Summary
Togoder Security scanned the npm package @reown/appkit-ui@1.7.8 on Oct 4, 2026. An AI review of 355 source files produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Unsanitized CSS injection via component properties
NPS-6AE61A8BD00E
All grid-related properties (gridTemplateRows, gridTemplateColumns, justifyItems, alignItems, justifyContent, alignContent, columnGap, rowGap, gap, padding, margin) are bound to LitElement @property() decorators without validation or sanitization. In render(), their raw values are interpolated directly into this.style.cssText. An application that sets these attributes (including from user-controlled or API-controlled data) could inject arbitrary CSS, enabling UI redressing, data exfiltration via CSS (e.g. attribute/selector-based leaks), or style-based attacks.
Dynamic DOM injection without sanitization
NPS-540685951595
initializeTheming and setThemeVariables create <style> elements and assign untrusted themeVariables into their textContent. No validation/sanitization of themeVariables keys or values is performed before writing to the DOM. If attacker-controlled theme variables are ever supplied (e.g., via dApp config, URL, or cross-window messaging), arbitrary CSS can be injected globally.
Unsafe CSS injection via unsafeCSS()
NPS-981095B93DCE
The code uses Lit's unsafeCSS() to interpolate user-supplied theme variables directly into CSS. If themeVariables originate from an untrusted source (e.g., URL parameters, postMessage, or remote config), an attacker could inject arbitrary CSS, enabling UI redressing, data exfiltration via CSS selectors/attribute leakage, or style-based attacks. The variables --w3m-color-mix-strength, --w3m-font-family, --w3m-accent, and --w3m-background are passed through without sanitization.
External resource loading at runtime
NPS-752A44D62A4C
The generated styles include an @import url('https://fonts.googleapis.com/css2?family=Inter...') directive that causes the browser to fetch a stylesheet from an external Google Fonts domain when the styles are applied. This is a third-party network dependency embedded in the library, which can leak user IP/user-agent to Google and creates a dependency on an external service. While common, it is a privacy/security consideration in a security-sensitive wallet UI package.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/layout/wui-grid/index.js | medium | The widget is a normal Lit web component but interpolates unvalidated property values into inline CSS, creating a CSS injection risk if those values are attacker-influenced; no network, filesystem, process, or obfuscated malicious behavior is present. |
| dist/esm/src/utils/ThemeUtil.js | medium | No direct malicious behavior, but the module unsafely interpolates potentially untrusted theme variables into global CSS via unsafeCSS(), which could enable CSS injection attacks if theme variables are attacker-controllable. |
| dist/esm/exports/index.js | safe | This file only re-exports symbols from internal utility modules with no suspicious or malicious patterns. |
| dist/esm/exports/jsx.js | safe | The file only re-exports utilities from an internal JSX type module and references a source map, with no malicious patterns detected. |
| dist/esm/exports/wui-account-button.js | safe | This is a simple re-export module that delegates to a relative source file, containing no suspicious or malicious patterns. |
| dist/esm/exports/wui-alertbar.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-all-wallets-image.js | safe | This file is a simple ES module re-export from an internal source directory with a source map comment, containing no executable code, network calls, credential access, or other malicious patterns. |
| dist/esm/exports/wui-avatar.js | safe | No malicious patterns detected; the file is a simple ESM re-export with a source map reference. |
| dist/esm/exports/wui-balance.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-banner-img.js | safe | No malicious patterns detected; the file only re-exports from an internal source module and includes a source map reference. |
| dist/esm/exports/wui-banner.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-button.js | safe | This is a simple re-export barrel file with no executable logic or suspicious patterns. |
| dist/esm/exports/wui-card-select-loader.js | safe | This file only re-exports from an internal source directory and contains no malicious patterns or executable code. |
| dist/esm/exports/wui-card-select.js | safe | The file is a simple ES module re-export with a source map comment and no malicious patterns. |
| dist/esm/exports/wui-card.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-certified-switch.js | safe | This is a simple re-export file with no suspicious patterns or malicious behavior. |
| dist/esm/exports/wui-checkbox.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-chip-button.js | safe | This file is a simple ESM re-export of another module and contains no executable code or malicious patterns. |
| dist/esm/exports/wui-chip.js | safe | The file is a simple re-export barrel module with no executable code or malicious patterns. |
| dist/esm/exports/wui-compatible-network.js | safe | This is a trivial ES module re-export with a source map reference and no malicious patterns. |
| dist/esm/exports/wui-connect-button.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-cta-button.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-details-group-item.js | safe | This is a simple re-export barrel file with no executable or malicious patterns. |
| dist/esm/exports/wui-details-group.js | safe | This file is a simple ES module re-export with no executable code or suspicious patterns. |
| dist/esm/exports/wui-dropdown-menu.js | safe | This file is a simple ESM re-export of an internal module with no executable code or malicious patterns. |
Show 330 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/exports/wui-email-input.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-ens-input.js | safe | This file is a simple re-export barrel module with no executable code, network calls, or suspicious patterns. |
| dist/esm/exports/wui-flex.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-grid.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-icon-box.js | safe | The file is a simple ESM re-export of an internal module with no malicious patterns or suspicious code. |
| dist/esm/exports/wui-icon-button.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-icon-link.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-icon.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-image.js | safe | The file is a simple ESM re-export with no executable logic or malicious patterns |
| dist/esm/exports/wui-input-amount.js | safe | This file is a simple re-export module with no executable logic, external requests, or malicious patterns. |
| dist/esm/exports/wui-input-element.js | safe | This is a simple re-export barrel file that has no executable code, network requests, or suspicious patterns. |
| dist/esm/exports/wui-input-numeric.js | safe | This file is a simple re-export of an internal module and contains no malicious patterns or security concerns. |
| dist/esm/exports/wui-input-text.js | safe | Simple re-export barrel file with no executable code or suspicious patterns. |
| dist/esm/exports/wui-link.js | safe | This file is a simple ESM re-export from an internal source module with no executable logic, network access, or suspicious patterns. |
| dist/esm/exports/wui-list-accordion.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-list-account.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-list-button.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-list-content.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-list-description.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-list-item.js | safe | This file is a simple re-export barrel module with no executable code or malicious patterns. |
| dist/esm/exports/wui-list-network.js | safe | No malicious patterns detected; the file is a simple re-export from the package's internal source directory. |
| dist/esm/exports/wui-list-social.js | safe | This file is a simple ESM re-export of a local module path with a source map comment, containing no executable code or malicious patterns. |
| dist/esm/exports/wui-list-token.js | safe | This file is a simple re-export of a source module with no executable code, network access, or suspicious patterns. |
| dist/esm/exports/wui-list-wallet-transaction.js | safe | The file is a simple ESM re-export of a sibling module with a source map comment and contains no malicious patterns, dynamic execution, or external I/O. |
| dist/esm/exports/wui-list-wallet.js | safe | The file only re-exports from a local module with no malicious patterns detected. |
| dist/esm/exports/wui-loading-hexagon.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-loading-spinner.js | safe | No malicious patterns detected; the file is a simple ESM re-export with a source map reference. |
| dist/esm/exports/wui-loading-thumbnail.js | safe | The file is a simple re-export module with no executable code or malicious patterns. |
| dist/esm/exports/wui-logo-select.js | safe | This is a simple re-export barrel file with no executable code, network activity, or suspicious patterns. |
| dist/esm/exports/wui-logo.js | safe | This is a simple re-export barrel file that only re-exports from an internal source module with no malicious patterns. |
| dist/esm/exports/wui-network-button.js | safe | The file is a simple ESM re-export with a source map reference, containing no malicious patterns or dynamic execution. |
| dist/esm/exports/wui-network-image.js | safe | The file is a simple ESM re-export with a source map reference and contains no malicious patterns or suspicious behavior. |
| dist/esm/exports/wui-notice-card.js | safe | The file is a simple re-export barrel module with a source map reference and contains no malicious patterns. |
| dist/esm/exports/wui-otp.js | safe | No malicious patterns detected; the file is a simple ES module re-export with a source map reference. |
| dist/esm/exports/wui-preview-item.js | safe | This file is a simple re-export module with no executable logic or malicious patterns. |
| dist/esm/exports/wui-profile-button-v2.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-profile-button.js | safe | No malicious patterns detected; the file is a simple re-export with an inline source map reference. |
| dist/esm/exports/wui-promo.js | safe | This is a simple re-export module with no malicious patterns, network activity, or dynamic code execution. |
| dist/esm/exports/wui-qr-code.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-search-bar.js | safe | This file is a simple re-export barrel module with no executable logic, network calls, or suspicious patterns. |
| dist/esm/exports/wui-select.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-separator.js | safe | This is a simple ESM re-export file with no executable logic, external calls, or suspicious patterns. |
| dist/esm/exports/wui-shimmer.js | safe | No malicious patterns detected; the file is a simple ESM re-export of an internal component module. |
| dist/esm/exports/wui-snackbar.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-switch.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-tabs.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-tag.js | safe | The file only re-exports from an internal module path and contains no malicious patterns, network activity, or dynamic code execution. |
| dist/esm/exports/wui-text.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-token-button.js | safe | The file only re-exports from an internal composite module with no malicious patterns, network calls, process execution, or obfuscation. |
| dist/esm/exports/wui-token-list-item.js | safe | No malicious patterns detected; this file only re-exports from an internal module path with no dynamic imports, network calls, or execution logic. |
| dist/esm/exports/wui-tooltip.js | safe | This file is a simple re-export module with no executable code, suspicious patterns, or security concerns. |
| dist/esm/exports/wui-transaction-list-item-loader.js | safe | The file contains only a static re-export statement and a source map comment, with no malicious patterns detected. |
| dist/esm/exports/wui-transaction-list-item.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-transaction-visual.js | safe | This file is a simple ESM re-export that only forwards exports from an internal module and contains no malicious patterns or executable code. |
| dist/esm/exports/wui-ux-by-reown.js | safe | This file is a simple ES module re-export with no executable code, network access, or malicious patterns. |
| dist/esm/exports/wui-visual-thumbnail.js | safe | This file is a simple re-export shim that only forwards exports from an internal source file, with no executable, obfuscated, or network-related code. |
| dist/esm/exports/wui-visual.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-wallet-button.js | safe | No malicious patterns detected |
| dist/esm/exports/wui-wallet-image.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/add.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/all-wallets.js | safe | The file contains only a static, inert SVG icon definition for a web component, with no network, file system, process execution, obfuscation, or install-time behavior. |
| dist/esm/src/assets/svg/app-store.js | safe | No malicious patterns detected; the file only exports a static SVG template for an App Store icon using lit's svg tag. |
| dist/esm/src/assets/svg/apple.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/arrow-bottom-circle.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/arrow-bottom.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/arrow-left.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/arrow-right.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/arrow-top.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/bank.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/browser.js | safe | This file only defines a static SVG Lit template with no executable logic, imports, network activity, or suspicious patterns. |
| dist/esm/src/assets/svg/card.js | safe | The file only exports a static SVG template using Lit's svg tag, with no dynamic code execution, network calls, filesystem access, or other malicious patterns. |
| dist/esm/src/assets/svg/checkmark-bold.js | safe | No malicious patterns detected; the file only exports a static SVG template using lit's svg tag. |
| dist/esm/src/assets/svg/checkmark.js | safe | The file only exports a static SVG template literal using lit's svg tag; no network, filesystem, process, credential, or dynamic execution behavior is present. |
| dist/esm/src/assets/svg/chevron-bottom.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/chevron-left.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/chevron-right.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/chevron-top.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/chrome-store.js | safe | This file only exports a static SVG icon using lit's svg template literal tag; it contains no executable logic, network requests, filesystem access, or other malicious patterns. |
| dist/esm/src/assets/svg/clock.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/close.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/coinPlaceholder.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/compass.js | safe | The file only defines a static SVG icon using lit's svg template tag with no executable, network, filesystem, or dynamic code patterns. |
| dist/esm/src/assets/svg/copy.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/cursor-transparent.js | safe | This file only defines a static SVG template using lit's svg tag with no executable, network, filesystem, or credential-related behavior. |
| dist/esm/src/assets/svg/cursor.js | safe | This file only exports a static SVG template literal with no executable, network, filesystem, or process-related code. |
| dist/esm/src/assets/svg/desktop.js | safe | This file only exports a static SVG template using Lit's svg tag; it contains no executable logic, network activity, file access, or other malicious patterns. |
| dist/esm/src/assets/svg/disconnect.js | safe | No malicious patterns detected; the file only exports a static SVG icon definition using lit's svg template literal. |
| dist/esm/src/assets/svg/discord.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/etherscan.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/exclamation-triangle.js | safe | No malicious patterns detected; the file only exports a static SVG icon definition using the 'lit' svg template tag. |
| dist/esm/src/assets/svg/extension.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/external-link.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/facebook.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/farcaster.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/filters.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/github.js | safe | No malicious patterns detected; this file only exports a static GitHub SVG icon using lit's svg template tag. |
| dist/esm/src/assets/svg/google.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/help-circle.js | safe | This file is a benign SVG icon definition using Lit's svg template tag with no executable or suspicious code. |
| dist/esm/src/assets/svg/id.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/image.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/info-circle.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/info.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/lightbulb.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/mail.js | safe | The file contains only a static SVG template literal for a mail icon with no executable logic or malicious patterns. |
| dist/esm/src/assets/svg/mobile.js | safe | The file contains only a static SVG template literal for a mobile icon with no executable, network, filesystem, or obfuscated malicious behavior. |
| dist/esm/src/assets/svg/more.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/network-placeholder.js | safe | No malicious patterns detected; the file only exports a static SVG icon definition using lit's svg template tag. |
| dist/esm/src/assets/svg/networkLg.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/networkMd.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/networkSm.js | safe | No malicious patterns detected; the file only defines a static SVG template using lit's svg tag. |
| dist/esm/src/assets/svg/nftPlaceholder.js | safe | No malicious patterns detected; the file only exports a static SVG template using lit's svg tagged template literal. |
| dist/esm/src/assets/svg/off.js | safe | No malicious patterns detected; the file only exports a static SVG icon template for lit. |
| dist/esm/src/assets/svg/play-store.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/plus.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/qr-code.js | safe | The file contains only a static SVG icon definition using lit's svg template tag with no executable code, network calls, or suspicious behavior. |
| dist/esm/src/assets/svg/recycle-horizontal.js | safe | The file contains only a static SVG icon definition with no executable or suspicious code. |
| dist/esm/src/assets/svg/refresh.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/reown-logo.js | safe | No malicious patterns detected; the file only exports a static SVG graphic via lit's svg template. |
| dist/esm/src/assets/svg/search.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/send.js | safe | No malicious patterns detected; the file is a simple SVG template export with no dynamic code, network, file system, or process activity. |
| dist/esm/src/assets/svg/swap-input-mask-bottom.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/swap-input-mask-top.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/swapHorizontal.js | safe | No malicious patterns detected; this file only defines a static SVG icon using lit's svg template tag. |
| dist/esm/src/assets/svg/swapHorizontalBold.js | safe | The file only exports a static SVG template using lit's svg tag, with no dynamic behavior, network access, filesystem operations, or executable code. |
| dist/esm/src/assets/svg/swapHorizontalMedium.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/swapHorizontalRoundedBold.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/swapVertical.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/telegram.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/three-dots.js | safe | No malicious patterns detected; the file only exports a static SVG template using lit's svg tag. |
| dist/esm/src/assets/svg/twitch.js | safe | The file defines a static Lit SVG template for a Twitch icon and contains no network, filesystem, execution, or obfuscation patterns. |
| dist/esm/src/assets/svg/twitterIcon.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/verify-filled.js | safe | No malicious patterns detected |
| dist/esm/src/assets/svg/verify.js | safe | This file contains only a static SVG icon template using lit's svg tag with no executable logic, network calls, or other malicious patterns. |
| dist/esm/src/assets/svg/wallet-placeholder.js | safe | No malicious patterns detected; the file only exports static SVG markup using lit's svg template tag with no executable or suspicious behavior. |
| dist/esm/src/assets/svg/wallet.js | safe | No malicious patterns detected; the file only exports a static SVG template using lit's svg tag with no dynamic behavior or external interactions. |
| dist/esm/src/assets/svg/walletconnect.js | safe | This file contains only static SVG icon definitions using lit's svg template tag, with no executable logic, network calls, or suspicious patterns. |
| dist/esm/src/assets/svg/warning-circle.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/assets/svg/x.js | safe | No malicious patterns detected |
| dist/esm/src/assets/visual/bitcoin.js | safe | This file only exports a static Bitcoin SVG icon using lit's svg template tag; no malicious patterns, dynamic code execution, network requests, or filesystem access were found. |
| dist/esm/src/assets/visual/browser.js | safe | The file contains only a static SVG template literal using lit's svg tag with no executable, network, filesystem, or obfuscated code. |
| dist/esm/src/assets/visual/coinbase.js | safe | No malicious patterns detected |
| dist/esm/src/assets/visual/dao.js | safe | This is a static SVG icon definition using lit's svg template tag with no executable code or malicious patterns. |
| dist/esm/src/assets/visual/defi.js | safe | No malicious patterns detected; the file only defines a static SVG icon via lit's svg template tag. |
| dist/esm/src/assets/visual/defiAlt.js | safe | This file only exports a static SVG template using lit's svg tag; it contains no executable logic, network calls, credential access, obfuscation, or other malicious patterns. |
| dist/esm/src/assets/visual/eth.js | safe | No malicious patterns detected; the file only exports a static SVG template for an Ethereum icon. |
| dist/esm/src/assets/visual/google.js | safe | No malicious patterns detected |
| dist/esm/src/assets/visual/layers.js | safe | No malicious patterns detected; this file only exports a static SVG template using lit's svg tag with no executable or network behavior. |
| dist/esm/src/assets/visual/lightbulb.js | safe | The file contains only a static SVG lightbulb icon built with lit's svg template tag; no malicious patterns, network calls, dynamic code execution, or credential access were detected. |
| dist/esm/src/assets/visual/lock.js | safe | The file contains only a static SVG template literal with no executable code, network access, or malicious patterns. |
| dist/esm/src/assets/visual/login.js | safe | The file only exports a static inline SVG template using lit's svg tag with no executable logic, network calls, credential access, or other malicious patterns. |
| dist/esm/src/assets/visual/meld.js | safe | The file contains only a static SVG icon defined via lit's svg template tag, with no executable code, network calls, file system access, or other malicious patterns. |
| dist/esm/src/assets/visual/moonpay.js | safe | No malicious patterns detected |
| dist/esm/src/assets/visual/network.js | safe | The file contains only a static SVG template literal for a UI icon with no executable code, network access, or file system interaction. |
| dist/esm/src/assets/visual/nft.js | safe | The file contains only a static SVG template literal for an NFT icon with no executable, network, filesystem, or dynamic behavior. |
| dist/esm/src/assets/visual/noun.js | safe | No malicious patterns detected |
| dist/esm/src/assets/visual/onramp-card.js | safe | No malicious patterns detected; the file only exports a static SVG template using lit's svg tag. |
| dist/esm/src/assets/visual/paypal.js | safe | No malicious patterns detected; the file only exports a static inline SVG definition for a PayPal icon. |
| dist/esm/src/assets/visual/pencil.js | safe | No malicious patterns detected |
| dist/esm/src/assets/visual/profile.js | safe | No malicious patterns detected; the file only exports a static SVG template using lit's svg tag. |
| dist/esm/src/assets/visual/solana.js | safe | No malicious patterns detected; the file only exports a static SVG template for the Solana logo. |
| dist/esm/src/assets/visual/stripe.js | safe | This file only exports a static SVG icon template using lit's svg tag with no executable logic or security concerns. |
| dist/esm/src/assets/visual/system.js | safe | No malicious patterns detected |
| dist/esm/src/components/wui-card/index.js | safe | The file is a standard LitElement web component definition with no malicious patterns, network calls, file system access, or dynamic code execution. |
| dist/esm/src/components/wui-card/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-icon/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for lazy-loading SVG icons with caching. |
| dist/esm/src/components/wui-icon/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-image/index.js | safe | No malicious patterns detected; this is a standard Lit web component for rendering an image with no network, filesystem, or process operations. |
| dist/esm/src/components/wui-image/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-loading-hexagon/index.js | safe | No malicious patterns detected; the file is a standard LitElement web component that renders an SVG loading spinner. |
| dist/esm/src/components/wui-loading-hexagon/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-loading-spinner/index.js | safe | No malicious patterns detected; this is a standard Lit web component for rendering a loading spinner. |
| dist/esm/src/components/wui-loading-spinner/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-loading-thumbnail/index.js | safe | No malicious patterns detected; the file defines a standard Lit web component for rendering an SVG loading thumbnail with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/src/components/wui-loading-thumbnail/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-shimmer/index.js | safe | No malicious patterns detected |
| dist/esm/src/components/wui-shimmer/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-text/index.js | safe | No malicious patterns detected |
| dist/esm/src/components/wui-text/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/components/wui-visual/index.js | safe | This is a standard Lit web component that renders inline SVG icons and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity. |
| dist/esm/src/components/wui-visual/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-account-button/index.js | safe | No malicious patterns detected; the file is a standard Lit web component for rendering an account button with imported UI utilities and no exfiltration, obfuscation, or system-level access. |
| dist/esm/src/composites/wui-account-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-alertbar/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for an alert bar with no network, filesystem, or process manipulation. |
| dist/esm/src/composites/wui-alertbar/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-all-wallets-image/index.js | safe | No malicious patterns detected; the file is a standard Lit web component rendering wallet images without any suspicious behavior. |
| dist/esm/src/composites/wui-all-wallets-image/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-avatar/index.js | safe | No malicious patterns detected; the code is a standard LitElement-based avatar web component with no network, filesystem, or dynamic execution concerns. |
| dist/esm/src/composites/wui-avatar/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-balance/index.js | safe | No malicious patterns detected; this is a benign LitElement web component for rendering a balance display. |
| dist/esm/src/composites/wui-balance/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-banner-img/index.js | safe | No malicious patterns detected; this is a benign Lit web component that renders a banner image and text. |
| dist/esm/src/composites/wui-banner-img/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-banner/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for rendering a banner UI with no network, filesystem, or dynamic execution activity. |
| dist/esm/src/composites/wui-banner/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-button/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-card-select-loader/index.js | safe | No malicious patterns detected; this is a benign Lit-based UI loading shimmer component. |
| dist/esm/src/composites/wui-card-select-loader/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-card-select/index.js | safe | This is a standard Lit web component for rendering a selectable card UI; no malicious patterns, network activity, dynamic code execution, or filesystem/process manipulation were detected. |
| dist/esm/src/composites/wui-card-select/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-certified-switch/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for a certified switch UI element with no data exfiltration, obfuscation, dynamic execution, or network/file system access. |
| dist/esm/src/composites/wui-certified-switch/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-checkbox/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-checkbox/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-chip-button/index.js | safe | No malicious patterns detected; this is a standard Lit web component chip button with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/src/composites/wui-chip-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-chip/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-chip/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-compatible-network/index.js | safe | No malicious patterns detected; this is a standard Lit web component for rendering network icons with no external data access, code execution, or network communication. |
| dist/esm/src/composites/wui-compatible-network/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-connect-button/index.js | safe | No malicious patterns detected; the file is a standard LitElement UI component with no network, filesystem, or process operations. |
| dist/esm/src/composites/wui-connect-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-cta-button/index.js | safe | The file is a standard Lit-based web component definition for a CTA button with no malicious patterns, network activity, credential access, or dynamic code execution. |
| dist/esm/src/composites/wui-cta-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-details-group-item/index.js | safe | This is a standard LitElement web component definition with no network, filesystem, process execution, or obfuscated code present. |
| dist/esm/src/composites/wui-details-group-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-details-group/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-details-group/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-dropdown-menu/index.js | safe | No malicious patterns detected; the file is a standard Lit web component implementation. |
| dist/esm/src/composites/wui-dropdown-menu/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-email-input/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-email-input/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-ens-input/index.js | safe | The file is a benign Lit web component for ENS input rendering with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/src/composites/wui-ens-input/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-icon-box/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-icon-box/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-icon-button/index.js | safe | No malicious patterns detected in the provided LitElement component source code. |
| dist/esm/src/composites/wui-icon-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-icon-link/index.js | safe | This is a standard Lit web component for rendering an icon link button with no malicious patterns, network calls, or dynamic code execution. |
| dist/esm/src/composites/wui-icon-link/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-input-amount/index.js | safe | No malicious patterns detected; the code is a standard LitElement web component for numeric input handling without any network, filesystem, or code execution concerns. |
| dist/esm/src/composites/wui-input-amount/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-input-element/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-input-element/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-input-numeric/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for numeric input with no network, filesystem, or dynamic execution concerns. |
| dist/esm/src/composites/wui-input-numeric/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-input-text/index.js | safe | This is a standard LitElement-based web component for a text input field with no malicious patterns, network calls, file system access, or dynamic code execution. |
| dist/esm/src/composites/wui-input-text/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-link/index.js | safe | The file is a standard Lit-based web component for a link button with no network, filesystem, process, or obfuscation activity. |
| dist/esm/src/composites/wui-link/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-accordion/index.js | safe | No malicious patterns detected; this is a standard Lit web component implementing an accordion UI with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/src/composites/wui-list-accordion/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-account/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for displaying account information with no exfiltration, obfuscation, or dangerous operations. |
| dist/esm/src/composites/wui-list-account/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-button/index.js | safe | This is a standard Lit-based web component for rendering a button; no malicious patterns, network calls, or exec/eval usage were found. |
| dist/esm/src/composites/wui-list-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-content/index.js | safe | No malicious patterns detected; this is a standard Lit web component for rendering list content with image/text/icon. |
| dist/esm/src/composites/wui-list-content/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-description/index.js | safe | No malicious patterns detected; this is a standard Lit web component for rendering a list description with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/src/composites/wui-list-description/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-item/index.js | safe | No malicious patterns detected; the file is a standard Lit-based UI list-item web component with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/src/composites/wui-list-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-network/index.js | safe | No malicious patterns detected; the file is a standard LitElement web component for rendering a network list item. |
| dist/esm/src/composites/wui-list-network/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-social/index.js | safe | This is a standard LitElement web component for rendering a social login list item with no malicious patterns, network activity, or dynamic code execution. |
| dist/esm/src/composites/wui-list-social/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-token/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-list-token/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-wallet-transaction/index.js | safe | No malicious patterns detected; this is a LitElement web component for displaying wallet transaction details with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/src/composites/wui-list-wallet-transaction/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-list-wallet/index.js | safe | This is a standard Lit web component for rendering a wallet list item with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist/esm/src/composites/wui-list-wallet/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-logo-select/index.js | safe | No malicious patterns detected; the file is a standard LitElement web component with no network, filesystem, or dynamic execution behavior. |
| dist/esm/src/composites/wui-logo-select/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-logo/index.js | safe | No malicious patterns detected; the file is a standard LitElement web component definition with no external data access, process execution, or obfuscation. |
| dist/esm/src/composites/wui-logo/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-network-button/index.js | safe | This is a standard LitElement web component for rendering a network button with no malicious patterns, external network calls, credential access, or dynamic code execution. |
| dist/esm/src/composites/wui-network-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-network-image/index.js | safe | This is a legitimate Lit-based web component for displaying network images; no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution were detected. |
| dist/esm/src/composites/wui-network-image/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-notice-card/index.js | safe | This is a standard Lit web component definition with no network, filesystem, process, or dynamic code execution patterns. |
| dist/esm/src/composites/wui-notice-card/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-otp/index.js | safe | No malicious patterns detected; the code is a standard Lit-based OTP input component with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/src/composites/wui-otp/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-preview-item/index.js | safe | No malicious patterns detected; this is a standard LitElement web component for rendering preview items. |
| dist/esm/src/composites/wui-preview-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-profile-button-v2/index.js | safe | No malicious patterns detected; this is a standard Lit web component for a profile button with no network, filesystem, process, or dynamic execution behavior. |
| dist/esm/src/composites/wui-profile-button-v2/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-profile-button/index.js | safe | No malicious patterns detected; the file is a legitimate LitElement UI component with no network exfiltration, credential harvesting, dynamic code execution, process spawning, or install-time behavior. |
| dist/esm/src/composites/wui-profile-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-promo/index.js | safe | This is a benign Lit-based web component definition with no network, filesystem, process, or dynamic code execution activity. |
| dist/esm/src/composites/wui-promo/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-qr-code/index.js | safe | No malicious patterns detected; the file is a standard LitElement component for QR code rendering with no suspicious behavior. |
| dist/esm/src/composites/wui-qr-code/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-search-bar/index.js | safe | No malicious patterns detected; this is a standard LitElement UI search bar component with no exfiltration, dynamic execution, or suspicious behavior. |
| dist/esm/src/composites/wui-search-bar/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-select/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-select/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-snackbar/index.js | safe | The file is a standard Lit web component definition for a UI snackbar with no network, filesystem, process, or dynamic code execution behavior. |
| dist/esm/src/composites/wui-snackbar/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-switch/index.js | safe | No malicious patterns detected; the file is a standard Lit web component switch implementation with no network, filesystem, credential, or dynamic code execution behavior. |
| dist/esm/src/composites/wui-switch/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-tabs/index.js | safe | No malicious patterns detected; the file is a benign Lit web component for tabs with no network, filesystem, process execution, or obfuscated code. |
| dist/esm/src/composites/wui-tabs/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-tag/index.js | safe | No malicious patterns detected; the code is a benign Lit web component definition for a UI tag element with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/src/composites/wui-tag/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-token-button/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-token-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-token-list-item/index.js | safe | No malicious patterns detected; the code is a standard Lit-based Web Component for rendering token list items with lazy loading via IntersectionObserver and no network, filesystem, or process activity. |
| dist/esm/src/composites/wui-token-list-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-tooltip/index.js | safe | This is a standard LitElement-based tooltip web component with no malicious patterns, no network calls, no dynamic code execution, and no sensitive data access. |
| dist/esm/src/composites/wui-tooltip/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-transaction-list-item-loader/index.js | safe | This is a benign LitElement web component that renders skeleton loading placeholders with no network, credential, process, or dynamic execution behavior. |
| dist/esm/src/composites/wui-transaction-list-item-loader/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-transaction-list-item/index.js | safe | This is a standard LitElement web component for rendering transaction list items with no malicious patterns, network activity, or dynamic code execution. |
| dist/esm/src/composites/wui-transaction-list-item/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-transaction-visual/index.js | safe | No malicious patterns detected; the code is a standard Lit web component for rendering transaction visuals with no network, filesystem, or dynamic execution behavior. |
| dist/esm/src/composites/wui-transaction-visual/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-ux-by-reown/index.js | safe | No malicious patterns detected; the code is a benign LitElement web component that renders a Reown branding link. |
| dist/esm/src/composites/wui-ux-by-reown/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-visual-thumbnail/index.js | safe | No malicious patterns detected |
| dist/esm/src/composites/wui-visual-thumbnail/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-wallet-button/index.js | safe | This is a standard Lit-based UI component for a wallet button with no malicious patterns, external network calls, dynamic code execution, or credential harvesting. |
| dist/esm/src/composites/wui-wallet-button/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/composites/wui-wallet-image/index.js | safe | The file is a standard Lit web component for rendering wallet images with no malicious patterns, network calls, file system access, or dynamic code execution. |
| dist/esm/src/composites/wui-wallet-image/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/layout/wui-flex/index.js | safe | No malicious patterns detected; this is a standard Lit web component for flexible layout with only CSS style bindings from component properties. |
| dist/esm/src/layout/wui-flex/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/layout/wui-grid/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/layout/wui-separator/index.js | safe | No malicious patterns detected; the code is a standard LitElement web component for rendering a separator with optional text. |
| dist/esm/src/layout/wui-separator/styles.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/CacheUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/ConstantsUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/JSXTypeUtil.js | safe | The file is an empty module export stub with only a source map comment, containing no executable code or malicious patterns. |
| dist/esm/src/utils/MathUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/QrCode.js | safe | No malicious patterns detected; the code only generates SVG QR codes using the qrcode library and lit templating with no network, filesystem, process, or dynamic execution activity. |
| dist/esm/src/utils/TransactionUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/TypeUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/UiHelperUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/WebComponentsUtil.js | safe | No malicious patterns detected; the code only provides standard custom element definition utilities. |
Scanned versions of @reown/appkit-ui
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.7.8 | Needs review | 355 | Oct 4, 2026 |
Frequently asked questions
Is @reown/appkit-ui safe to use?
No confirmed malware was found in @reown/appkit-ui@1.7.8, but the review flagged 3 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @reown/appkit-ui contain malware?
No malware was identified in @reown/appkit-ui@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @reown/appkit-ui checked?
Togoder Security downloaded the published npm package and had an AI model read its 355 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @reown/appkit-ui together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-ui@1.7.8, cost nothing.