Summary
Togoder Security scanned the npm package @solana/wallet-standard-features@1.3.0 on Oct 4, 2026. An AI review of 18 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/cjs/index.js | safe | No malicious patterns detected; the file contains standard TypeScript/CommonJS re-export boilerplate. |
| lib/cjs/signAndSendAllTransactions.js | safe | The file only exports a string constant for a Solana wallet feature name and contains no malicious patterns, network calls, or executable logic. |
| lib/cjs/signAndSendTransaction.js | safe | This file only exports a constant string identifier for a Solana wallet feature and contains no executable code or malicious patterns. |
| lib/cjs/signIn.js | safe | No malicious patterns detected |
| lib/cjs/signMessage.js | safe | No malicious patterns detected in the provided JavaScript file. |
| lib/cjs/signTransaction.js | safe | This is a minimal type/constant definition file exporting a feature name string with no executable logic or malicious patterns. |
| lib/esm/index.js | safe | The file is a simple re-export barrel file with no executable code, no suspicious imports, and no malicious patterns. |
| lib/esm/signAndSendAllTransactions.js | safe | No malicious patterns detected; the file only exports a constant string identifier with a source map reference. |
| lib/esm/signAndSendTransaction.js | safe | No malicious patterns detected |
| lib/esm/signIn.js | safe | No malicious patterns detected |
| lib/esm/signMessage.js | safe | No malicious patterns detected |
| lib/esm/signTransaction.js | safe | The file only exports a constant string and contains a source map reference, with no malicious patterns detected. |
| src/index.ts | safe | No malicious patterns detected |
| src/signAndSendAllTransactions.ts | safe | No malicious patterns detected; the file only defines TypeScript types and constants for a Solana wallet feature. |
| src/signAndSendTransaction.ts | safe | The file only contains TypeScript type definitions and constants for the Solana wallet-standard signAndSendTransaction feature, with no executable code, side effects, or malicious patterns. |
| src/signIn.ts | safe | This is a type-definition-only file for Solana Sign In; it contains no executable code, network calls, file system access, or other malicious patterns. |
| src/signMessage.ts | safe | No malicious patterns detected |
| src/signTransaction.ts | safe | No malicious patterns detected |
Frequently asked questions
Is @solana/wallet-standard-features safe to use?
Our AI source review of @solana/wallet-standard-features@1.3.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @solana/wallet-standard-features contain malware?
No malware was identified in @solana/wallet-standard-features@1.3.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @solana/wallet-standard-features checked?
Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @solana/wallet-standard-features together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @solana/wallet-standard-features@1.3.0, cost nothing.