# Why is eval still in use when it is a big concern regarding security?

**URL:** <https://es.discourse.group/t/why-is-eval-still-in-use-when-it-is-a-big-concern-regarding-security/1602>\
**Category:** I have questions\
**Created:** [January 26, 2023, 10:00am UTC](https://es.discourse.group/t/why-is-eval-still-in-use-when-it-is-a-big-concern-regarding-security/1602 "2023-01-26T10:00:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![LorenaAnayaDiaz](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/lorenaanayadiaz/32/1628_2.png) [@LorenaAnayaDiaz](https://es.discourse.group/u/LorenaAnayaDiaz)\
**Post date:** [January 26, 2023, 10:00am UTC](https://es.discourse.group/t/why-is-eval-still-in-use-when-it-is-a-big-concern-regarding-security/1602/1 "2023-01-26T10:00:55Z")

</div>

MDN documentation says:

### [Never use eval()!](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/eval#never_use_eval!)

Using direct `eval()` suffers from multiple problems:

- `eval()` executes the code it's passed with the privileges of the caller. If you run `eval()` with a string that could be affected by a malicious party, you may end up running malicious code on the user's machine with the permissions of your webpage / extension. More importantly, allowing third-party code to access the scope in which `eval()` was invoked (if it's a direct eval) can lead to possible attacks that reads or changes local variables.
- `eval()` is slower than the alternatives, since it has to invoke the JavaScript interpreter, while many other constructs are optimized by modern JS engines.
- Modern JavaScript interpreters convert JavaScript to machine code. This means that any concept of variable naming gets obliterated. Thus, any use of `eval()` will force the browser to do long expensive variable name lookups to figure out where the variable exists in the machine code and set its value. Additionally, new things can be introduced to that variable through `eval()`, such as changing the type of that variable, forcing the browser to re-evaluate all of the generated machine code to compensate.
- Minifiers give up on any minification if the scope is transitively depended on by `eval()`, because otherwise `eval()` cannot read the correct variable at runtime.

---

<div class="post-metadata">

**Author:** ![kettanaito](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/kettanaito/32/1623_2.png) [@kettanaito](https://es.discourse.group/u/kettanaito)\
**Post date:** [January 26, 2023, 6:04pm UTC](https://es.discourse.group/t/why-is-eval-still-in-use-when-it-is-a-big-concern-regarding-security/1602/2 "2023-01-26T18:04:46Z")

</div>

MDN documentation is right in regard to suggesting a very sensible default. You are unlikely to ever need to use `eval()` when developing applications in JavaScript. However, `eval()` is handy when writing _tooling_ in JavaScript. Whenever you do so, you must acknowledge and account for the security concerns surrounding the usage of `eval()`.

---

<div class="post-metadata">

**Author:** ![7ombie](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/7ombie/32/1631_2.png) [@7ombie](https://es.discourse.group/u/7ombie)\
**Post date:** [February 2, 2023, 1:44pm UTC](https://es.discourse.group/t/why-is-eval-still-in-use-when-it-is-a-big-concern-regarding-security/1602/3 "2023-02-02T13:44:21Z")

</div>

If you make an app that executes JavaScript written by the app's user (a spreadsheet app, for example), you need something like `eval` to run the code.

Named-eval was specifically supported so we can evaluate multiple user-provided JS source strings, and know which is which in stack traces (as the strings have no URLs). I made a browser based REPL back in the day which would have been impossible without these features.

---

<div class="post-metadata">

**Author:** ![Rudxain](https://yyz2.discourse-cdn.com/free1/user_avatar/es.discourse.group/rudxain/32/2272_2.png) [@Rudxain](https://es.discourse.group/u/Rudxain)\
**Post date:** [October 4, 2023, 6:47pm UTC](https://es.discourse.group/t/why-is-eval-still-in-use-when-it-is-a-big-concern-regarding-security/1602/4 "2023-10-04T18:47:25Z")

</div>

I think `eval` should be deprecated in the same way as `with`. That is, to stop supporting it, recommend alts such as `Function()`, and don't outright delete it from `globalThis`
