# @reown/appkit-ui@1.7.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:15:57.000Z
- Files reviewed: 355
- Findings: 3 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@reown/appkit-ui
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @reown/appkit-ui@1.7.8 on Oct 4, 2026. An AI review of 355 source files produced 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unsanitized CSS injection via component properties

Finding ID: `NPS-6AE61A8BD00E`

File: `dist/esm/src/layout/wui-grid/index.js:13`

All grid-related properties (gridTemplateRows, gridTemplateColumns, justifyItems, alignItems, justifyContent, alignContent, columnGap, rowGap, gap, padding, margin) are bound to LitElement @property() decorators without validation or sanitization. In render(), their raw values are interpolated directly into this.style.cssText. An application that sets these attributes (including from user-controlled or API-controlled data) could inject arbitrary CSS, enabling UI redressing, data exfiltration via CSS (e.g. attribute/selector-based leaks), or style-based attacks.

### [medium] Dynamic DOM injection without sanitization

Finding ID: `NPS-540685951595`

File: `dist/esm/src/utils/ThemeUtil.js:8`

initializeTheming and setThemeVariables create <style> elements and assign untrusted themeVariables into their textContent. No validation/sanitization of themeVariables keys or values is performed before writing to the DOM. If attacker-controlled theme variables are ever supplied (e.g., via dApp config, URL, or cross-window messaging), arbitrary CSS can be injected globally.

### [medium] Unsafe CSS injection via unsafeCSS()

Finding ID: `NPS-981095B93DCE`

File: `dist/esm/src/utils/ThemeUtil.js:42`

The code uses Lit's unsafeCSS() to interpolate user-supplied theme variables directly into CSS. If themeVariables originate from an untrusted source (e.g., URL parameters, postMessage, or remote config), an attacker could inject arbitrary CSS, enabling UI redressing, data exfiltration via CSS selectors/attribute leakage, or style-based attacks. The variables --w3m-color-mix-strength, --w3m-font-family, --w3m-accent, and --w3m-background are passed through without sanitization.

### [low] External resource loading at runtime

Finding ID: `NPS-752A44D62A4C`

File: `dist/esm/src/utils/ThemeUtil.js:36`

The generated styles include an @import url('https://fonts.googleapis.com/css2?family=Inter...') directive that causes the browser to fetch a stylesheet from an external Google Fonts domain when the styles are applied. This is a third-party network dependency embedded in the library, which can leak user IP/user-agent to Google and creates a dependency on an external service. While common, it is a privacy/security consideration in a security-sensitive wallet UI package.

## Files reviewed

- `dist/esm/src/layout/wui-grid/index.js` (medium): The widget is a normal Lit web component but interpolates unvalidated property values into inline CSS, creating a CSS injection risk if those values are attacker-influenced; no network, filesystem, process, or obfuscated malicious behavior is present.
- `dist/esm/src/utils/ThemeUtil.js` (medium): No direct malicious behavior, but the module unsafely interpolates potentially untrusted theme variables into global CSS via unsafeCSS(), which could enable CSS injection attacks if theme variables are attacker-controllable.
- `dist/esm/exports/index.js` (safe): This file only re-exports symbols from internal utility modules with no suspicious or malicious patterns.
- `dist/esm/exports/jsx.js` (safe): The file only re-exports utilities from an internal JSX type module and references a source map, with no malicious patterns detected.
- `dist/esm/exports/wui-account-button.js` (safe): This is a simple re-export module that delegates to a relative source file, containing no suspicious or malicious patterns.
- `dist/esm/exports/wui-alertbar.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-all-wallets-image.js` (safe): This file is a simple ES module re-export from an internal source directory with a source map comment, containing no executable code, network calls, credential access, or other malicious patterns.
- `dist/esm/exports/wui-avatar.js` (safe): No malicious patterns detected; the file is a simple ESM re-export with a source map reference.
- `dist/esm/exports/wui-balance.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-banner-img.js` (safe): No malicious patterns detected; the file only re-exports from an internal source module and includes a source map reference.
- `dist/esm/exports/wui-banner.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-button.js` (safe): This is a simple re-export barrel file with no executable logic or suspicious patterns.
- `dist/esm/exports/wui-card-select-loader.js` (safe): This file only re-exports from an internal source directory and contains no malicious patterns or executable code.
- `dist/esm/exports/wui-card-select.js` (safe): The file is a simple ES module re-export with a source map comment and no malicious patterns.
- `dist/esm/exports/wui-card.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-certified-switch.js` (safe): This is a simple re-export file with no suspicious patterns or malicious behavior.
- `dist/esm/exports/wui-checkbox.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-chip-button.js` (safe): This file is a simple ESM re-export of another module and contains no executable code or malicious patterns.
- `dist/esm/exports/wui-chip.js` (safe): The file is a simple re-export barrel module with no executable code or malicious patterns.
- `dist/esm/exports/wui-compatible-network.js` (safe): This is a trivial ES module re-export with a source map reference and no malicious patterns.
- `dist/esm/exports/wui-connect-button.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-cta-button.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-details-group-item.js` (safe): This is a simple re-export barrel file with no executable or malicious patterns.
- `dist/esm/exports/wui-details-group.js` (safe): This file is a simple ES module re-export with no executable code or suspicious patterns.
- `dist/esm/exports/wui-dropdown-menu.js` (safe): This file is a simple ESM re-export of an internal module with no executable code or malicious patterns.
- `dist/esm/exports/wui-email-input.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-ens-input.js` (safe): This file is a simple re-export barrel module with no executable code, network calls, or suspicious patterns.
- `dist/esm/exports/wui-flex.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-grid.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-icon-box.js` (safe): The file is a simple ESM re-export of an internal module with no malicious patterns or suspicious code.
- `dist/esm/exports/wui-icon-button.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-icon-link.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-icon.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-image.js` (safe): The file is a simple ESM re-export with no executable logic or malicious patterns
- `dist/esm/exports/wui-input-amount.js` (safe): This file is a simple re-export module with no executable logic, external requests, or malicious patterns.
- `dist/esm/exports/wui-input-element.js` (safe): This is a simple re-export barrel file that has no executable code, network requests, or suspicious patterns.
- `dist/esm/exports/wui-input-numeric.js` (safe): This file is a simple re-export of an internal module and contains no malicious patterns or security concerns.
- `dist/esm/exports/wui-input-text.js` (safe): Simple re-export barrel file with no executable code or suspicious patterns.
- `dist/esm/exports/wui-link.js` (safe): This file is a simple ESM re-export from an internal source module with no executable logic, network access, or suspicious patterns.
- `dist/esm/exports/wui-list-accordion.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-list-account.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-list-button.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-list-content.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-list-description.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-list-item.js` (safe): This file is a simple re-export barrel module with no executable code or malicious patterns.
- `dist/esm/exports/wui-list-network.js` (safe): No malicious patterns detected; the file is a simple re-export from the package's internal source directory.
- `dist/esm/exports/wui-list-social.js` (safe): This file is a simple ESM re-export of a local module path with a source map comment, containing no executable code or malicious patterns.
- `dist/esm/exports/wui-list-token.js` (safe): This file is a simple re-export of a source module with no executable code, network access, or suspicious patterns.
- `dist/esm/exports/wui-list-wallet-transaction.js` (safe): The file is a simple ESM re-export of a sibling module with a source map comment and contains no malicious patterns, dynamic execution, or external I/O.
- `dist/esm/exports/wui-list-wallet.js` (safe): The file only re-exports from a local module with no malicious patterns detected.
- `dist/esm/exports/wui-loading-hexagon.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-loading-spinner.js` (safe): No malicious patterns detected; the file is a simple ESM re-export with a source map reference.
- `dist/esm/exports/wui-loading-thumbnail.js` (safe): The file is a simple re-export module with no executable code or malicious patterns.
- `dist/esm/exports/wui-logo-select.js` (safe): This is a simple re-export barrel file with no executable code, network activity, or suspicious patterns.
- `dist/esm/exports/wui-logo.js` (safe): This is a simple re-export barrel file that only re-exports from an internal source module with no malicious patterns.
- `dist/esm/exports/wui-network-button.js` (safe): The file is a simple ESM re-export with a source map reference, containing no malicious patterns or dynamic execution.
- `dist/esm/exports/wui-network-image.js` (safe): The file is a simple ESM re-export with a source map reference and contains no malicious patterns or suspicious behavior.
- `dist/esm/exports/wui-notice-card.js` (safe): The file is a simple re-export barrel module with a source map reference and contains no malicious patterns.
- `dist/esm/exports/wui-otp.js` (safe): No malicious patterns detected; the file is a simple ES module re-export with a source map reference.
- `dist/esm/exports/wui-preview-item.js` (safe): This file is a simple re-export module with no executable logic or malicious patterns.
- `dist/esm/exports/wui-profile-button-v2.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-profile-button.js` (safe): No malicious patterns detected; the file is a simple re-export with an inline source map reference.
- `dist/esm/exports/wui-promo.js` (safe): This is a simple re-export module with no malicious patterns, network activity, or dynamic code execution.
- `dist/esm/exports/wui-qr-code.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-search-bar.js` (safe): This file is a simple re-export barrel module with no executable logic, network calls, or suspicious patterns.
- `dist/esm/exports/wui-select.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-separator.js` (safe): This is a simple ESM re-export file with no executable logic, external calls, or suspicious patterns.
- `dist/esm/exports/wui-shimmer.js` (safe): No malicious patterns detected; the file is a simple ESM re-export of an internal component module.
- `dist/esm/exports/wui-snackbar.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-switch.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-tabs.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-tag.js` (safe): The file only re-exports from an internal module path and contains no malicious patterns, network activity, or dynamic code execution.
- `dist/esm/exports/wui-text.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-token-button.js` (safe): The file only re-exports from an internal composite module with no malicious patterns, network calls, process execution, or obfuscation.
- `dist/esm/exports/wui-token-list-item.js` (safe): No malicious patterns detected; this file only re-exports from an internal module path with no dynamic imports, network calls, or execution logic.
- `dist/esm/exports/wui-tooltip.js` (safe): This file is a simple re-export module with no executable code, suspicious patterns, or security concerns.
- `dist/esm/exports/wui-transaction-list-item-loader.js` (safe): The file contains only a static re-export statement and a source map comment, with no malicious patterns detected.
- `dist/esm/exports/wui-transaction-list-item.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-transaction-visual.js` (safe): This file is a simple ESM re-export that only forwards exports from an internal module and contains no malicious patterns or executable code.
- `dist/esm/exports/wui-ux-by-reown.js` (safe): This file is a simple ES module re-export with no executable code, network access, or malicious patterns.
- `dist/esm/exports/wui-visual-thumbnail.js` (safe): This file is a simple re-export shim that only forwards exports from an internal source file, with no executable, obfuscated, or network-related code.
- `dist/esm/exports/wui-visual.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-wallet-button.js` (safe): No malicious patterns detected
- `dist/esm/exports/wui-wallet-image.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/add.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/all-wallets.js` (safe): The file contains only a static, inert SVG icon definition for a web component, with no network, file system, process execution, obfuscation, or install-time behavior.
- `dist/esm/src/assets/svg/app-store.js` (safe): No malicious patterns detected; the file only exports a static SVG template for an App Store icon using lit's svg tag.
- `dist/esm/src/assets/svg/apple.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/arrow-bottom-circle.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/arrow-bottom.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/arrow-left.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/arrow-right.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/arrow-top.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/bank.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/browser.js` (safe): This file only defines a static SVG Lit template with no executable logic, imports, network activity, or suspicious patterns.
- `dist/esm/src/assets/svg/card.js` (safe): The file only exports a static SVG template using Lit's svg tag, with no dynamic code execution, network calls, filesystem access, or other malicious patterns.
- `dist/esm/src/assets/svg/checkmark-bold.js` (safe): No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
- `dist/esm/src/assets/svg/checkmark.js` (safe): The file only exports a static SVG template literal using lit's svg tag; no network, filesystem, process, credential, or dynamic execution behavior is present.
- `dist/esm/src/assets/svg/chevron-bottom.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/chevron-left.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/chevron-right.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/chevron-top.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/chrome-store.js` (safe): This file only exports a static SVG icon using lit's svg template literal tag; it contains no executable logic, network requests, filesystem access, or other malicious patterns.
- `dist/esm/src/assets/svg/clock.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/close.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/coinPlaceholder.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/compass.js` (safe): The file only defines a static SVG icon using lit's svg template tag with no executable, network, filesystem, or dynamic code patterns.
- `dist/esm/src/assets/svg/copy.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/cursor-transparent.js` (safe): This file only defines a static SVG template using lit's svg tag with no executable, network, filesystem, or credential-related behavior.
- `dist/esm/src/assets/svg/cursor.js` (safe): This file only exports a static SVG template literal with no executable, network, filesystem, or process-related code.
- `dist/esm/src/assets/svg/desktop.js` (safe): This file only exports a static SVG template using Lit's svg tag; it contains no executable logic, network activity, file access, or other malicious patterns.
- `dist/esm/src/assets/svg/disconnect.js` (safe): No malicious patterns detected; the file only exports a static SVG icon definition using lit's svg template literal.
- `dist/esm/src/assets/svg/discord.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/etherscan.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/exclamation-triangle.js` (safe): No malicious patterns detected; the file only exports a static SVG icon definition using the 'lit' svg template tag.
- `dist/esm/src/assets/svg/extension.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/external-link.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/facebook.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/farcaster.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/filters.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/github.js` (safe): No malicious patterns detected; this file only exports a static GitHub SVG icon using lit's svg template tag.
- `dist/esm/src/assets/svg/google.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/help-circle.js` (safe): This file is a benign SVG icon definition using Lit's svg template tag with no executable or suspicious code.
- `dist/esm/src/assets/svg/id.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/image.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/info-circle.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/info.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/lightbulb.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/mail.js` (safe): The file contains only a static SVG template literal for a mail icon with no executable logic or malicious patterns.
- `dist/esm/src/assets/svg/mobile.js` (safe): The file contains only a static SVG template literal for a mobile icon with no executable, network, filesystem, or obfuscated malicious behavior.
- `dist/esm/src/assets/svg/more.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/network-placeholder.js` (safe): No malicious patterns detected; the file only exports a static SVG icon definition using lit's svg template tag.
- `dist/esm/src/assets/svg/networkLg.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/networkMd.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/networkSm.js` (safe): No malicious patterns detected; the file only defines a static SVG template using lit's svg tag.
- `dist/esm/src/assets/svg/nftPlaceholder.js` (safe): No malicious patterns detected; the file only exports a static SVG template using lit's svg tagged template literal.
- `dist/esm/src/assets/svg/off.js` (safe): No malicious patterns detected; the file only exports a static SVG icon template for lit.
- `dist/esm/src/assets/svg/play-store.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/plus.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/qr-code.js` (safe): The file contains only a static SVG icon definition using lit's svg template tag with no executable code, network calls, or suspicious behavior.
- `dist/esm/src/assets/svg/recycle-horizontal.js` (safe): The file contains only a static SVG icon definition with no executable or suspicious code.
- `dist/esm/src/assets/svg/refresh.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/reown-logo.js` (safe): No malicious patterns detected; the file only exports a static SVG graphic via lit's svg template.
- `dist/esm/src/assets/svg/search.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/send.js` (safe): No malicious patterns detected; the file is a simple SVG template export with no dynamic code, network, file system, or process activity.
- `dist/esm/src/assets/svg/swap-input-mask-bottom.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/swap-input-mask-top.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/swapHorizontal.js` (safe): No malicious patterns detected; this file only defines a static SVG icon using lit's svg template tag.
- `dist/esm/src/assets/svg/swapHorizontalBold.js` (safe): The file only exports a static SVG template using lit's svg tag, with no dynamic behavior, network access, filesystem operations, or executable code.
- `dist/esm/src/assets/svg/swapHorizontalMedium.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/swapHorizontalRoundedBold.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/swapVertical.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/telegram.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/three-dots.js` (safe): No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
- `dist/esm/src/assets/svg/twitch.js` (safe): The file defines a static Lit SVG template for a Twitch icon and contains no network, filesystem, execution, or obfuscation patterns.
- `dist/esm/src/assets/svg/twitterIcon.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/verify-filled.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/svg/verify.js` (safe): This file contains only a static SVG icon template using lit's svg tag with no executable logic, network calls, or other malicious patterns.
- `dist/esm/src/assets/svg/wallet-placeholder.js` (safe): No malicious patterns detected; the file only exports static SVG markup using lit's svg template tag with no executable or suspicious behavior.
- `dist/esm/src/assets/svg/wallet.js` (safe): No malicious patterns detected; the file only exports a static SVG template using lit's svg tag with no dynamic behavior or external interactions.
- `dist/esm/src/assets/svg/walletconnect.js` (safe): This file contains only static SVG icon definitions using lit's svg template tag, with no executable logic, network calls, or suspicious patterns.
- `dist/esm/src/assets/svg/warning-circle.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/assets/svg/x.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/visual/bitcoin.js` (safe): This file only exports a static Bitcoin SVG icon using lit's svg template tag; no malicious patterns, dynamic code execution, network requests, or filesystem access were found.
- `dist/esm/src/assets/visual/browser.js` (safe): The file contains only a static SVG template literal using lit's svg tag with no executable, network, filesystem, or obfuscated code.
- `dist/esm/src/assets/visual/coinbase.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/visual/dao.js` (safe): This is a static SVG icon definition using lit's svg template tag with no executable code or malicious patterns.
- `dist/esm/src/assets/visual/defi.js` (safe): No malicious patterns detected; the file only defines a static SVG icon via lit's svg template tag.
- `dist/esm/src/assets/visual/defiAlt.js` (safe): This file only exports a static SVG template using lit's svg tag; it contains no executable logic, network calls, credential access, obfuscation, or other malicious patterns.
- `dist/esm/src/assets/visual/eth.js` (safe): No malicious patterns detected; the file only exports a static SVG template for an Ethereum icon.
- `dist/esm/src/assets/visual/google.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/visual/layers.js` (safe): No malicious patterns detected; this file only exports a static SVG template using lit's svg tag with no executable or network behavior.
- `dist/esm/src/assets/visual/lightbulb.js` (safe): The file contains only a static SVG lightbulb icon built with lit's svg template tag; no malicious patterns, network calls, dynamic code execution, or credential access were detected.
- `dist/esm/src/assets/visual/lock.js` (safe): The file contains only a static SVG template literal with no executable code, network access, or malicious patterns.
- `dist/esm/src/assets/visual/login.js` (safe): The file only exports a static inline SVG template using lit's svg tag with no executable logic, network calls, credential access, or other malicious patterns.
- `dist/esm/src/assets/visual/meld.js` (safe): The file contains only a static SVG icon defined via lit's svg template tag, with no executable code, network calls, file system access, or other malicious patterns.
- `dist/esm/src/assets/visual/moonpay.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/visual/network.js` (safe): The file contains only a static SVG template literal for a UI icon with no executable code, network access, or file system interaction.
- `dist/esm/src/assets/visual/nft.js` (safe): The file contains only a static SVG template literal for an NFT icon with no executable, network, filesystem, or dynamic behavior.
- `dist/esm/src/assets/visual/noun.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/visual/onramp-card.js` (safe): No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
- `dist/esm/src/assets/visual/paypal.js` (safe): No malicious patterns detected; the file only exports a static inline SVG definition for a PayPal icon.
- `dist/esm/src/assets/visual/pencil.js` (safe): No malicious patterns detected
- `dist/esm/src/assets/visual/profile.js` (safe): No malicious patterns detected; the file only exports a static SVG template using lit's svg tag.
- `dist/esm/src/assets/visual/solana.js` (safe): No malicious patterns detected; the file only exports a static SVG template for the Solana logo.
- `dist/esm/src/assets/visual/stripe.js` (safe): This file only exports a static SVG icon template using lit's svg tag with no executable logic or security concerns.
- `dist/esm/src/assets/visual/system.js` (safe): No malicious patterns detected
- `dist/esm/src/components/wui-card/index.js` (safe): The file is a standard LitElement web component definition with no malicious patterns, network calls, file system access, or dynamic code execution.
- `dist/esm/src/components/wui-card/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/components/wui-icon/index.js` (safe): No malicious patterns detected; the code is a standard Lit web component for lazy-loading SVG icons with caching.
- `dist/esm/src/components/wui-icon/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/components/wui-image/index.js` (safe): No malicious patterns detected; this is a standard Lit web component for rendering an image with no network, filesystem, or process operations.
- `dist/esm/src/components/wui-image/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/components/wui-loading-hexagon/index.js` (safe): No malicious patterns detected; the file is a standard LitElement web component that renders an SVG loading spinner.
- `dist/esm/src/components/wui-loading-hexagon/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/components/wui-loading-spinner/index.js` (safe): No malicious patterns detected; this is a standard Lit web component for rendering a loading spinner.
- `dist/esm/src/components/wui-loading-spinner/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/components/wui-loading-thumbnail/index.js` (safe): No malicious patterns detected; the file defines a standard Lit web component for rendering an SVG loading thumbnail with no network, filesystem, process, or dynamic execution behavior.
- `dist/esm/src/components/wui-loading-thumbnail/styles.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/components/wui-shimmer/index.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
