Togoder security

npm package security report

@reown/appkit-ui npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 355 Size 494.6 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit-ui@1.7.8 on Oct 4, 2026. An AI review of 355 source files produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
1
low

Findings 4

medium

Unsanitized CSS injection via component properties

NPS-6AE61A8BD00E

All grid-related properties (gridTemplateRows, gridTemplateColumns, justifyItems, alignItems, justifyContent, alignContent, columnGap, rowGap, gap, padding, margin) are bound to LitElement @property() decorators without validation or sanitization. In render(), their raw values are interpolated directly into this.style.cssText. An application that sets these attributes (including from user-controlled or API-controlled data) could inject arbitrary CSS, enabling UI redressing, data exfiltration via CSS (e.g. attribute/selector-based leaks), or style-based attacks.

dist/esm/src/layout/wui-grid/index.js:13
medium

Dynamic DOM injection without sanitization

NPS-540685951595

initializeTheming and setThemeVariables create <style> elements and assign untrusted themeVariables into their textContent. No validation/sanitization of themeVariables keys or values is performed before writing to the DOM. If attacker-controlled theme variables are ever supplied (e.g., via dApp config, URL, or cross-window messaging), arbitrary CSS can be injected globally.

dist/esm/src/utils/ThemeUtil.js:8
medium

Unsafe CSS injection via unsafeCSS()

NPS-981095B93DCE

The code uses Lit's unsafeCSS() to interpolate user-supplied theme variables directly into CSS. If themeVariables originate from an untrusted source (e.g., URL parameters, postMessage, or remote config), an attacker could inject arbitrary CSS, enabling UI redressing, data exfiltration via CSS selectors/attribute leakage, or style-based attacks. The variables --w3m-color-mix-strength, --w3m-font-family, --w3m-accent, and --w3m-background are passed through without sanitization.

dist/esm/src/utils/ThemeUtil.js:42
low

External resource loading at runtime

NPS-752A44D62A4C

The generated styles include an @import url('https://fonts.googleapis.com/css2?family=Inter...') directive that causes the browser to fetch a stylesheet from an external Google Fonts domain when the styles are applied. This is a third-party network dependency embedded in the library, which can leak user IP/user-agent to Google and creates a dependency on an external service. While common, it is a privacy/security consideration in a security-sensitive wallet UI package.

dist/esm/src/utils/ThemeUtil.js:36

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/src/layout/wui-grid/index.js medium The widget is a normal Lit web component but interpolates unvalidated property values into inline CSS, creating a CSS injection risk if those values are attacker-influenced; no network, filesystem, process, or obfuscated malicious behavior is present.
dist/esm/src/utils/ThemeUtil.js medium No direct malicious behavior, but the module unsafely interpolates potentially untrusted theme variables into global CSS via unsafeCSS(), which could enable CSS injection attacks if theme variables are attacker-controllable.
dist/esm/exports/index.js safe This file only re-exports symbols from internal utility modules with no suspicious or malicious patterns.
dist/esm/exports/jsx.js safe The file only re-exports utilities from an internal JSX type module and references a source map, with no malicious patterns detected.
dist/esm/exports/wui-account-button.js safe This is a simple re-export module that delegates to a relative source file, containing no suspicious or malicious patterns.
dist/esm/exports/wui-alertbar.js safe No malicious patterns detected
dist/esm/exports/wui-all-wallets-image.js safe This file is a simple ES module re-export from an internal source directory with a source map comment, containing no executable code, network calls, credential access, or other malicious patterns.
dist/esm/exports/wui-avatar.js safe No malicious patterns detected; the file is a simple ESM re-export with a source map reference.
dist/esm/exports/wui-balance.js safe No malicious patterns detected
dist/esm/exports/wui-banner-img.js safe No malicious patterns detected; the file only re-exports from an internal source module and includes a source map reference.
dist/esm/exports/wui-banner.js safe No malicious patterns detected
dist/esm/exports/wui-button.js safe This is a simple re-export barrel file with no executable logic or suspicious patterns.
dist/esm/exports/wui-card-select-loader.js safe This file only re-exports from an internal source directory and contains no malicious patterns or executable code.
dist/esm/exports/wui-card-select.js safe The file is a simple ES module re-export with a source map comment and no malicious patterns.
dist/esm/exports/wui-card.js safe No malicious patterns detected
dist/esm/exports/wui-certified-switch.js safe This is a simple re-export file with no suspicious patterns or malicious behavior.
dist/esm/exports/wui-checkbox.js safe No malicious patterns detected
dist/esm/exports/wui-chip-button.js safe This file is a simple ESM re-export of another module and contains no executable code or malicious patterns.
dist/esm/exports/wui-chip.js safe The file is a simple re-export barrel module with no executable code or malicious patterns.
dist/esm/exports/wui-compatible-network.js safe This is a trivial ES module re-export with a source map reference and no malicious patterns.
dist/esm/exports/wui-connect-button.js safe No malicious patterns detected
dist/esm/exports/wui-cta-button.js safe No malicious patterns detected
dist/esm/exports/wui-details-group-item.js safe This is a simple re-export barrel file with no executable or malicious patterns.
dist/esm/exports/wui-details-group.js safe This file is a simple ES module re-export with no executable code or suspicious patterns.
dist/esm/exports/wui-dropdown-menu.js safe This file is a simple ESM re-export of an internal module with no executable code or malicious patterns.
Show 330 more files
FileVerdictWhat the reviewer saw
dist/esm/exports/wui-email-input.js safe No malicious patterns detected
dist/esm/exports/wui-ens-input.js safe This file is a simple re-export barrel module with no executable code, network calls, or suspicious patterns.
dist/esm/exports/wui-flex.js safe No malicious patterns detected
dist/esm/exports/wui-grid.js safe No malicious patterns detected
dist/esm/exports/wui-icon-box.js safe The file is a simple ESM re-export of an internal module with no malicious patterns or suspicious code.
dist/esm/exports/wui-icon-button.js safe No malicious patterns detected
dist/esm/exports/wui-icon-link.js safe No malicious patterns detected
dist/esm/exports/wui-icon.js safe No malicious patterns detected
dist/esm/exports/wui-image.js safe The file is a simple ESM re-export with no executable logic or malicious patterns
dist/esm/exports/wui-input-amount.js safe This file is a simple re-export module with no executable logic, external requests, or malicious patterns.
dist/esm/exports/wui-input-element.js safe This is a simple re-export barrel file that has no executable code, network requests, or suspicious patterns.
dist/esm/exports/wui-input-numeric.js safe This file is a simple re-export of an internal module and contains no malicious patterns or security concerns.
dist/esm/exports/wui-input-text.js safe Simple re-export barrel file with no executable code or suspicious patterns.
dist/esm/exports/wui-link.js safe This file is a simple ESM re-export from an internal source module with no executable logic, network access, or suspicious patterns.
dist/esm/exports/wui-list-accordion.js safe No malicious patterns detected
dist/esm/exports/wui-list-account.js safe No malicious patterns detected
dist/esm/exports/wui-list-button.js safe No malicious patterns detected
dist/esm/exports/wui-list-content.js safe No malicious patterns detected
dist/esm/exports/wui-list-description.js safe No malicious patterns detected
dist/esm/exports/wui-list-item.js safe This file is a simple re-export barrel module with no executable code or malicious patterns.
dist/esm/exports/wui-list-network.js safe No malicious patterns detected; the file is a simple re-export from the package's internal source directory.
dist/esm/exports/wui-list-social.js safe This file is a simple ESM re-export of a local module path with a source map comment, containing no executable code or malicious patterns.
dist/esm/exports/wui-list-token.js safe This file is a simple re-export of a source module with no executable code, network access, or suspicious patterns.
dist/esm/exports/wui-list-wallet-transaction.js safe The file is a simple ESM re-export of a sibling module with a source map comment and contains no malicious patterns, dynamic execution, or external I/O.
dist/esm/exports/wui-list-wallet.js safe The file only re-exports from a local module with no malicious patterns detected.
dist/esm/exports/wui-loading-hexagon.js safe No malicious patterns detected
dist/esm/exports/wui-loading-spinner.js safe No malicious patterns detected; the file is a simple ESM re-export with a source map reference.
dist/esm/exports/wui-loading-thumbnail.js safe The file is a simple re-export module with no executable code or malicious patterns.
dist/esm/exports/wui-logo-select.js safe This is a simple re-export barrel file with no executable code, network activity, or suspicious patterns.
dist/esm/exports/wui-logo.js safe This is a simple re-export barrel file that only re-exports from an internal source module with no malicious patterns.
dist/esm/exports/wui-network-button.js safe The file is a simple ESM re-export with a source map reference, containing no malicious patterns or dynamic execution.
dist/esm/exports/wui-network-image.js safe The file is a simple ESM re-export with a source map reference and contains no malicious patterns or suspicious behavior.
dist/esm/exports/wui-notice-card.js safe The file is a simple re-export barrel module with a source map reference and contains no malicious patterns.
dist/esm/exports/wui-otp.js safe No malicious patterns detected; the file is a simple ES module re-export with a source map reference.
dist/esm/exports/wui-preview-item.js safe This file is a simple re-export module with no executable logic or malicious patterns.
dist/esm/exports/wui-profile-button-v2.js safe No malicious patterns detected
dist/esm/exports/wui-profile-button.js safe No malicious patterns detected; the file is a simple re-export with an inline source map reference.
dist/esm/exports/wui-promo.js safe This is a simple re-export module with no malicious patterns, network activity, or dynamic code execution.
dist/esm/exports/wui-qr-code.js safe No malicious patterns detected
dist/esm/exports/wui-search-bar.js safe This file is a simple re-export barrel module with no executable logic, network calls, or suspicious patterns.
dist/esm/exports/wui-select.js safe No malicious patterns detected
dist/esm/exports/wui-separator.js safe This is a simple ESM re-export file with no executable logic, external calls, or suspicious patterns.
dist/esm/exports/wui-shimmer.js safe No malicious patterns detected; the file is a simple ESM re-export of an internal component module.
dist/esm/exports/wui-snackbar.js safe No malicious patterns detected
dist/esm/exports/wui-switch.js safe No malicious patterns detected
dist/esm/exports/wui-tabs.js safe No malicious patterns detected
dist/esm/exports/wui-tag.js safe The file only re-exports from an internal module path and contains no malicious patterns, network activity, or dynamic code execution.
dist/esm/exports/wui-text.js safe No malicious patterns detected
dist/esm/exports/wui-token-button.js safe The file only re-exports from an internal composite module with no malicious patterns, network calls, process execution, or obfuscation.
dist/esm/exports/wui-token-list-item.js safe No malicious patterns detected; this file only re-exports from an internal module path with no dynamic imports, network calls, or execution logic.
dist/esm/exports/wui-tooltip.js safe This file is a simple re-export module with no executable code, suspicious patterns, or security concerns.
dist/esm/exports/wui-transaction-list-item-loader.js safe The file contains only a static re-export statement and a source map comment, with no malicious patterns detected.
dist/esm/exports/wui-transaction-list-item.js safe No malicious patterns detected
dist/esm/exports/wui-transaction-visual.js safe This file is a simple ESM re-export that only forwards exports from an internal module and contains no malicious patterns or executable code.
dist/esm/exports/wui-ux-by-reown.js safe This file is a simple ES module re-export with no executable code, network access, or malicious patterns.
dist/esm/exports/wui-visual-thumbnail.js safe This file is a simple re-export shim that only forwards exports from an internal source file, with no executable, obfuscated, or network-related code.
dist/esm/exports/wui-visual.js safe No malicious patterns detected
dist/esm/exports/wui-wallet-button.js safe No malicious patterns detected
dist/esm/exports/wui-wallet-image.js safe No malicious patterns detected
dist/esm/src/assets/svg/add.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/all-wallets.js safe The file contains only a static, inert SVG icon definition for a web component, with no network, file system, process execution, obfuscation, or install-time behavior.
dist/esm/src/assets/svg/app-store.js safe No malicious patterns detected; the file only exports a static SVG template for an App Store icon using lit's svg tag.
dist/esm/src/assets/svg/apple.js safe No malicious patterns detected
dist/esm/src/assets/svg/arrow-bottom-circle.js safe No malicious patterns detected
dist/esm/src/assets/svg/arrow-bottom.js safe No malicious patterns detected
dist/esm/src/assets/svg/arrow-left.js safe No malicious patterns detected
dist/esm/src/assets/svg/arrow-right.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/arrow-top.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/bank.js safe No malicious patterns detected
dist/esm/src/assets/svg/browser.js safe This file only defines a static SVG Lit template with no executable logic, imports, network activity, or suspicious patterns.
dist/esm/src/assets/svg/card.js safe The file only exports a static SVG template using Lit's svg tag, with no dynamic code execution, network calls, filesystem access, or other malicious patterns.
dist/esm/src/assets/svg/checkmark-bold.js safe No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
dist/esm/src/assets/svg/checkmark.js safe The file only exports a static SVG template literal using lit's svg tag; no network, filesystem, process, credential, or dynamic execution behavior is present.
dist/esm/src/assets/svg/chevron-bottom.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/chevron-left.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/chevron-right.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/chevron-top.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/chrome-store.js safe This file only exports a static SVG icon using lit's svg template literal tag; it contains no executable logic, network requests, filesystem access, or other malicious patterns.
dist/esm/src/assets/svg/clock.js safe No malicious patterns detected
dist/esm/src/assets/svg/close.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/coinPlaceholder.js safe No malicious patterns detected
dist/esm/src/assets/svg/compass.js safe The file only defines a static SVG icon using lit's svg template tag with no executable, network, filesystem, or dynamic code patterns.
dist/esm/src/assets/svg/copy.js safe No malicious patterns detected
dist/esm/src/assets/svg/cursor-transparent.js safe This file only defines a static SVG template using lit's svg tag with no executable, network, filesystem, or credential-related behavior.
dist/esm/src/assets/svg/cursor.js safe This file only exports a static SVG template literal with no executable, network, filesystem, or process-related code.
dist/esm/src/assets/svg/desktop.js safe This file only exports a static SVG template using Lit's svg tag; it contains no executable logic, network activity, file access, or other malicious patterns.
dist/esm/src/assets/svg/disconnect.js safe No malicious patterns detected; the file only exports a static SVG icon definition using lit's svg template literal.
dist/esm/src/assets/svg/discord.js safe No malicious patterns detected
dist/esm/src/assets/svg/etherscan.js safe No malicious patterns detected
dist/esm/src/assets/svg/exclamation-triangle.js safe No malicious patterns detected; the file only exports a static SVG icon definition using the 'lit' svg template tag.
dist/esm/src/assets/svg/extension.js safe No malicious patterns detected
dist/esm/src/assets/svg/external-link.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/facebook.js safe No malicious patterns detected
dist/esm/src/assets/svg/farcaster.js safe No malicious patterns detected
dist/esm/src/assets/svg/filters.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/github.js safe No malicious patterns detected; this file only exports a static GitHub SVG icon using lit's svg template tag.
dist/esm/src/assets/svg/google.js safe No malicious patterns detected
dist/esm/src/assets/svg/help-circle.js safe This file is a benign SVG icon definition using Lit's svg template tag with no executable or suspicious code.
dist/esm/src/assets/svg/id.js safe No malicious patterns detected
dist/esm/src/assets/svg/image.js safe No malicious patterns detected
dist/esm/src/assets/svg/info-circle.js safe No malicious patterns detected
dist/esm/src/assets/svg/info.js safe No malicious patterns detected
dist/esm/src/assets/svg/lightbulb.js safe No malicious patterns detected
dist/esm/src/assets/svg/mail.js safe The file contains only a static SVG template literal for a mail icon with no executable logic or malicious patterns.
dist/esm/src/assets/svg/mobile.js safe The file contains only a static SVG template literal for a mobile icon with no executable, network, filesystem, or obfuscated malicious behavior.
dist/esm/src/assets/svg/more.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/network-placeholder.js safe No malicious patterns detected; the file only exports a static SVG icon definition using lit's svg template tag.
dist/esm/src/assets/svg/networkLg.js safe No malicious patterns detected
dist/esm/src/assets/svg/networkMd.js safe No malicious patterns detected
dist/esm/src/assets/svg/networkSm.js safe No malicious patterns detected; the file only defines a static SVG template using lit's svg tag.
dist/esm/src/assets/svg/nftPlaceholder.js safe No malicious patterns detected; the file only exports a static SVG template using lit's svg tagged template literal.
dist/esm/src/assets/svg/off.js safe No malicious patterns detected; the file only exports a static SVG icon template for lit.
dist/esm/src/assets/svg/play-store.js safe No malicious patterns detected
dist/esm/src/assets/svg/plus.js safe No malicious patterns detected
dist/esm/src/assets/svg/qr-code.js safe The file contains only a static SVG icon definition using lit's svg template tag with no executable code, network calls, or suspicious behavior.
dist/esm/src/assets/svg/recycle-horizontal.js safe The file contains only a static SVG icon definition with no executable or suspicious code.
dist/esm/src/assets/svg/refresh.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/reown-logo.js safe No malicious patterns detected; the file only exports a static SVG graphic via lit's svg template.
dist/esm/src/assets/svg/search.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/send.js safe No malicious patterns detected; the file is a simple SVG template export with no dynamic code, network, file system, or process activity.
dist/esm/src/assets/svg/swap-input-mask-bottom.js safe No malicious patterns detected
dist/esm/src/assets/svg/swap-input-mask-top.js safe No malicious patterns detected
dist/esm/src/assets/svg/swapHorizontal.js safe No malicious patterns detected; this file only defines a static SVG icon using lit's svg template tag.
dist/esm/src/assets/svg/swapHorizontalBold.js safe The file only exports a static SVG template using lit's svg tag, with no dynamic behavior, network access, filesystem operations, or executable code.
dist/esm/src/assets/svg/swapHorizontalMedium.js safe No malicious patterns detected
dist/esm/src/assets/svg/swapHorizontalRoundedBold.js safe No malicious patterns detected
dist/esm/src/assets/svg/swapVertical.js safe No malicious patterns detected
dist/esm/src/assets/svg/telegram.js safe No malicious patterns detected
dist/esm/src/assets/svg/three-dots.js safe No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
dist/esm/src/assets/svg/twitch.js safe The file defines a static Lit SVG template for a Twitch icon and contains no network, filesystem, execution, or obfuscation patterns.
dist/esm/src/assets/svg/twitterIcon.js safe No malicious patterns detected
dist/esm/src/assets/svg/verify-filled.js safe No malicious patterns detected
dist/esm/src/assets/svg/verify.js safe This file contains only a static SVG icon template using lit's svg tag with no executable logic, network calls, or other malicious patterns.
dist/esm/src/assets/svg/wallet-placeholder.js safe No malicious patterns detected; the file only exports static SVG markup using lit's svg template tag with no executable or suspicious behavior.
dist/esm/src/assets/svg/wallet.js safe No malicious patterns detected; the file only exports a static SVG template using lit's svg tag with no dynamic behavior or external interactions.
dist/esm/src/assets/svg/walletconnect.js safe This file contains only static SVG icon definitions using lit's svg template tag, with no executable logic, network calls, or suspicious patterns.
dist/esm/src/assets/svg/warning-circle.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/assets/svg/x.js safe No malicious patterns detected
dist/esm/src/assets/visual/bitcoin.js safe This file only exports a static Bitcoin SVG icon using lit's svg template tag; no malicious patterns, dynamic code execution, network requests, or filesystem access were found.
dist/esm/src/assets/visual/browser.js safe The file contains only a static SVG template literal using lit's svg tag with no executable, network, filesystem, or obfuscated code.
dist/esm/src/assets/visual/coinbase.js safe No malicious patterns detected
dist/esm/src/assets/visual/dao.js safe This is a static SVG icon definition using lit's svg template tag with no executable code or malicious patterns.
dist/esm/src/assets/visual/defi.js safe No malicious patterns detected; the file only defines a static SVG icon via lit's svg template tag.
dist/esm/src/assets/visual/defiAlt.js safe This file only exports a static SVG template using lit's svg tag; it contains no executable logic, network calls, credential access, obfuscation, or other malicious patterns.
dist/esm/src/assets/visual/eth.js safe No malicious patterns detected; the file only exports a static SVG template for an Ethereum icon.
dist/esm/src/assets/visual/google.js safe No malicious patterns detected
dist/esm/src/assets/visual/layers.js safe No malicious patterns detected; this file only exports a static SVG template using lit's svg tag with no executable or network behavior.
dist/esm/src/assets/visual/lightbulb.js safe The file contains only a static SVG lightbulb icon built with lit's svg template tag; no malicious patterns, network calls, dynamic code execution, or credential access were detected.
dist/esm/src/assets/visual/lock.js safe The file contains only a static SVG template literal with no executable code, network access, or malicious patterns.
dist/esm/src/assets/visual/login.js safe The file only exports a static inline SVG template using lit's svg tag with no executable logic, network calls, credential access, or other malicious patterns.
dist/esm/src/assets/visual/meld.js safe The file contains only a static SVG icon defined via lit's svg template tag, with no executable code, network calls, file system access, or other malicious patterns.
dist/esm/src/assets/visual/moonpay.js safe No malicious patterns detected
dist/esm/src/assets/visual/network.js safe The file contains only a static SVG template literal for a UI icon with no executable code, network access, or file system interaction.
dist/esm/src/assets/visual/nft.js safe The file contains only a static SVG template literal for an NFT icon with no executable, network, filesystem, or dynamic behavior.
dist/esm/src/assets/visual/noun.js safe No malicious patterns detected
dist/esm/src/assets/visual/onramp-card.js safe No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
dist/esm/src/assets/visual/paypal.js safe No malicious patterns detected; the file only exports a static inline SVG definition for a PayPal icon.
dist/esm/src/assets/visual/pencil.js safe No malicious patterns detected
dist/esm/src/assets/visual/profile.js safe No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
dist/esm/src/assets/visual/solana.js safe No malicious patterns detected; the file only exports a static SVG template for the Solana logo.
dist/esm/src/assets/visual/stripe.js safe This file only exports a static SVG icon template using lit's svg tag with no executable logic or security concerns.
dist/esm/src/assets/visual/system.js safe No malicious patterns detected
dist/esm/src/components/wui-card/index.js safe The file is a standard LitElement web component definition with no malicious patterns, network calls, file system access, or dynamic code execution.
dist/esm/src/components/wui-card/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-icon/index.js safe No malicious patterns detected; the code is a standard Lit web component for lazy-loading SVG icons with caching.
dist/esm/src/components/wui-icon/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-image/index.js safe No malicious patterns detected; this is a standard Lit web component for rendering an image with no network, filesystem, or process operations.
dist/esm/src/components/wui-image/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-loading-hexagon/index.js safe No malicious patterns detected; the file is a standard LitElement web component that renders an SVG loading spinner.
dist/esm/src/components/wui-loading-hexagon/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-loading-spinner/index.js safe No malicious patterns detected; this is a standard Lit web component for rendering a loading spinner.
dist/esm/src/components/wui-loading-spinner/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-loading-thumbnail/index.js safe No malicious patterns detected; the file defines a standard Lit web component for rendering an SVG loading thumbnail with no network, filesystem, process, or dynamic execution behavior.
dist/esm/src/components/wui-loading-thumbnail/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-shimmer/index.js safe No malicious patterns detected
dist/esm/src/components/wui-shimmer/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-text/index.js safe No malicious patterns detected
dist/esm/src/components/wui-text/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/components/wui-visual/index.js safe This is a standard Lit web component that renders inline SVG icons and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity.
dist/esm/src/components/wui-visual/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-account-button/index.js safe No malicious patterns detected; the file is a standard Lit web component for rendering an account button with imported UI utilities and no exfiltration, obfuscation, or system-level access.
dist/esm/src/composites/wui-account-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-alertbar/index.js safe No malicious patterns detected; the code is a standard Lit web component for an alert bar with no network, filesystem, or process manipulation.
dist/esm/src/composites/wui-alertbar/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-all-wallets-image/index.js safe No malicious patterns detected; the file is a standard Lit web component rendering wallet images without any suspicious behavior.
dist/esm/src/composites/wui-all-wallets-image/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-avatar/index.js safe No malicious patterns detected; the code is a standard LitElement-based avatar web component with no network, filesystem, or dynamic execution concerns.
dist/esm/src/composites/wui-avatar/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-balance/index.js safe No malicious patterns detected; this is a benign LitElement web component for rendering a balance display.
dist/esm/src/composites/wui-balance/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-banner-img/index.js safe No malicious patterns detected; this is a benign Lit web component that renders a banner image and text.
dist/esm/src/composites/wui-banner-img/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-banner/index.js safe No malicious patterns detected; the code is a standard Lit web component for rendering a banner UI with no network, filesystem, or dynamic execution activity.
dist/esm/src/composites/wui-banner/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-button/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-card-select-loader/index.js safe No malicious patterns detected; this is a benign Lit-based UI loading shimmer component.
dist/esm/src/composites/wui-card-select-loader/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-card-select/index.js safe This is a standard Lit web component for rendering a selectable card UI; no malicious patterns, network activity, dynamic code execution, or filesystem/process manipulation were detected.
dist/esm/src/composites/wui-card-select/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-certified-switch/index.js safe No malicious patterns detected; the code is a standard Lit web component for a certified switch UI element with no data exfiltration, obfuscation, dynamic execution, or network/file system access.
dist/esm/src/composites/wui-certified-switch/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-checkbox/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-checkbox/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-chip-button/index.js safe No malicious patterns detected; this is a standard Lit web component chip button with no network, filesystem, process, or dynamic execution behavior.
dist/esm/src/composites/wui-chip-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-chip/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-chip/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-compatible-network/index.js safe No malicious patterns detected; this is a standard Lit web component for rendering network icons with no external data access, code execution, or network communication.
dist/esm/src/composites/wui-compatible-network/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-connect-button/index.js safe No malicious patterns detected; the file is a standard LitElement UI component with no network, filesystem, or process operations.
dist/esm/src/composites/wui-connect-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-cta-button/index.js safe The file is a standard Lit-based web component definition for a CTA button with no malicious patterns, network activity, credential access, or dynamic code execution.
dist/esm/src/composites/wui-cta-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-details-group-item/index.js safe This is a standard LitElement web component definition with no network, filesystem, process execution, or obfuscated code present.
dist/esm/src/composites/wui-details-group-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-details-group/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-details-group/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-dropdown-menu/index.js safe No malicious patterns detected; the file is a standard Lit web component implementation.
dist/esm/src/composites/wui-dropdown-menu/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-email-input/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-email-input/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-ens-input/index.js safe The file is a benign Lit web component for ENS input rendering with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/src/composites/wui-ens-input/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-icon-box/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-icon-box/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-icon-button/index.js safe No malicious patterns detected in the provided LitElement component source code.
dist/esm/src/composites/wui-icon-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-icon-link/index.js safe This is a standard Lit web component for rendering an icon link button with no malicious patterns, network calls, or dynamic code execution.
dist/esm/src/composites/wui-icon-link/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-input-amount/index.js safe No malicious patterns detected; the code is a standard LitElement web component for numeric input handling without any network, filesystem, or code execution concerns.
dist/esm/src/composites/wui-input-amount/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-input-element/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-input-element/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-input-numeric/index.js safe No malicious patterns detected; the code is a standard Lit web component for numeric input with no network, filesystem, or dynamic execution concerns.
dist/esm/src/composites/wui-input-numeric/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-input-text/index.js safe This is a standard LitElement-based web component for a text input field with no malicious patterns, network calls, file system access, or dynamic code execution.
dist/esm/src/composites/wui-input-text/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-link/index.js safe The file is a standard Lit-based web component for a link button with no network, filesystem, process, or obfuscation activity.
dist/esm/src/composites/wui-link/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-accordion/index.js safe No malicious patterns detected; this is a standard Lit web component implementing an accordion UI with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/src/composites/wui-list-accordion/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-account/index.js safe No malicious patterns detected; the code is a standard Lit web component for displaying account information with no exfiltration, obfuscation, or dangerous operations.
dist/esm/src/composites/wui-list-account/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-button/index.js safe This is a standard Lit-based web component for rendering a button; no malicious patterns, network calls, or exec/eval usage were found.
dist/esm/src/composites/wui-list-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-content/index.js safe No malicious patterns detected; this is a standard Lit web component for rendering list content with image/text/icon.
dist/esm/src/composites/wui-list-content/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-description/index.js safe No malicious patterns detected; this is a standard Lit web component for rendering a list description with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/src/composites/wui-list-description/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-item/index.js safe No malicious patterns detected; the file is a standard Lit-based UI list-item web component with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/src/composites/wui-list-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-network/index.js safe No malicious patterns detected; the file is a standard LitElement web component for rendering a network list item.
dist/esm/src/composites/wui-list-network/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-social/index.js safe This is a standard LitElement web component for rendering a social login list item with no malicious patterns, network activity, or dynamic code execution.
dist/esm/src/composites/wui-list-social/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-token/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-list-token/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-wallet-transaction/index.js safe No malicious patterns detected; this is a LitElement web component for displaying wallet transaction details with no network, filesystem, process, or dynamic execution behavior.
dist/esm/src/composites/wui-list-wallet-transaction/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-list-wallet/index.js safe This is a standard Lit web component for rendering a wallet list item with no malicious patterns, network activity, file system access, or dynamic code execution.
dist/esm/src/composites/wui-list-wallet/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-logo-select/index.js safe No malicious patterns detected; the file is a standard LitElement web component with no network, filesystem, or dynamic execution behavior.
dist/esm/src/composites/wui-logo-select/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-logo/index.js safe No malicious patterns detected; the file is a standard LitElement web component definition with no external data access, process execution, or obfuscation.
dist/esm/src/composites/wui-logo/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-network-button/index.js safe This is a standard LitElement web component for rendering a network button with no malicious patterns, external network calls, credential access, or dynamic code execution.
dist/esm/src/composites/wui-network-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-network-image/index.js safe This is a legitimate Lit-based web component for displaying network images; no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution were detected.
dist/esm/src/composites/wui-network-image/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-notice-card/index.js safe This is a standard Lit web component definition with no network, filesystem, process, or dynamic code execution patterns.
dist/esm/src/composites/wui-notice-card/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-otp/index.js safe No malicious patterns detected; the code is a standard Lit-based OTP input component with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/src/composites/wui-otp/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-preview-item/index.js safe No malicious patterns detected; this is a standard LitElement web component for rendering preview items.
dist/esm/src/composites/wui-preview-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-profile-button-v2/index.js safe No malicious patterns detected; this is a standard Lit web component for a profile button with no network, filesystem, process, or dynamic execution behavior.
dist/esm/src/composites/wui-profile-button-v2/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-profile-button/index.js safe No malicious patterns detected; the file is a legitimate LitElement UI component with no network exfiltration, credential harvesting, dynamic code execution, process spawning, or install-time behavior.
dist/esm/src/composites/wui-profile-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-promo/index.js safe This is a benign Lit-based web component definition with no network, filesystem, process, or dynamic code execution activity.
dist/esm/src/composites/wui-promo/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-qr-code/index.js safe No malicious patterns detected; the file is a standard LitElement component for QR code rendering with no suspicious behavior.
dist/esm/src/composites/wui-qr-code/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-search-bar/index.js safe No malicious patterns detected; this is a standard LitElement UI search bar component with no exfiltration, dynamic execution, or suspicious behavior.
dist/esm/src/composites/wui-search-bar/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-select/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-select/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-snackbar/index.js safe The file is a standard Lit web component definition for a UI snackbar with no network, filesystem, process, or dynamic code execution behavior.
dist/esm/src/composites/wui-snackbar/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-switch/index.js safe No malicious patterns detected; the file is a standard Lit web component switch implementation with no network, filesystem, credential, or dynamic code execution behavior.
dist/esm/src/composites/wui-switch/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-tabs/index.js safe No malicious patterns detected; the file is a benign Lit web component for tabs with no network, filesystem, process execution, or obfuscated code.
dist/esm/src/composites/wui-tabs/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-tag/index.js safe No malicious patterns detected; the code is a benign Lit web component definition for a UI tag element with no network, filesystem, process, or dynamic execution activity.
dist/esm/src/composites/wui-tag/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-token-button/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-token-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-token-list-item/index.js safe No malicious patterns detected; the code is a standard Lit-based Web Component for rendering token list items with lazy loading via IntersectionObserver and no network, filesystem, or process activity.
dist/esm/src/composites/wui-token-list-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-tooltip/index.js safe This is a standard LitElement-based tooltip web component with no malicious patterns, no network calls, no dynamic code execution, and no sensitive data access.
dist/esm/src/composites/wui-tooltip/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-transaction-list-item-loader/index.js safe This is a benign LitElement web component that renders skeleton loading placeholders with no network, credential, process, or dynamic execution behavior.
dist/esm/src/composites/wui-transaction-list-item-loader/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-transaction-list-item/index.js safe This is a standard LitElement web component for rendering transaction list items with no malicious patterns, network activity, or dynamic code execution.
dist/esm/src/composites/wui-transaction-list-item/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-transaction-visual/index.js safe No malicious patterns detected; the code is a standard Lit web component for rendering transaction visuals with no network, filesystem, or dynamic execution behavior.
dist/esm/src/composites/wui-transaction-visual/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-ux-by-reown/index.js safe No malicious patterns detected; the code is a benign LitElement web component that renders a Reown branding link.
dist/esm/src/composites/wui-ux-by-reown/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-visual-thumbnail/index.js safe No malicious patterns detected
dist/esm/src/composites/wui-visual-thumbnail/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-wallet-button/index.js safe This is a standard Lit-based UI component for a wallet button with no malicious patterns, external network calls, dynamic code execution, or credential harvesting.
dist/esm/src/composites/wui-wallet-button/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/composites/wui-wallet-image/index.js safe The file is a standard Lit web component for rendering wallet images with no malicious patterns, network calls, file system access, or dynamic code execution.
dist/esm/src/composites/wui-wallet-image/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/layout/wui-flex/index.js safe No malicious patterns detected; this is a standard Lit web component for flexible layout with only CSS style bindings from component properties.
dist/esm/src/layout/wui-flex/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/layout/wui-grid/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/layout/wui-separator/index.js safe No malicious patterns detected; the code is a standard LitElement web component for rendering a separator with optional text.
dist/esm/src/layout/wui-separator/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/CacheUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/ConstantsUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/JSXTypeUtil.js safe The file is an empty module export stub with only a source map comment, containing no executable code or malicious patterns.
dist/esm/src/utils/MathUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/QrCode.js safe No malicious patterns detected; the code only generates SVG QR codes using the qrcode library and lit templating with no network, filesystem, process, or dynamic execution activity.
dist/esm/src/utils/TransactionUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/TypeUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/UiHelperUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/WebComponentsUtil.js safe No malicious patterns detected; the code only provides standard custom element definition utilities.

Scanned versions of @reown/appkit-ui

VersionVerdictFilesScanned
1.7.8 Needs review 355 Oct 4, 2026

Frequently asked questions

Is @reown/appkit-ui safe to use?

No confirmed malware was found in @reown/appkit-ui@1.7.8, but the review flagged 3 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit-ui contain malware?

No malware was identified in @reown/appkit-ui@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit-ui checked?

Togoder Security downloaded the published npm package and had an AI model read its 355 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit-ui together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-ui@1.7.8, cost nothing.

Related security reports