# @lit/reactive-element@2.1.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:06:42.000Z
- Files reviewed: 58
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@lit/reactive-element
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @lit/reactive-element@2.1.1 on Oct 4, 2026. An AI review of 58 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] dynamic code execution

Finding ID: `NPS-5620E992A388`

File: `node/css-tag.js`

The code uses CSSStyleSheet.replaceSync and adoptedStyleSheets to apply CSS styles, which is standard for the lit library's css tag. No eval, Function, or other dynamic code execution mechanisms are present.

### [low] DOM manipulation

Finding ID: `NPS-44B9F47D3E2B`

File: `node/css-tag.js`

The adoptStyles function creates <style> elements and appends them to the document or shadow root. This is intended behavior for applying styles and is confined to the page's DOM, not external systems.

### [low] Known legitimate polyfill

Finding ID: `NPS-7572ECE3913F`

File: `polyfill-support.js`

This is the official @webcomponents/polyfill-support package from Google/Lit. It installs a globalThis.reactiveElementPolyfillSupport function that integrates ReactiveElement with ShadyCSS/ShadyDOM. No network calls, no obfuscation, no eval, no filesystem access, no environment/credential access, and no process spawning. The UMD wrapper and 'use strict' are standard.

## Files reviewed

- `css-tag.js` (safe): This is the standard lit-html CSS tag implementation from Google's Lit library, containing no malicious patterns.
- `decorators.js` (safe): No malicious patterns detected
- `decorators/base.js` (safe): No malicious patterns detected; the file is a standard Lit decorator utility with no network, filesystem, process, or dynamic execution behavior.
- `decorators/custom-element.js` (safe): No malicious patterns detected; the code is a standard Lit customElement decorator from Google with clear licensing and no obfuscation or risky behavior.
- `decorators/event-options.js` (safe): No malicious patterns detected; the code is a legitimate event options decorator from Lit that assigns options to a function or method.
- `decorators/property.js` (safe): This is the standard Lit library property decorator implementation with no malicious patterns, network activity, credential access, or dynamic code execution.
- `decorators/query-all.js` (safe): No malicious patterns detected
- `decorators/query-assigned-elements.js` (safe): No malicious patterns detected
- `decorators/query-assigned-nodes.js` (safe): No malicious patterns detected
- `decorators/query-async.js` (safe): No malicious patterns detected in this standard Lit reactive property decorator utility.
- `decorators/query.js` (safe): No malicious patterns detected
- `decorators/state.js` (safe): No malicious patterns detected; this is a benign Lit decorator definition from Google's lit library that simply re-exports a state property decorator.
- `development/css-tag.js` (safe): No malicious patterns detected; this is a legitimate Lit CSS-tag utility module with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `development/decorators.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/base.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/custom-element.js` (safe): No malicious patterns detected
- `development/decorators/event-options.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/property.js` (safe): No malicious patterns detected; the file is legitimate Lit library decorator code with only expected warnings and metadata handling.
- `development/decorators/query-all.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/query-assigned-elements.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/query-assigned-nodes.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/query-async.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/decorators/query.js` (safe): No malicious patterns detected; the file contains a legitimate Lit library property decorator with only development-mode warning logic and no network, filesystem, process, or dynamic code execution behavior.
- `development/decorators/state.js` (safe): Cleared by Jev triage; no further analysis needed
- `development/polyfill-support.js` (safe): No malicious patterns detected
- `development/reactive-controller.js` (safe): No malicious patterns detected
- `development/reactive-element.js` (safe): No malicious patterns detected; this is the standard Lit ReactiveElement base class implementation with dev-mode warnings and no network, filesystem, process, or dynamic code execution behavior.
- `node/css-tag.js` (safe): The code is a minified build of lit's css-tag module, which safely handles CSS styles without any malicious patterns such as data exfiltration, credential harvesting, or backdoor installation.
- `node/decorators.js` (safe): No malicious patterns detected
- `node/decorators/base.js` (safe): No malicious patterns detected; the file is a standard Lit decorator utility with no network, filesystem, process, or dynamic execution behavior.
- `node/decorators/custom-element.js` (safe): No malicious patterns detected; the code is a standard Lit customElement decorator from Google with clear licensing and no obfuscation or risky behavior.
- `node/decorators/event-options.js` (safe): No malicious patterns detected; the code is a legitimate event options decorator from Lit that assigns options to a function or method.
- `node/decorators/property.js` (safe): This is the standard Lit library property decorator implementation with no malicious patterns, network activity, credential access, or dynamic code execution.
- `node/decorators/query-all.js` (safe): No malicious patterns detected
- `node/decorators/query-assigned-elements.js` (safe): No malicious patterns detected
- `node/decorators/query-assigned-nodes.js` (safe): No malicious patterns detected
- `node/decorators/query-async.js` (safe): No malicious patterns detected in this standard Lit reactive property decorator utility.
- `node/decorators/query.js` (safe): No malicious patterns detected
- `node/decorators/state.js` (safe): No malicious patterns detected; this is a benign Lit decorator definition from Google's lit library that simply re-exports a state property decorator.
- `node/development/css-tag.js` (safe): No malicious patterns detected; the file is legitimate Lit CSS-tag implementation code with no network, filesystem, process, or credential-related activity.
- `node/development/decorators.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/base.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/custom-element.js` (safe): The code is a standard Lit decorator for defining custom elements and contains no malicious patterns.
- `node/development/decorators/event-options.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/property.js` (safe): No malicious patterns detected; the file is standard Lit decorator implementation code with no data exfiltration, credential harvesting, obfuscation, network activity, filesystem abuse, or shell execution.
- `node/development/decorators/query-all.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/query-assigned-elements.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/query-assigned-nodes.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/query-async.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/decorators/query.js` (safe): No malicious patterns detected; the code is a standard Lit decorator implementation for DOM querying with no network, filesystem, process, or obfuscated behavior.
- `node/development/decorators/state.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/development/reactive-controller.js` (safe): The file contains only a source map reference comment and no executable code or malicious patterns
- `node/development/reactive-element.js` (safe): No malicious patterns detected; this is the legitimate Lit ReactiveElement base class with only standard dev-mode warnings and global state management.
- `node/reactive-controller.js` (safe): The file contains only a source map reference comment and no executable code or malicious patterns
- `node/reactive-element.js` (safe): No malicious patterns detected
- `polyfill-support.js` (safe): This is a legitimate Web Components polyfill with no malicious patterns detected.
- `reactive-controller.js` (safe): The file contains only a source map reference comment and no executable code or malicious patterns
- `reactive-element.js` (safe): This is the standard Lit ReactiveElement implementation from Google with no malicious patterns detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
