Togoder security

npm package security report

@reown/appkit-scaffold-ui@1.7.8 security report

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 200 Size 609.8 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit-scaffold-ui@1.7.8 on Oct 4, 2026. An AI review of 200 source files produced 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
6
low

Findings 6

low

Suspicious URL redirection

NPS-EE1DA11D68DF

The code constructs a native URL from wallet-provided desktop_link and opens it in a new tab using CoreHelperUtil.openHref(redirect, '_blank'). While this is a legitimate deep-linking mechanism for wallet connections, it could be abused if the desktop_link is not strictly validated, potentially leading to phishing or open redirect. However, within the context of the wallet connection flow, this is expected behavior.

dist/esm/src/partials/w3m-connecting-wc-desktop/index.js:30
low

Implicit State Manipulation

NPS-845304A72AD2

The debounced search handler updates shared controller state (SendController) based on user input and ENS resolution results, including setting receiver address, profile name, and image URL. This is normal application behavior but demonstrates interaction with shared state that could be exploited if the underlying controllers were compromised.

dist/esm/src/partials/w3m-input-address/index.js:36
low

External Network Requests

NPS-4C69E27BD6A0

The code calls ConnectionController.getEnsAddress() and ConnectionController.getEnsAvatar() to resolve ENS names, which typically trigger network requests to external services. These are expected behaviors for address resolution but involve sending user input to external endpoints.

dist/esm/src/partials/w3m-input-address/index.js:38
low

Clipboard Access

NPS-5D451E08997D

The component reads from the system clipboard using navigator.clipboard.readText() when the user clicks the Paste button. While this is a legitimate UI feature for pasting an address, clipboard access can be a privacy concern if the component or an upstream dependency were compromised, as clipboard contents may contain sensitive data.

dist/esm/src/partials/w3m-input-address/index.js:155
low

Scroll/resize handlers binding new function instances

NPS-A8B8539AF8E1

addEventListener('scroll', this.handleConnectListScroll.bind(this)) is called multiple times (in firstUpdated and disconnectedCallback) with a fresh bound function each time, and the same happens with ResizeObserver. The removeEventListener in disconnectedCallback will not remove the listener added in firstUpdated since the bound references differ, resulting in a listener leak. This is a correctness/resource issue, not a malicious pattern.

dist/esm/src/views/w3m-connect-view/index.js:65
low

Telegram/Safari/iOS auto-connect behavior

NPS-4F4EE2E377C3

In walletListTemplate(), the component calls ConnectionController.connectWalletConnect() automatically when CoreHelperUtil.isTelegram() and (CoreHelperUtil.isSafari() || CoreHelperUtil.isIos()) are true. While this is a deliberate UX behavior in a wallet-connection UI library (not exfiltration or a backdoor), auto-initiating a wallet connection without an explicit user gesture in these environments could be considered unexpected and warrants review for consent/UX and security implications.

dist/esm/src/views/w3m-connect-view/index.js:265

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/src/partials/w3m-input-address/index.js medium This is a legitimate Lit-based UI component for inputting a cryptocurrency address with ENS resolution and clipboard paste functionality; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process execution were detected, though clipboard and external network interactions warrant routine awareness.
dist/esm/exports/basic.js safe No malicious patterns detected
dist/esm/exports/core.js safe No malicious patterns detected
dist/esm/exports/email.js safe No malicious patterns detected
dist/esm/exports/embedded-wallet.js safe No malicious patterns detected
dist/esm/exports/index.js safe This file only re-exports modules from a relative source directory with no executable code, network calls, file system access, or other malicious patterns.
dist/esm/exports/onramp.js safe No malicious patterns detected; file only re-exports modules from the same package.
dist/esm/exports/receive.js safe Simple re-export statement with no malicious patterns detected
dist/esm/exports/send.js safe No malicious patterns detected
dist/esm/exports/socials.js safe No malicious patterns detected
dist/esm/exports/swaps.js safe No malicious patterns detected
dist/esm/exports/transactions.js safe The file is a simple ESM re-export with a source map comment and contains no malicious patterns.
dist/esm/exports/utils.js safe No malicious patterns detected; the file only re-exports utilities from internal modules with no executable code or external interactions.
dist/esm/exports/w3m-modal.js safe No malicious patterns detected
dist/esm/src/modal/w3m-account-button/index.js safe This is a standard LitElement web component from Reown AppKit for displaying wallet account buttons; no malicious patterns such as data exfiltration, credential harvesting, code obfuscation, or dynamic code execution were detected.
dist/esm/src/modal/w3m-button/index.js safe No malicious patterns detected; the code is a standard LitElement web component for wallet connection UI without data exfiltration, credential harvesting, or dynamic code execution.
dist/esm/src/modal/w3m-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/modal/w3m-connect-button/index.js safe No malicious patterns detected; this is a legitimate UI web component for a wallet connect button with no data exfiltration, credential harvesting, obfuscation, or dangerous code execution.
dist/esm/src/modal/w3m-modal/index.js safe No malicious patterns detected; the code is a standard Web3Modal/AppKit UI component using LitElement with expected network prefetching and theming behavior.
dist/esm/src/modal/w3m-modal/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/modal/w3m-network-button/index.js safe No malicious patterns detected; this is a standard Lit-based web component for network selection in a wallet UI library with no data exfiltration, obfuscation, credential harvesting, or suspicious system/network activity.
dist/esm/src/modal/w3m-network-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/modal/w3m-onramp-widget/index.js safe No malicious patterns detected; the code is a legitimate Lit-based UI component for an on-ramp widget with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process activity.
dist/esm/src/modal/w3m-onramp-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/modal/w3m-router/index.js safe No malicious patterns detected; the file is a standard LitElement router component for a wallet modal UI with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
Show 175 more files
FileVerdictWhat the reviewer saw
dist/esm/src/modal/w3m-router/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-account-activity-widget/index.js safe This is a standard Lit web component for displaying account activity with no malicious patterns, network requests, dynamic code execution, or credential harvesting.
dist/esm/src/partials/w3m-account-activity-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-account-auth-button/index.js safe This is a standard Lit web component for displaying account authentication buttons, with no malicious patterns detected.
dist/esm/src/partials/w3m-account-default-widget/index.js safe No malicious patterns detected; the code is a legitimate LitElement Web3 wallet account widget from Reown AppKit with standard UI and state management logic.
dist/esm/src/partials/w3m-account-default-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-account-nfts-widget/index.js safe No malicious patterns detected; the code is a standard LitElement UI component for a wallet NFT placeholder with no data exfiltration, credential harvesting, obfuscation, or network manipulation.
dist/esm/src/partials/w3m-account-nfts-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-account-tokens-widget/index.js safe No malicious patterns detected; this is a standard Lit web component for displaying wallet token balances without any suspicious network, filesystem, or code execution behavior.
dist/esm/src/partials/w3m-account-tokens-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-account-wallet-features-widget/index.js safe No malicious patterns detected
dist/esm/src/partials/w3m-account-wallet-features-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-activity-list/index.js safe No malicious patterns detected in this Web3Modal activity list UI component; it contains only standard UI rendering, state subscription, transaction pagination, and analytics tracking logic.
dist/esm/src/partials/w3m-activity-list/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-alertbar/index.js safe No malicious patterns detected; the file is a standard LitElement UI component for an alert bar with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/src/partials/w3m-alertbar/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-all-wallets-list-item/index.js safe No malicious patterns detected; the code is a standard Lit web component for rendering wallet list items with lazy image loading via IntersectionObserver.
dist/esm/src/partials/w3m-all-wallets-list-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-all-wallets-list/index.js safe No malicious patterns detected; the code is a standard LitElement UI component for listing wallets with no data exfiltration, credential harvesting, or dynamic code execution.
dist/esm/src/partials/w3m-all-wallets-list/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-all-wallets-search/index.js safe No malicious patterns detected; the file is a benign Lit web component for wallet search within the Reown AppKit UI library.
dist/esm/src/partials/w3m-all-wallets-search/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-all-wallets-widget/index.js safe No malicious patterns detected; the code is a standard UI widget for a cryptocurrency wallet connection library with no data exfiltration, credential harvesting, obfuscation, or network calls.
dist/esm/src/partials/w3m-connect-announced-widget/index.js safe No malicious patterns detected; this is a standard Lit web component for displaying announced wallet connectors within the Reown AppKit UI library.
dist/esm/src/partials/w3m-connect-custom-widget/index.js safe No malicious patterns detected; this is a legitimate UI component from the Reown AppKit (formerly WalletConnect) library that only renders custom wallet options.
dist/esm/src/partials/w3m-connect-external-widget/index.js safe No malicious patterns detected
dist/esm/src/partials/w3m-connect-featured-widget/index.js safe No malicious patterns detected; the file is a standard Lit web component for a wallet connect featured widget with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process activity.
dist/esm/src/partials/w3m-connect-injected-widget/index.js safe No malicious patterns detected; this is a legitimate LitElement web component for wallet connection UI from the Reown AppKit library.
dist/esm/src/partials/w3m-connect-multi-chain-widget/index.js safe No malicious patterns detected; this is a standard Lit-based web component for a multi-chain wallet connector UI with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/esm/src/partials/w3m-connect-recent-widget/index.js safe No malicious patterns detected; this is a benign Lit web component for displaying recent wallet connections in the Reown AppKit UI library.
dist/esm/src/partials/w3m-connect-recommended-widget/index.js safe This is a benign Lit web component from Reown AppKit for displaying recommended wallet connectors; no malicious patterns, data exfiltration, obfuscation, or dangerous execution were detected.
dist/esm/src/partials/w3m-connect-walletconnect-widget/index.js safe The code is a standard Lit web component for a WalletConnect UI widget within the Reown AppKit library, with no malicious patterns such as data exfiltration, obfuscation, dynamic execution, or process spawning.
dist/esm/src/partials/w3m-connecting-header/index.js safe The code is a standard LitElement web component for tabbed platform selection with no malicious patterns such as exfiltration, credential harvesting, dynamic execution, or suspicious network/file operations.
dist/esm/src/partials/w3m-connecting-wc-browser/index.js safe No malicious patterns detected; the code is a standard web component for wallet connection in the Reown AppKit library.
dist/esm/src/partials/w3m-connecting-wc-desktop/index.js safe The code appears to be a legitimate wallet connection component with no malicious patterns; it handles deep linking and event tracking as expected.
dist/esm/src/partials/w3m-connecting-wc-mobile/index.js safe No malicious patterns detected; the code is a legitimate Web3Modal mobile wallet connection UI component that opens wallet deeplinks and sends only standard analytics events.
dist/esm/src/partials/w3m-connecting-wc-qrcode/index.js safe No malicious patterns detected; the file is a UI component for displaying a WalletConnect QR code with no suspicious network, filesystem, or code-execution behavior.
dist/esm/src/partials/w3m-connecting-wc-qrcode/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-connecting-wc-unsupported/index.js safe No malicious patterns detected; the code is a standard Lit web component for displaying a wallet-not-detected UI with benign analytics event sending.
dist/esm/src/partials/w3m-connecting-wc-web/index.js safe No malicious patterns detected in the analyzed file.
dist/esm/src/partials/w3m-connector-list/index.js safe No malicious patterns detected; this is a standard Lit-based UI connector list component for the Reown AppKit wallet library.
dist/esm/src/partials/w3m-connector-list/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-email-login-widget/index.js safe No malicious patterns detected in this Lit-based email login widget component.
dist/esm/src/partials/w3m-email-login-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-header/index.js safe No malicious patterns detected; the file is a legitimate LitElement-based header component for the Reown AppKit wallet UI with only standard state management, event tracking, and DOM animation.
dist/esm/src/partials/w3m-header/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-help-widget/index.js safe No malicious patterns detected; the file is a standard Lit-based web component renderer with no network, filesystem, process, obfuscation, or dynamic code execution behavior.
dist/esm/src/partials/w3m-input-address/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-input-token/index.js safe No malicious patterns detected; the file is a standard Lit web component for a crypto wallet UI with no data exfiltration, obfuscation, or unsafe execution.
dist/esm/src/partials/w3m-input-token/styles.js safe This file contains only static CSS styling for a Lit web component with no executable logic, network calls, or malicious patterns.
dist/esm/src/partials/w3m-legal-checkbox/index.js safe The code is a legitimate LitElement component for displaying a legal checkbox with terms and privacy links, with no malicious patterns detected.
dist/esm/src/partials/w3m-legal-checkbox/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-legal-footer/index.js safe This LitElement web component renders a legal footer with configurable Terms of Service and Privacy Policy URLs, contains no network calls, file system access, code execution, credential harvesting, or other malicious patterns.
dist/esm/src/partials/w3m-legal-footer/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-mobile-download-links/index.js safe This is a benign Lit-based UI component for displaying mobile download links; no malicious patterns, obfuscation, exfiltration, or dangerous execution were detected.
dist/esm/src/partials/w3m-mobile-download-links/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-onramp-activity-item/index.js safe No malicious patterns detected; the file is a standard Lit web component for displaying on-ramp activity items with no data exfiltration, credential harvesting, dynamic code execution, or suspicious network/filesystem/process operations.
dist/esm/src/partials/w3m-onramp-activity-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-onramp-input/index.js safe No malicious patterns detected; the code is a standard LitElement web component for an on-ramp input UI with no data exfiltration, obfuscation, or suspicious behavior.
dist/esm/src/partials/w3m-onramp-input/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-onramp-provider-item/index.js safe No malicious patterns detected; the file is a standard Lit web component for rendering an on-ramp provider item with no network exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
dist/esm/src/partials/w3m-onramp-provider-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-onramp-providers-footer/index.js safe The code is a benign Lit web component for a wallet UI footer with no malicious patterns detected.
dist/esm/src/partials/w3m-onramp-providers-footer/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-siwx-sign-message-thumbnails/index.js safe No malicious patterns detected in this LitElement web component that only renders wallet and dapp thumbnail images with CSS animations.
dist/esm/src/partials/w3m-siwx-sign-message-thumbnails/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-snackbar/index.js safe This is a standard LitElement web component for displaying snackbar notifications with no malicious patterns detected.
dist/esm/src/partials/w3m-snackbar/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-social-login-list/index.js safe No malicious patterns detected in the social login list component; it uses standard LitElement patterns and package-internal imports for UI and authentication logic.
dist/esm/src/partials/w3m-social-login-list/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-social-login-widget/index.js safe This is a legitimate LitElement-based social login widget from the Reown AppKit library with no malicious patterns, external data exfiltration, dynamic code execution, or suspicious behaviors.
dist/esm/src/partials/w3m-social-login-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-swap-details/index.js safe No malicious patterns detected; this is a standard LitElement UI component for displaying swap details without any data exfiltration, code execution, or filesystem/network abuse.
dist/esm/src/partials/w3m-swap-details/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-swap-input-skeleton/index.js safe No malicious patterns detected; this is a standard LitElement skeleton UI component with no network, filesystem, or dynamic code execution behavior.
dist/esm/src/partials/w3m-swap-input-skeleton/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-swap-input/index.js safe No malicious patterns detected; the code is a standard LitElement-based UI component for a cryptocurrency swap input with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/src/partials/w3m-swap-input/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-tooltip-trigger/index.js safe No malicious patterns detected
dist/esm/src/partials/w3m-tooltip-trigger/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-tooltip/index.js safe This is a standard LitElement web component for a tooltip in the Reown AppKit UI library; no malicious patterns, network exfiltration, credential harvesting, obfuscation, or install-time execution were detected.
dist/esm/src/partials/w3m-tooltip/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-wallet-guide/index.js safe This is a standard Lit web component for a wallet guide UI with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
dist/esm/src/partials/w3m-wallet-guide/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/partials/w3m-wallet-login-list/index.js safe No malicious patterns detected; the file is a standard Lit web component rendering wallet login UI elements.
dist/esm/src/partials/w3m-wallet-send-details/index.js safe No malicious patterns detected
dist/esm/src/partials/w3m-wallet-send-details/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/ConnectorUtil.js safe The code is a utility module for managing wallet connector display logic and contains no malicious patterns, network exfiltration, dynamic code execution, or filesystem/process manipulation.
dist/esm/src/utils/ConstantsUtil.js safe No malicious patterns detected
dist/esm/src/utils/HelpersUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/WalletUtil.js safe The file contains only legitimate wallet filtering and sorting utility functions with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning.
dist/esm/src/utils/w3m-connecting-widget/index.js safe No malicious patterns detected; the code is a standard WalletConnect UI component with no data exfiltration, code execution, credential harvesting, or suspicious network activity.
dist/esm/src/utils/w3m-connecting-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/w3m-email-otp-widget/index.js safe This is a legitimate LitElement-based email OTP widget from the Reown AppKit UI library with no malicious patterns, no external data exfiltration, no credential harvesting, and no dynamic code execution.
dist/esm/src/utils/w3m-email-otp-widget/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-account-settings-view/index.js safe This is a legitimate LitElement UI component for wallet account settings with no malicious patterns, external data exfiltration, or suspicious code execution detected.
dist/esm/src/views/w3m-account-view/index.js safe No malicious patterns detected; the code is a standard Lit web component for an account view using Reown AppKit controllers and UI partials.
dist/esm/src/views/w3m-all-wallets-view/index.js safe This is a standard LitElement UI component for a wallet selection view, with no malicious patterns, external data transmission, or dangerous code execution detected.
dist/esm/src/views/w3m-approve-transaction-view/index.js safe No malicious patterns detected
dist/esm/src/views/w3m-approve-transaction-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-buy-in-progress-view/index.js safe This is a legitimate Lit-based UI component for the Reown AppKit (formerly WalletConnect) on-ramp flow, with no malicious patterns, obfuscation, credential harvesting, or suspicious behavior detected.
dist/esm/src/views/w3m-buy-in-progress-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-choose-account-name-view/index.js safe No malicious patterns detected; the file is a standard LitElement UI component from the Reown AppKit library that only handles user interaction and navigation.
dist/esm/src/views/w3m-choose-account-name-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connect-socials-view/index.js safe This is a standard Lit web component for a UI view with no malicious patterns; it only reads configuration state and renders a social login list with legal checkbox handling.
dist/esm/src/views/w3m-connect-socials-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connect-view/index.js safe The file contains no malicious patterns (no exfiltration, credential harvesting, obfuscation, dynamic code execution, or shell/process spawning); it is a standard Lit-based wallet connect view with at most minor code-quality/UX concerns.
dist/esm/src/views/w3m-connect-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connect-wallets-view/index.js safe No malicious patterns detected; the file is a standard Lit web component for a crypto wallet connection UI with only delegated UI logic and no network, filesystem, process, or credential access.
dist/esm/src/views/w3m-connect-wallets-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connecting-external-view/index.js safe No malicious patterns detected; the file is a legitimate UI component from the Reown AppKit library handling wallet connection and event tracking.
dist/esm/src/views/w3m-connecting-farcaster-view/index.js safe No malicious patterns detected; the code is a standard LitElement UI component for Farcaster wallet connection without any exfiltration, obfuscation, or suspicious behavior.
dist/esm/src/views/w3m-connecting-farcaster-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connecting-multi-chain-view/index.js safe Legitimate UI component for a multi-chain wallet connector with no malicious patterns detected.
dist/esm/src/views/w3m-connecting-multi-chain-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connecting-social-view/index.js safe No malicious patterns detected; the file is a legitimate Reown AppKit UI component handling social login via postMessage with origin validation against a trusted origin.
dist/esm/src/views/w3m-connecting-social-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-connecting-wc-basic-view/index.js safe This is a standard Lit web component for a wallet connection UI with no malicious patterns, network exfiltration, dynamic code execution, or filesystem/process access.
dist/esm/src/views/w3m-connecting-wc-view/index.js safe This is a legitimate WalletConnect UI component from the Reown AppKit library with no malicious patterns detected.
dist/esm/src/views/w3m-downloads-view/index.js safe No malicious patterns detected; the file is a benign Lit web component that renders wallet download links and opens them in a new tab via an imported utility.
dist/esm/src/views/w3m-email-login-view/index.js safe No malicious patterns detected
dist/esm/src/views/w3m-email-verify-device-view/index.js safe No malicious patterns detected; this is a standard Lit web component for email device verification within the Reown AppKit wallet library.
dist/esm/src/views/w3m-email-verify-device-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-email-verify-otp-view/index.js safe No malicious patterns detected
dist/esm/src/views/w3m-get-wallet-view/index.js safe No malicious patterns detected; the code is a standard LitElement UI component from Reown AppKit that renders wallet recommendations and opens external links via CoreHelperUtil.openHref.
dist/esm/src/views/w3m-network-switch-view/index.js safe This is a legitimate Lit web component for network switching in the Reown AppKit UI library, with no malicious patterns detected.
dist/esm/src/views/w3m-network-switch-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-networks-view/index.js safe No malicious patterns detected; the file is a legitimate Lit web component for a wallet network selection UI.
dist/esm/src/views/w3m-networks-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-onramp-activity-view/index.js safe No malicious patterns detected; this is a legitimate LitElement component for displaying onramp transaction activity via standard Reown AppKit controllers.
dist/esm/src/views/w3m-onramp-activity-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-onramp-fiat-select-view/index.js safe No malicious patterns detected; this is a benign Lit-based UI component for selecting on-ramp fiat currencies.
dist/esm/src/views/w3m-onramp-fiat-select-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-onramp-providers-view/index.js safe No malicious patterns detected; the code is a legitimate UI component for on-ramp providers using standard Web3 modal patterns without exfiltration, code execution, or credential harvesting.
dist/esm/src/views/w3m-onramp-tokens-select-view/index.js safe No malicious patterns detected; this is a legitimate UI component for selecting onramp tokens using Lit and internal AppKit controllers.
dist/esm/src/views/w3m-onramp-tokens-select-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-profile-view/index.js safe No malicious patterns detected; the code is a standard Lit-based UI component for a wallet profile view that interacts only with application controllers and UI utilities.
dist/esm/src/views/w3m-profile-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-register-account-name-success-view/index.js safe No malicious patterns detected; the file is a standard LitElement UI component with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/esm/src/views/w3m-register-account-name-success-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-register-account-name-view/index.js safe This is a benign Lit web component for registering ENS names in the Reown AppKit wallet UI, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution.
dist/esm/src/views/w3m-register-account-name-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-siwx-sign-message-view/index.js safe No malicious patterns detected; the file is a standard Lit web component for a Sign-In With X (SIWX) message signing view with no exfiltration, obfuscation, or shell execution.
dist/esm/src/views/w3m-swap-preview-view/index.js safe No malicious patterns detected; the file is a legitimate LitElement UI component for a cryptocurrency swap preview with no exfiltration, credential harvesting, code execution, or filesystem/process manipulation.
dist/esm/src/views/w3m-swap-preview-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-swap-select-token-view/index.js safe This is a standard Lit-based UI component from the Reown AppKit library for selecting swap tokens; it contains no malicious patterns, obfuscation, credential harvesting, network exfiltration, or dangerous code execution.
dist/esm/src/views/w3m-swap-select-token-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-swap-view/index.js safe No malicious patterns detected; the code is a legitimate swap view component from the Reown AppKit library.
dist/esm/src/views/w3m-swap-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-switch-active-chain-view/index.js safe This file is a legitimate UI component from the Reown AppKit library with no malicious patterns, external data exfiltration, dynamic code execution, or suspicious network/file system activity.
dist/esm/src/views/w3m-switch-active-chain-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-switch-address-view/index.js safe This is a legitimate Lit web component for switching wallet addresses from the Reown AppKit library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution were detected.
dist/esm/src/views/w3m-switch-address-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-transactions-view/index.js safe No malicious patterns detected
dist/esm/src/views/w3m-transactions-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-unsupported-chain-view/index.js safe No malicious patterns detected; the code is a standard UI component from the Reown AppKit library with no exfiltration, credential harvesting, dynamic execution, or other security concerns.
dist/esm/src/views/w3m-unsupported-chain-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-update-email-primary-otp-view/index.js safe This is a standard UI component for OTP email verification from the Reown AppKit library with no malicious patterns, external data exfiltration, obfuscation, or suspicious behavior detected.
dist/esm/src/views/w3m-update-email-secondary-otp-view/index.js safe No malicious patterns detected; the code is a standard Lit-based UI component for OTP email verification within the Reown AppKit wallet library.
dist/esm/src/views/w3m-update-email-wallet-view/index.js safe The code is a UI component for updating an email address in a wallet application, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution detected.
dist/esm/src/views/w3m-update-email-wallet-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-upgrade-wallet-view/index.js safe No malicious patterns detected; the file is a standard LitElement UI component rendering a static link to a dashboard.
dist/esm/src/views/w3m-wallet-compatible-networks-view/index.js safe No malicious patterns detected; the file is a legitimate Lit web component for displaying compatible networks in the Reown AppKit wallet UI.
dist/esm/src/views/w3m-wallet-compatible-networks-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-wallet-receive-view/index.js safe No malicious patterns detected
dist/esm/src/views/w3m-wallet-receive-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-wallet-send-preview-view/index.js safe No malicious patterns detected; the code is a normal Lit-based UI component for a wallet send preview with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
dist/esm/src/views/w3m-wallet-send-preview-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-wallet-send-select-token-view/index.js safe This is a standard Lit UI component for selecting tokens in a wallet send flow; it contains no network calls, file system access, process spawning, obfuscation, or credential harvesting patterns.
dist/esm/src/views/w3m-wallet-send-select-token-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-wallet-send-view/index.js safe No malicious patterns detected; this is a benign Lit UI component for a wallet send view that relies on internal appkit-controllers and performs no external data exfiltration, code execution, or credential access.
dist/esm/src/views/w3m-wallet-send-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/views/w3m-what-is-a-buy-view/index.js safe No malicious patterns detected
dist/esm/src/views/w3m-what-is-a-network-view/index.js safe This is a benign LitElement UI component that renders informational content about blockchain networks and opens a fixed external documentation URL on button click; no malicious patterns detected.
dist/esm/src/views/w3m-what-is-a-wallet-view/index.js safe No malicious patterns detected; the file is a standard Lit web component view with no data exfiltration, credential harvesting, obfuscation, or process execution.

Frequently asked questions

Is @reown/appkit-scaffold-ui safe to use?

No confirmed malware was found in @reown/appkit-scaffold-ui@1.7.8, but the review flagged 6 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit-scaffold-ui contain malware?

No malware was identified in @reown/appkit-scaffold-ui@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit-scaffold-ui checked?

Togoder Security downloaded the published npm package and had an AI model read its 200 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit-scaffold-ui together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-scaffold-ui@1.7.8, cost nothing.

Related security reports