Summary
Togoder Security scanned the npm package @reown/appkit-scaffold-ui@1.7.8 on Oct 4, 2026. An AI review of 200 source files produced 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 6
Suspicious URL redirection
NPS-EE1DA11D68DF
The code constructs a native URL from wallet-provided desktop_link and opens it in a new tab using CoreHelperUtil.openHref(redirect, '_blank'). While this is a legitimate deep-linking mechanism for wallet connections, it could be abused if the desktop_link is not strictly validated, potentially leading to phishing or open redirect. However, within the context of the wallet connection flow, this is expected behavior.
Implicit State Manipulation
NPS-845304A72AD2
The debounced search handler updates shared controller state (SendController) based on user input and ENS resolution results, including setting receiver address, profile name, and image URL. This is normal application behavior but demonstrates interaction with shared state that could be exploited if the underlying controllers were compromised.
External Network Requests
NPS-4C69E27BD6A0
The code calls ConnectionController.getEnsAddress() and ConnectionController.getEnsAvatar() to resolve ENS names, which typically trigger network requests to external services. These are expected behaviors for address resolution but involve sending user input to external endpoints.
Clipboard Access
NPS-5D451E08997D
The component reads from the system clipboard using navigator.clipboard.readText() when the user clicks the Paste button. While this is a legitimate UI feature for pasting an address, clipboard access can be a privacy concern if the component or an upstream dependency were compromised, as clipboard contents may contain sensitive data.
Scroll/resize handlers binding new function instances
NPS-A8B8539AF8E1
addEventListener('scroll', this.handleConnectListScroll.bind(this)) is called multiple times (in firstUpdated and disconnectedCallback) with a fresh bound function each time, and the same happens with ResizeObserver. The removeEventListener in disconnectedCallback will not remove the listener added in firstUpdated since the bound references differ, resulting in a listener leak. This is a correctness/resource issue, not a malicious pattern.
Telegram/Safari/iOS auto-connect behavior
NPS-4F4EE2E377C3
In walletListTemplate(), the component calls ConnectionController.connectWalletConnect() automatically when CoreHelperUtil.isTelegram() and (CoreHelperUtil.isSafari() || CoreHelperUtil.isIos()) are true. While this is a deliberate UX behavior in a wallet-connection UI library (not exfiltration or a backdoor), auto-initiating a wallet connection without an explicit user gesture in these environments could be considered unexpected and warrants review for consent/UX and security implications.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/partials/w3m-input-address/index.js | medium | This is a legitimate Lit-based UI component for inputting a cryptocurrency address with ENS resolution and clipboard paste functionality; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution were detected, though clipboard and external network interactions warrant routine awareness. |
| dist/esm/exports/basic.js | safe | No malicious patterns detected |
| dist/esm/exports/core.js | safe | No malicious patterns detected |
| dist/esm/exports/email.js | safe | No malicious patterns detected |
| dist/esm/exports/embedded-wallet.js | safe | No malicious patterns detected |
| dist/esm/exports/index.js | safe | This file only re-exports modules from a relative source directory with no executable code, network calls, file system access, or other malicious patterns. |
| dist/esm/exports/onramp.js | safe | No malicious patterns detected; file only re-exports modules from the same package. |
| dist/esm/exports/receive.js | safe | Simple re-export statement with no malicious patterns detected |
| dist/esm/exports/send.js | safe | No malicious patterns detected |
| dist/esm/exports/socials.js | safe | No malicious patterns detected |
| dist/esm/exports/swaps.js | safe | No malicious patterns detected |
| dist/esm/exports/transactions.js | safe | The file is a simple ESM re-export with a source map comment and contains no malicious patterns. |
| dist/esm/exports/utils.js | safe | No malicious patterns detected; the file only re-exports utilities from internal modules with no executable code or external interactions. |
| dist/esm/exports/w3m-modal.js | safe | No malicious patterns detected |
| dist/esm/src/modal/w3m-account-button/index.js | safe | This is a standard LitElement web component from Reown AppKit for displaying wallet account buttons; no malicious patterns such as data exfiltration, credential harvesting, code obfuscation, or dynamic code execution were detected. |
| dist/esm/src/modal/w3m-button/index.js | safe | No malicious patterns detected; the code is a standard LitElement web component for wallet connection UI without data exfiltration, credential harvesting, or dynamic code execution. |
| dist/esm/src/modal/w3m-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/modal/w3m-connect-button/index.js | safe | No malicious patterns detected; this is a legitimate UI web component for a wallet connect button with no data exfiltration, credential harvesting, obfuscation, or dangerous code execution. |
| dist/esm/src/modal/w3m-modal/index.js | safe | No malicious patterns detected; the code is a standard Web3Modal/AppKit UI component using LitElement with expected network prefetching and theming behavior. |
| dist/esm/src/modal/w3m-modal/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/modal/w3m-network-button/index.js | safe | No malicious patterns detected; this is a standard Lit-based web component for network selection in a wallet UI library with no data exfiltration, obfuscation, credential harvesting, or suspicious system/network activity. |
| dist/esm/src/modal/w3m-network-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/modal/w3m-onramp-widget/index.js | safe | No malicious patterns detected; the code is a legitimate Lit-based UI component for an on-ramp widget with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process activity. |
| dist/esm/src/modal/w3m-onramp-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/modal/w3m-router/index.js | safe | No malicious patterns detected; the file is a standard LitElement router component for a wallet modal UI with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
Show 175 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/modal/w3m-router/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-account-activity-widget/index.js | safe | This is a standard Lit web component for displaying account activity with no malicious patterns, network requests, dynamic code execution, or credential harvesting. |
| dist/esm/src/partials/w3m-account-activity-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-account-auth-button/index.js | safe | This is a standard Lit web component for displaying account authentication buttons, with no malicious patterns detected. |
| dist/esm/src/partials/w3m-account-default-widget/index.js | safe | No malicious patterns detected; the code is a legitimate LitElement Web3 wallet account widget from Reown AppKit with standard UI and state management logic. |
| dist/esm/src/partials/w3m-account-default-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-account-nfts-widget/index.js | safe | No malicious patterns detected; the code is a standard LitElement UI component for a wallet NFT placeholder with no data exfiltration, credential harvesting, obfuscation, or network manipulation. |
| dist/esm/src/partials/w3m-account-nfts-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-account-tokens-widget/index.js | safe | No malicious patterns detected; this is a standard Lit web component for displaying wallet token balances without any suspicious network, filesystem, or code execution behavior. |
| dist/esm/src/partials/w3m-account-tokens-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-account-wallet-features-widget/index.js | safe | No malicious patterns detected |
| dist/esm/src/partials/w3m-account-wallet-features-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-activity-list/index.js | safe | No malicious patterns detected in this Web3Modal activity list UI component; it contains only standard UI rendering, state subscription, transaction pagination, and analytics tracking logic. |
| dist/esm/src/partials/w3m-activity-list/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-alertbar/index.js | safe | No malicious patterns detected; the file is a standard LitElement UI component for an alert bar with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/src/partials/w3m-alertbar/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-all-wallets-list-item/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for rendering wallet list items with lazy image loading via IntersectionObserver. |
| dist/esm/src/partials/w3m-all-wallets-list-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-all-wallets-list/index.js | safe | No malicious patterns detected; the code is a standard LitElement UI component for listing wallets with no data exfiltration, credential harvesting, or dynamic code execution. |
| dist/esm/src/partials/w3m-all-wallets-list/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-all-wallets-search/index.js | safe | No malicious patterns detected; the file is a benign Lit web component for wallet search within the Reown AppKit UI library. |
| dist/esm/src/partials/w3m-all-wallets-search/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-all-wallets-widget/index.js | safe | No malicious patterns detected; the code is a standard UI widget for a cryptocurrency wallet connection library with no data exfiltration, credential harvesting, obfuscation, or network calls. |
| dist/esm/src/partials/w3m-connect-announced-widget/index.js | safe | No malicious patterns detected; this is a standard Lit web component for displaying announced wallet connectors within the Reown AppKit UI library. |
| dist/esm/src/partials/w3m-connect-custom-widget/index.js | safe | No malicious patterns detected; this is a legitimate UI component from the Reown AppKit (formerly WalletConnect) library that only renders custom wallet options. |
| dist/esm/src/partials/w3m-connect-external-widget/index.js | safe | No malicious patterns detected |
| dist/esm/src/partials/w3m-connect-featured-widget/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for a wallet connect featured widget with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process activity. |
| dist/esm/src/partials/w3m-connect-injected-widget/index.js | safe | No malicious patterns detected; this is a legitimate LitElement web component for wallet connection UI from the Reown AppKit library. |
| dist/esm/src/partials/w3m-connect-multi-chain-widget/index.js | safe | No malicious patterns detected; this is a standard Lit-based web component for a multi-chain wallet connector UI with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/esm/src/partials/w3m-connect-recent-widget/index.js | safe | No malicious patterns detected; this is a benign Lit web component for displaying recent wallet connections in the Reown AppKit UI library. |
| dist/esm/src/partials/w3m-connect-recommended-widget/index.js | safe | This is a benign Lit web component from Reown AppKit for displaying recommended wallet connectors; no malicious patterns, data exfiltration, obfuscation, or dangerous execution were detected. |
| dist/esm/src/partials/w3m-connect-walletconnect-widget/index.js | safe | The code is a standard Lit web component for a WalletConnect UI widget within the Reown AppKit library, with no malicious patterns such as data exfiltration, obfuscation, dynamic execution, or process spawning. |
| dist/esm/src/partials/w3m-connecting-header/index.js | safe | The code is a standard LitElement web component for tabbed platform selection with no malicious patterns such as exfiltration, credential harvesting, dynamic execution, or suspicious network/file operations. |
| dist/esm/src/partials/w3m-connecting-wc-browser/index.js | safe | No malicious patterns detected; the code is a standard web component for wallet connection in the Reown AppKit library. |
| dist/esm/src/partials/w3m-connecting-wc-desktop/index.js | safe | The code appears to be a legitimate wallet connection component with no malicious patterns; it handles deep linking and event tracking as expected. |
| dist/esm/src/partials/w3m-connecting-wc-mobile/index.js | safe | No malicious patterns detected; the code is a legitimate Web3Modal mobile wallet connection UI component that opens wallet deeplinks and sends only standard analytics events. |
| dist/esm/src/partials/w3m-connecting-wc-qrcode/index.js | safe | No malicious patterns detected; the file is a UI component for displaying a WalletConnect QR code with no suspicious network, filesystem, or code-execution behavior. |
| dist/esm/src/partials/w3m-connecting-wc-qrcode/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-connecting-wc-unsupported/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for displaying a wallet-not-detected UI with benign analytics event sending. |
| dist/esm/src/partials/w3m-connecting-wc-web/index.js | safe | No malicious patterns detected in the analyzed file. |
| dist/esm/src/partials/w3m-connector-list/index.js | safe | No malicious patterns detected; this is a standard Lit-based UI connector list component for the Reown AppKit wallet library. |
| dist/esm/src/partials/w3m-connector-list/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-email-login-widget/index.js | safe | No malicious patterns detected in this Lit-based email login widget component. |
| dist/esm/src/partials/w3m-email-login-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-header/index.js | safe | No malicious patterns detected; the file is a legitimate LitElement-based header component for the Reown AppKit wallet UI with only standard state management, event tracking, and DOM animation. |
| dist/esm/src/partials/w3m-header/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-help-widget/index.js | safe | No malicious patterns detected; the file is a standard Lit-based web component renderer with no network, filesystem, process, obfuscation, or dynamic code execution behavior. |
| dist/esm/src/partials/w3m-input-address/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-input-token/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for a crypto wallet UI with no data exfiltration, obfuscation, or unsafe execution. |
| dist/esm/src/partials/w3m-input-token/styles.js | safe | This file contains only static CSS styling for a Lit web component with no executable logic, network calls, or malicious patterns. |
| dist/esm/src/partials/w3m-legal-checkbox/index.js | safe | The code is a legitimate LitElement component for displaying a legal checkbox with terms and privacy links, with no malicious patterns detected. |
| dist/esm/src/partials/w3m-legal-checkbox/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-legal-footer/index.js | safe | This LitElement web component renders a legal footer with configurable Terms of Service and Privacy Policy URLs, contains no network calls, file system access, code execution, credential harvesting, or other malicious patterns. |
| dist/esm/src/partials/w3m-legal-footer/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-mobile-download-links/index.js | safe | This is a benign Lit-based UI component for displaying mobile download links; no malicious patterns, obfuscation, exfiltration, or dangerous execution were detected. |
| dist/esm/src/partials/w3m-mobile-download-links/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-onramp-activity-item/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for displaying on-ramp activity items with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network/filesystem/process operations. |
| dist/esm/src/partials/w3m-onramp-activity-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-onramp-input/index.js | safe | No malicious patterns detected; the code is a standard LitElement web component for an on-ramp input UI with no data exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/src/partials/w3m-onramp-input/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-onramp-provider-item/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for rendering an on-ramp provider item with no network exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| dist/esm/src/partials/w3m-onramp-provider-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-onramp-providers-footer/index.js | safe | The code is a benign Lit web component for a wallet UI footer with no malicious patterns detected. |
| dist/esm/src/partials/w3m-onramp-providers-footer/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-siwx-sign-message-thumbnails/index.js | safe | No malicious patterns detected in this LitElement web component that only renders wallet and dapp thumbnail images with CSS animations. |
| dist/esm/src/partials/w3m-siwx-sign-message-thumbnails/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-snackbar/index.js | safe | This is a standard LitElement web component for displaying snackbar notifications with no malicious patterns detected. |
| dist/esm/src/partials/w3m-snackbar/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-social-login-list/index.js | safe | No malicious patterns detected in the social login list component; it uses standard LitElement patterns and package-internal imports for UI and authentication logic. |
| dist/esm/src/partials/w3m-social-login-list/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-social-login-widget/index.js | safe | This is a legitimate LitElement-based social login widget from the Reown AppKit library with no malicious patterns, external data exfiltration, dynamic code execution, or suspicious behaviors. |
| dist/esm/src/partials/w3m-social-login-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-swap-details/index.js | safe | No malicious patterns detected; this is a standard LitElement UI component for displaying swap details without any data exfiltration, code execution, or filesystem/network abuse. |
| dist/esm/src/partials/w3m-swap-details/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-swap-input-skeleton/index.js | safe | No malicious patterns detected; this is a standard LitElement skeleton UI component with no network, filesystem, or dynamic code execution behavior. |
| dist/esm/src/partials/w3m-swap-input-skeleton/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-swap-input/index.js | safe | No malicious patterns detected; the code is a standard LitElement-based UI component for a cryptocurrency swap input with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/src/partials/w3m-swap-input/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-tooltip-trigger/index.js | safe | No malicious patterns detected |
| dist/esm/src/partials/w3m-tooltip-trigger/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-tooltip/index.js | safe | This is a standard LitElement web component for a tooltip in the Reown AppKit UI library; no malicious patterns, network exfiltration, credential harvesting, obfuscation, or install-time execution were detected. |
| dist/esm/src/partials/w3m-tooltip/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-wallet-guide/index.js | safe | This is a standard Lit web component for a wallet guide UI with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| dist/esm/src/partials/w3m-wallet-guide/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/partials/w3m-wallet-login-list/index.js | safe | No malicious patterns detected; the file is a standard Lit web component rendering wallet login UI elements. |
| dist/esm/src/partials/w3m-wallet-send-details/index.js | safe | No malicious patterns detected |
| dist/esm/src/partials/w3m-wallet-send-details/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/ConnectorUtil.js | safe | The code is a utility module for managing wallet connector display logic and contains no malicious patterns, network exfiltration, dynamic code execution, or filesystem/process manipulation. |
| dist/esm/src/utils/ConstantsUtil.js | safe | No malicious patterns detected |
| dist/esm/src/utils/HelpersUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/WalletUtil.js | safe | The file contains only legitimate wallet filtering and sorting utility functions with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning. |
| dist/esm/src/utils/w3m-connecting-widget/index.js | safe | No malicious patterns detected; the code is a standard WalletConnect UI component with no data exfiltration, code execution, credential harvesting, or suspicious network activity. |
| dist/esm/src/utils/w3m-connecting-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/w3m-email-otp-widget/index.js | safe | This is a legitimate LitElement-based email OTP widget from the Reown AppKit UI library with no malicious patterns, no external data exfiltration, no credential harvesting, and no dynamic code execution. |
| dist/esm/src/utils/w3m-email-otp-widget/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-account-settings-view/index.js | safe | This is a legitimate LitElement UI component for wallet account settings with no malicious patterns, external data exfiltration, or suspicious code execution detected. |
| dist/esm/src/views/w3m-account-view/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for an account view using Reown AppKit controllers and UI partials. |
| dist/esm/src/views/w3m-all-wallets-view/index.js | safe | This is a standard LitElement UI component for a wallet selection view, with no malicious patterns, external data transmission, or dangerous code execution detected. |
| dist/esm/src/views/w3m-approve-transaction-view/index.js | safe | No malicious patterns detected |
| dist/esm/src/views/w3m-approve-transaction-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-buy-in-progress-view/index.js | safe | This is a legitimate Lit-based UI component for the Reown AppKit (formerly WalletConnect) on-ramp flow, with no malicious patterns, obfuscation, credential harvesting, or suspicious behavior detected. |
| dist/esm/src/views/w3m-buy-in-progress-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-choose-account-name-view/index.js | safe | No malicious patterns detected; the file is a standard LitElement UI component from the Reown AppKit library that only handles user interaction and navigation. |
| dist/esm/src/views/w3m-choose-account-name-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connect-socials-view/index.js | safe | This is a standard Lit web component for a UI view with no malicious patterns; it only reads configuration state and renders a social login list with legal checkbox handling. |
| dist/esm/src/views/w3m-connect-socials-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connect-view/index.js | safe | The file contains no malicious patterns (no exfiltration, credential harvesting, obfuscation, dynamic code execution, or shell/process spawning); it is a standard Lit-based wallet connect view with at most minor code-quality/UX concerns. |
| dist/esm/src/views/w3m-connect-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connect-wallets-view/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for a crypto wallet connection UI with only delegated UI logic and no network, filesystem, process, or credential access. |
| dist/esm/src/views/w3m-connect-wallets-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connecting-external-view/index.js | safe | No malicious patterns detected; the file is a legitimate UI component from the Reown AppKit library handling wallet connection and event tracking. |
| dist/esm/src/views/w3m-connecting-farcaster-view/index.js | safe | No malicious patterns detected; the code is a standard LitElement UI component for Farcaster wallet connection without any exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/src/views/w3m-connecting-farcaster-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connecting-multi-chain-view/index.js | safe | Legitimate UI component for a multi-chain wallet connector with no malicious patterns detected. |
| dist/esm/src/views/w3m-connecting-multi-chain-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connecting-social-view/index.js | safe | No malicious patterns detected; the file is a legitimate Reown AppKit UI component handling social login via postMessage with origin validation against a trusted origin. |
| dist/esm/src/views/w3m-connecting-social-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-connecting-wc-basic-view/index.js | safe | This is a standard Lit web component for a wallet connection UI with no malicious patterns, network exfiltration, dynamic code execution, or filesystem/process access. |
| dist/esm/src/views/w3m-connecting-wc-view/index.js | safe | This is a legitimate WalletConnect UI component from the Reown AppKit library with no malicious patterns detected. |
| dist/esm/src/views/w3m-downloads-view/index.js | safe | No malicious patterns detected; the file is a benign Lit web component that renders wallet download links and opens them in a new tab via an imported utility. |
| dist/esm/src/views/w3m-email-login-view/index.js | safe | No malicious patterns detected |
| dist/esm/src/views/w3m-email-verify-device-view/index.js | safe | No malicious patterns detected; this is a standard Lit web component for email device verification within the Reown AppKit wallet library. |
| dist/esm/src/views/w3m-email-verify-device-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-email-verify-otp-view/index.js | safe | No malicious patterns detected |
| dist/esm/src/views/w3m-get-wallet-view/index.js | safe | No malicious patterns detected; the code is a standard LitElement UI component from Reown AppKit that renders wallet recommendations and opens external links via CoreHelperUtil.openHref. |
| dist/esm/src/views/w3m-network-switch-view/index.js | safe | This is a legitimate Lit web component for network switching in the Reown AppKit UI library, with no malicious patterns detected. |
| dist/esm/src/views/w3m-network-switch-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-networks-view/index.js | safe | No malicious patterns detected; the file is a legitimate Lit web component for a wallet network selection UI. |
| dist/esm/src/views/w3m-networks-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-onramp-activity-view/index.js | safe | No malicious patterns detected; this is a legitimate LitElement component for displaying onramp transaction activity via standard Reown AppKit controllers. |
| dist/esm/src/views/w3m-onramp-activity-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-onramp-fiat-select-view/index.js | safe | No malicious patterns detected; this is a benign Lit-based UI component for selecting on-ramp fiat currencies. |
| dist/esm/src/views/w3m-onramp-fiat-select-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-onramp-providers-view/index.js | safe | No malicious patterns detected; the code is a legitimate UI component for on-ramp providers using standard Web3 modal patterns without exfiltration, code execution, or credential harvesting. |
| dist/esm/src/views/w3m-onramp-tokens-select-view/index.js | safe | No malicious patterns detected; this is a legitimate UI component for selecting onramp tokens using Lit and internal AppKit controllers. |
| dist/esm/src/views/w3m-onramp-tokens-select-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-profile-view/index.js | safe | No malicious patterns detected; the code is a standard Lit-based UI component for a wallet profile view that interacts only with application controllers and UI utilities. |
| dist/esm/src/views/w3m-profile-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-register-account-name-success-view/index.js | safe | No malicious patterns detected; the file is a standard LitElement UI component with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/esm/src/views/w3m-register-account-name-success-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-register-account-name-view/index.js | safe | This is a benign Lit web component for registering ENS names in the Reown AppKit wallet UI, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution. |
| dist/esm/src/views/w3m-register-account-name-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-siwx-sign-message-view/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for a Sign-In With X (SIWX) message signing view with no exfiltration, obfuscation, or shell execution. |
| dist/esm/src/views/w3m-swap-preview-view/index.js | safe | No malicious patterns detected; the file is a legitimate LitElement UI component for a cryptocurrency swap preview with no exfiltration, credential harvesting, code execution, or filesystem/process manipulation. |
| dist/esm/src/views/w3m-swap-preview-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-swap-select-token-view/index.js | safe | This is a standard Lit-based UI component from the Reown AppKit library for selecting swap tokens; it contains no malicious patterns, obfuscation, credential harvesting, network exfiltration, or dangerous code execution. |
| dist/esm/src/views/w3m-swap-select-token-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-swap-view/index.js | safe | No malicious patterns detected; the code is a legitimate swap view component from the Reown AppKit library. |
| dist/esm/src/views/w3m-swap-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-switch-active-chain-view/index.js | safe | This file is a legitimate UI component from the Reown AppKit library with no malicious patterns, external data exfiltration, dynamic code execution, or suspicious network/file system activity. |
| dist/esm/src/views/w3m-switch-active-chain-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-switch-address-view/index.js | safe | This is a legitimate Lit web component for switching wallet addresses from the Reown AppKit library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution were detected. |
| dist/esm/src/views/w3m-switch-address-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-transactions-view/index.js | safe | No malicious patterns detected |
| dist/esm/src/views/w3m-transactions-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-unsupported-chain-view/index.js | safe | No malicious patterns detected; the code is a standard UI component from the Reown AppKit library with no exfiltration, credential harvesting, dynamic execution, or other security concerns. |
| dist/esm/src/views/w3m-unsupported-chain-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-update-email-primary-otp-view/index.js | safe | This is a standard UI component for OTP email verification from the Reown AppKit library with no malicious patterns, external data exfiltration, obfuscation, or suspicious behavior detected. |
| dist/esm/src/views/w3m-update-email-secondary-otp-view/index.js | safe | No malicious patterns detected; the code is a standard Lit-based UI component for OTP email verification within the Reown AppKit wallet library. |
| dist/esm/src/views/w3m-update-email-wallet-view/index.js | safe | The code is a UI component for updating an email address in a wallet application, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution detected. |
| dist/esm/src/views/w3m-update-email-wallet-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-upgrade-wallet-view/index.js | safe | No malicious patterns detected; the file is a standard LitElement UI component rendering a static link to a dashboard. |
| dist/esm/src/views/w3m-wallet-compatible-networks-view/index.js | safe | No malicious patterns detected; the file is a legitimate Lit web component for displaying compatible networks in the Reown AppKit wallet UI. |
| dist/esm/src/views/w3m-wallet-compatible-networks-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-wallet-receive-view/index.js | safe | No malicious patterns detected |
| dist/esm/src/views/w3m-wallet-receive-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-wallet-send-preview-view/index.js | safe | No malicious patterns detected; the code is a normal Lit-based UI component for a wallet send preview with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| dist/esm/src/views/w3m-wallet-send-preview-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-wallet-send-select-token-view/index.js | safe | This is a standard Lit UI component for selecting tokens in a wallet send flow; it contains no network calls, file system access, process spawning, obfuscation, or credential harvesting patterns. |
| dist/esm/src/views/w3m-wallet-send-select-token-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-wallet-send-view/index.js | safe | No malicious patterns detected; this is a benign Lit UI component for a wallet send view that relies on internal appkit-controllers and performs no external data exfiltration, code execution, or credential access. |
| dist/esm/src/views/w3m-wallet-send-view/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/views/w3m-what-is-a-buy-view/index.js | safe | No malicious patterns detected |
| dist/esm/src/views/w3m-what-is-a-network-view/index.js | safe | This is a benign LitElement UI component that renders informational content about blockchain networks and opens a fixed external documentation URL on button click; no malicious patterns detected. |
| dist/esm/src/views/w3m-what-is-a-wallet-view/index.js | safe | No malicious patterns detected; the file is a standard Lit web component view with no data exfiltration, credential harvesting, obfuscation, or process execution. |
Scanned versions of @reown/appkit-scaffold-ui
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.7.8 | Needs review | 200 | Oct 4, 2026 |
Frequently asked questions
Is @reown/appkit-scaffold-ui safe to use?
No confirmed malware was found in @reown/appkit-scaffold-ui@1.7.8, but the review flagged 6 low severity findings for risky patterns worth checking before you rely on it.
Does @reown/appkit-scaffold-ui contain malware?
No malware was identified in @reown/appkit-scaffold-ui@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @reown/appkit-scaffold-ui checked?
Togoder Security downloaded the published npm package and had an AI model read its 200 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @reown/appkit-scaffold-ui together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-scaffold-ui@1.7.8, cost nothing.