# @reown/appkit-pay@1.7.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:14:54.000Z
- Files reviewed: 17
- Findings: 3 medium, 7 low severity findings
- Report: https://security.togoder.click/npm/@reown/appkit-pay
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @reown/appkit-pay@1.7.8 on Oct 4, 2026. An AI review of 17 source files produced 3 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic navigation

Finding ID: `NPS-4942E1CC71C3`

File: `dist/esm/src/controllers/PayController.js`

The openPayUrl method uses CoreHelperUtil.openHref(payUrl.url, target) to open a URL received from an external API. If the API is compromised or returns a malicious URL, this could lead to phishing or drive-by downloads. However, the URL is generated based on the exchange and user parameters, and the risk is mitigated if the API is trusted.

### [medium] External API dependency

Finding ID: `NPS-D10BAEBC5213`

File: `dist/esm/src/utils/ApiUtil.js:18`

The code fetches data from an external API controlled by a third party. If API_URL or the reown controllers package were compromised, responses could contain malicious payloads. No validation is performed on the response structure beyond checking json.error.

### [medium] Unvalidated recipient address in payment flows

Finding ID: `NPS-0A272A6CA4CE`

File: `dist/esm/src/utils/PaymentUtil.js:47`

processEvmNativePayment and processEvmErc20Payment send funds/ERC20 transfers to params.recipient without validating the recipient address format, checksum, or comparing against an allowlist. If params.recipient can be influenced by untrusted input (e.g. a dapp or redirect parameter), funds may be misdirected. This is a financial-safety concern rather than a confirmed malicious pattern.

### [low] Cryptocurrency wallet interaction

Finding ID: `NPS-97726A2EC8FF`

File: `dist/esm/src/controllers/PayController.js`

The controller handles cryptocurrency payments, interacting with wallet providers and processing EVM native and ERC20 payments. While this appears to be legitimate payment functionality, it involves sending funds to a recipient address. The recipient address and payment asset are configurable, which could theoretically be exploited if the configuration is tampered with, but no malicious intent is evident.

### [low] External network requests

Finding ID: `NPS-8E4227650304`

File: `dist/esm/src/controllers/PayController.js`

The code makes network requests to external APIs via getExchanges, getPayUrl, and getBuyStatus from ApiUtil.js. These are likely legitimate services for fetching exchange data and payment URLs, but the destinations are not visible in this file, so their safety cannot be fully verified.

### [low] Network request / data exfiltration

Finding ID: `NPS-F5646492323C`

File: `dist/esm/src/utils/ApiUtil.js:6`

The module sends JSON-RPC requests containing the application's projectId to an external API endpoint (API_URL). While this appears to be legitimate functionality for the reown/appkit library, the projectId is embedded in the URL query string and sent to an external server on every request, which could be considered data collection/exfiltration if the endpoint is not trusted.

### [low] Error handling / information disclosure

Finding ID: `NPS-BCD361F2FB2C`

File: `dist/esm/src/utils/ApiUtil.js:26`

Errors from the remote server are surfaced directly via JsonRpcError(json.error.message), which could leak internal details if not sanitized by callers.

### [low] Implicit network switching based on asset metadata

Finding ID: `NPS-104F7C0CF788`

File: `dist/esm/src/utils/PaymentUtil.js:20`

ensureCorrectNetwork automatically invokes ChainController.switchActiveNetwork based on an asset-supplied network id. If payment asset metadata is attacker-influenced, the wallet could be prompted to switch to an unintended network during payment operations.

### [low] Float parsing of payment amounts

Finding ID: `NPS-F277976B820F`

File: `dist/esm/src/utils/PaymentUtil.js:30`

processEvmNativePayment uses parseFloat on string amounts before converting to BigInt via parseUnits. Binary floating-point rounding can silently alter payment amounts, leading to incorrect transfer values.

### [low] Silent undefined propagation on ERC20 amount parse

Finding ID: `NPS-88B01B762FFE`

File: `dist/esm/src/utils/PaymentUtil.js:67`

processEvmErc20Payment only checks for undefined from parseUnits, but not for null/invalid results, and passes the derived amountBigInt directly into writeContract. Combined with number coercion of params.amount, unexpected values could reach the contract call.

## Files reviewed

- `dist/esm/src/controllers/PayController.js` (medium): The code appears to be a legitimate payment controller for a cryptocurrency wallet application, with no clear malicious patterns, but it involves external API calls and cryptocurrency transactions that carry inherent risks if the external services are compromised.
- `dist/esm/src/utils/ApiUtil.js` (medium): The file implements a JSON-RPC client that sends the application projectId and requests to an external API endpoint; no obfuscation, credential harvesting, shell execution, or wallet draining patterns are present, but outbound network communication to a third-party service is a mild concern.
- `dist/esm/src/utils/PaymentUtil.js` (medium): No malicious patterns (exfiltration, credential harvesting, obfuscation, process spawning, or install-time hooks) were detected; findings are limited to payment-flow validation and safety concerns.
- `dist/esm/exports/index.js` (safe): No malicious patterns detected; the file only re-exports modules from the package's own source tree.
- `dist/esm/exports/react.js` (safe): No malicious patterns detected; the file contains standard React hooks for payment integration without data exfiltration, credential harvesting, obfuscation, or suspicious system interactions.
- `dist/esm/src/client.js` (safe): No malicious patterns detected; the file is a thin wrapper exposing PayController methods.
- `dist/esm/src/controllers/index.js` (safe): No malicious patterns detected
- `dist/esm/src/types/assets.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/types/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/types/exchange.js` (safe): No malicious patterns detected
- `dist/esm/src/types/options.js` (safe): No malicious patterns detected
- `dist/esm/src/ui/w3m-pay-loading-view/index.js` (safe): No malicious patterns detected; the file is a legitimate LitElement UI component for a payment loading view within the Reown AppKit library.
- `dist/esm/src/ui/w3m-pay-loading-view/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/ui/w3m-pay-view/index.js` (safe): No malicious patterns detected; the file is a standard Lit-based payment UI component with no data exfiltration, obfuscation, or suspicious behavior.
- `dist/esm/src/ui/w3m-pay-view/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/AssetUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/ConstantsUtil.js` (safe): This file only defines a single constant URL for WalletConnect's public RPC endpoint with no executable, obfuscated, or exfiltrating code.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
