Togoder security

npm package security report

@lit/reactive-element@2.1.1 security report

No malicious code found.

No issues Version 2.1.1 Files reviewed 58 Size 173.1 KB Scanned

Summary

Togoder Security scanned the npm package @lit/reactive-element@2.1.1 on Oct 4, 2026. An AI review of 58 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
3
low

Findings 3

low

dynamic code execution

NPS-5620E992A388

The code uses CSSStyleSheet.replaceSync and adoptedStyleSheets to apply CSS styles, which is standard for the lit library's css tag. No eval, Function, or other dynamic code execution mechanisms are present.

node/css-tag.js
low

DOM manipulation

NPS-44B9F47D3E2B

The adoptStyles function creates <style> elements and appends them to the document or shadow root. This is intended behavior for applying styles and is confined to the page's DOM, not external systems.

node/css-tag.js
low

Known legitimate polyfill

NPS-7572ECE3913F

This is the official @webcomponents/polyfill-support package from Google/Lit. It installs a globalThis.reactiveElementPolyfillSupport function that integrates ReactiveElement with ShadyCSS/ShadyDOM. No network calls, no obfuscation, no eval, no filesystem access, no environment/credential access, and no process spawning. The UMD wrapper and 'use strict' are standard.

polyfill-support.js

Files reviewed

FileVerdictWhat the reviewer saw
css-tag.js safe This is the standard lit-html CSS tag implementation from Google's Lit library, containing no malicious patterns.
decorators.js safe No malicious patterns detected
decorators/base.js safe No malicious patterns detected; the file is a standard Lit decorator utility with no network, filesystem, process, or dynamic execution behavior.
decorators/custom-element.js safe No malicious patterns detected; the code is a standard Lit customElement decorator from Google with clear licensing and no obfuscation or risky behavior.
decorators/event-options.js safe No malicious patterns detected; the code is a legitimate event options decorator from Lit that assigns options to a function or method.
decorators/property.js safe This is the standard Lit library property decorator implementation with no malicious patterns, network activity, credential access, or dynamic code execution.
decorators/query-all.js safe No malicious patterns detected
decorators/query-assigned-elements.js safe No malicious patterns detected
decorators/query-assigned-nodes.js safe No malicious patterns detected
decorators/query-async.js safe No malicious patterns detected in this standard Lit reactive property decorator utility.
decorators/query.js safe No malicious patterns detected
decorators/state.js safe No malicious patterns detected; this is a benign Lit decorator definition from Google's lit library that simply re-exports a state property decorator.
development/css-tag.js safe No malicious patterns detected; this is a legitimate Lit CSS-tag utility module with no data exfiltration, credential harvesting, obfuscation, or process execution.
development/decorators.js safe Cleared by Jev triage; no further analysis needed
development/decorators/base.js safe Cleared by Jev triage; no further analysis needed
development/decorators/custom-element.js safe No malicious patterns detected
development/decorators/event-options.js safe Cleared by Jev triage; no further analysis needed
development/decorators/property.js safe No malicious patterns detected; the file is legitimate Lit library decorator code with only expected warnings and metadata handling.
development/decorators/query-all.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-assigned-elements.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-assigned-nodes.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-async.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query.js safe No malicious patterns detected; the file contains a legitimate Lit library property decorator with only development-mode warning logic and no network, filesystem, process, or dynamic code execution behavior.
development/decorators/state.js safe Cleared by Jev triage; no further analysis needed
development/polyfill-support.js safe No malicious patterns detected
Show 33 more files
FileVerdictWhat the reviewer saw
development/reactive-controller.js safe No malicious patterns detected
development/reactive-element.js safe No malicious patterns detected; this is the standard Lit ReactiveElement base class implementation with dev-mode warnings and no network, filesystem, process, or dynamic code execution behavior.
node/css-tag.js safe The code is a minified build of lit's css-tag module, which safely handles CSS styles without any malicious patterns such as data exfiltration, credential harvesting, or backdoor installation.
node/decorators.js safe No malicious patterns detected
node/decorators/base.js safe No malicious patterns detected; the file is a standard Lit decorator utility with no network, filesystem, process, or dynamic execution behavior.
node/decorators/custom-element.js safe No malicious patterns detected; the code is a standard Lit customElement decorator from Google with clear licensing and no obfuscation or risky behavior.
node/decorators/event-options.js safe No malicious patterns detected; the code is a legitimate event options decorator from Lit that assigns options to a function or method.
node/decorators/property.js safe This is the standard Lit library property decorator implementation with no malicious patterns, network activity, credential access, or dynamic code execution.
node/decorators/query-all.js safe No malicious patterns detected
node/decorators/query-assigned-elements.js safe No malicious patterns detected
node/decorators/query-assigned-nodes.js safe No malicious patterns detected
node/decorators/query-async.js safe No malicious patterns detected in this standard Lit reactive property decorator utility.
node/decorators/query.js safe No malicious patterns detected
node/decorators/state.js safe No malicious patterns detected; this is a benign Lit decorator definition from Google's lit library that simply re-exports a state property decorator.
node/development/css-tag.js safe No malicious patterns detected; the file is legitimate Lit CSS-tag implementation code with no network, filesystem, process, or credential-related activity.
node/development/decorators.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/base.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/custom-element.js safe The code is a standard Lit decorator for defining custom elements and contains no malicious patterns.
node/development/decorators/event-options.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/property.js safe No malicious patterns detected; the file is standard Lit decorator implementation code with no data exfiltration, credential harvesting, obfuscation, network activity, filesystem abuse, or shell execution.
node/development/decorators/query-all.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/query-assigned-elements.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/query-assigned-nodes.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/query-async.js safe Cleared by Jev triage; no further analysis needed
node/development/decorators/query.js safe No malicious patterns detected; the code is a standard Lit decorator implementation for DOM querying with no network, filesystem, process, or obfuscated behavior.
node/development/decorators/state.js safe Cleared by Jev triage; no further analysis needed
node/development/reactive-controller.js safe The file contains only a source map reference comment and no executable code or malicious patterns
node/development/reactive-element.js safe No malicious patterns detected; this is the legitimate Lit ReactiveElement base class with only standard dev-mode warnings and global state management.
node/reactive-controller.js safe The file contains only a source map reference comment and no executable code or malicious patterns
node/reactive-element.js safe No malicious patterns detected
polyfill-support.js safe This is a legitimate Web Components polyfill with no malicious patterns detected.
reactive-controller.js safe The file contains only a source map reference comment and no executable code or malicious patterns
reactive-element.js safe This is the standard Lit ReactiveElement implementation from Google with no malicious patterns detected.

Frequently asked questions

Is @lit/reactive-element safe to use?

Our AI source review of @lit/reactive-element@2.1.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @lit/reactive-element contain malware?

No malware was identified in @lit/reactive-element@2.1.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @lit/reactive-element checked?

Togoder Security downloaded the published npm package and had an AI model read its 58 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @lit/reactive-element together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @lit/reactive-element@2.1.1, cost nothing.

Related security reports