- 1.0.0 — 2015-03-18
- 0.8.1 — 2014-07-03
- 0.8.0 — 2013-12-03
- 0.7.0 — 2013-11-25
- 0.6.0 — 2013-11-25
- 0.5.0 — 2013-11-25
- 0.4.0 — 2013-11-24
- 0.3.0 — 2013-11-24
- 0.2.0 — 2013-11-24
- … 4 more at https://npm.io/package/notevil/versions

## README

notevil
===

Evalulate javascript like the built-in javascript `eval()` method but **safely**. 

This module uses [esprima](https://github.com/ariya/esprima) to parse the javascript AST then walks each node and evaluates the result. 

Like built-in `eval`, the result of the last expression will be returned. Unlike built-in, there is no access to global objects, only the context that is passed in as the second object.

Built in types such as `Object` and `String` are still available, but they are wrapped so that any changes to prototypes are contained in the eval instance.

[![NPM](https://nodei.co/npm/notevil.png?compact=true)](https://nodei.co/npm/notevil/)

## Example

```js
var safeEval = require('notevil')

// basic math
var result = safeEval('1+2+3')
console.log(result) // 6

// context and functions
var result = safeEval('1+f(2,3)+x', {
  x: 100, 
  f: function(a,b){
    return a*b
  }
})
console.log(result) // 107

// multiple statements, variables and if statements
var result = safeEval('var x = 100, y = 200; if (x > y) { "cats" } else { "dogs" }')
console.log(result) // dogs

// inner functions
var result = safeEval('[1,2,3,4].map(function(item){ return item*100 })')
console.log(result) // [100, 200, 300, 400]
```

### Updating context from safeEval

```js
var context = { x: 1, obj: {y: 2} }

// update context global
safeEval('x = 300', context)
console.log(context.x) // 300

// update property on object
safeEval('obj.y = 300', context)
console.log(context.obj.y) // 300
```

### Creating functions
```js
var func = safeEval.Function('param', 'return param * 100')
var result = func(2)
console.log(result) // 200
```

### Tracing errors

A `.trace` property is available on error objects generated by code running inside of the sandbox. It contains an array containing the esprima node stack which has a `loc` property, allowing you to get the line and column where the error occurred.

```
try {
  safeEval('throw "some error"')
} catch (ex) {
  ex.trace //=> [...esprimaAstTrace]
  ex.trace[0].loc.start.line //=> 1
}
```

---
_Source: https://npm.io/package/notevil · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
