Togoder security

npm package security report

@wagmi/core npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.22.1 Files reviewed 326 Size 590.7 KB Scanned

Summary

Togoder Security scanned the npm package @wagmi/core@2.22.1 on Oct 4, 2026. An AI review of 326 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
6
low

Findings 8

medium

Suspicious network requests

NPS-2767A4A8D258

The mock connector makes real HTTP RPC requests to the chain's default RPC URL using rpc.http(url, ...) when handling wallet_sendCalls and wallet_getCallsStatus. While this is intended to simulate transaction submission and receipt retrieval for the mock connector, it means that calls to these methods will actually broadcast transactions to a live RPC endpoint if the default chain URL points to production infrastructure. This is unexpected behavior for a 'mock' connector and could lead to real on-chain transactions and unintended fund movement during testing.

dist/esm/connectors/mock.js
medium

Weak Randomness for Identifier Generation

NPS-C10BE1F4762F

The uid() function uses Math.random() to generate identifiers. Math.random() is not cryptographically secure and is predictable, which is unsuitable for security-sensitive uses such as tokens, session IDs, CSRF nonces, or password reset links. If this utility is used for such purposes, it could allow attackers to predict or brute-force generated values. This is a code-quality/security weakness rather than an active malicious pattern.

src/utils/uid.ts:10
low

deprecated API usage

NPS-CDAFBEE10460

The getToken function is marked as deprecated but does not introduce security risks.

dist/esm/actions/getToken.js:4
low

code quality issue

NPS-9F1602FE9276

The condition typeof account === 'object' && account?.type === 'local' checks the wrong variable (should likely be connector). However, this is a logic error, not a security vulnerability. The code does not exhibit any malicious patterns such as data exfiltration, credential harvesting, obfuscation, mining, backdoors, suspicious network requests, file system manipulation, process spawning, or dynamic imports with external input.

dist/esm/actions/writeContract.js:10
low

Hardcoded address allowlist

NPS-3670BB82DE8C

The wallet_getCapabilities handler hardcodes a specific checksummed Ethereum address (0x95132632579b073D12a6673e18Ab05777a6B86f8) and returns paymaster support only for that address. This is likely a test fixture rather than a malicious backdoor, but it is an unusual hardcoded credential-like value embedded in production code.

dist/esm/connectors/mock.js
low

Top-level code execution

NPS-C04AE3F285FA

The module executes mock.type = 'mock' at top-level import time. This is a benign property assignment and does not introduce a security risk, included here for completeness of top-level execution analysis.

dist/esm/connectors/mock.js
low

Mock Connector Simulating Wallet Behavior

NPS-12381625EB78

This file is explicitly a mock connector for a wallet library (viem). It simulates wallet RPC methods such as eth_requestAccounts, eth_signTypedData_v4, personal_sign, wallet_sendCalls, etc. While it contains network requests (rpc.http) and handles account data, these are expected for a connector mock used in testing. No exfiltration to hardcoded external servers, no credential harvesting, no obfuscation or dynamic code execution, and no suspicious processes were observed. The code appears to be legitimate testing infrastructure. However, the mock's behavior of forwarding transactions and signing operations could be misused if imported in production unexpectedly; it should remain strictly a test utility.

src/connectors/mock.ts
low

cookie security

NPS-BA7BCF88AAAE

Cookies are set without the 'secure' flag and only with 'samesite=Lax'. This could allow cookie theft over insecure connections (HTTP) via network eavesdropping or XSS. However, it is a common pattern and not inherently malicious.

src/utils/cookie.ts:16

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/connectors/mock.js medium No malicious exfiltration, credential harvesting, obfuscation, backdoors, or process spawning detected, but the mock connector performs live RPC network calls for wallet_sendCalls/wallet_getCallsStatus and contains a hardcoded address allowlist, which warrants a warning.
src/connectors/mock.ts medium This is a benign mock connector for the viem library used for testing wallet interactions, with no malicious patterns detected.
src/utils/uid.ts medium No malicious behavior detected, but the uid() helper relies on non-cryptographic Math.random(), making it unsafe for security-sensitive identifier generation.
dist/esm/actions/call.js safe No malicious patterns detected; code is a simple wrapper around the viem library's call action with no exfiltration, obfuscation, or dangerous operations.
dist/esm/actions/codegen/createReadContract.js safe No malicious patterns detected
dist/esm/actions/codegen/createSimulateContract.js safe No malicious patterns detected; the file is a straightforward contract simulation helper with no network, filesystem, process, or dynamic execution activity.
dist/esm/actions/codegen/createWatchContractEvent.js safe No malicious patterns detected; the code is a benign wrapper for watchContractEvent in a blockchain library.
dist/esm/actions/codegen/createWriteContract.js safe No malicious patterns detected; the file is a standard viem-style helper for creating contract write actions with no network, filesystem, process, or obfuscation concerns.
dist/esm/actions/connect.js safe No malicious patterns detected; the code is a legitimate connector initialization routine for the wagmi library.
dist/esm/actions/deployContract.js safe No malicious patterns detected; this is a standard wagmi wrapper for deploying contracts via viem with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/actions/disconnect.js safe No malicious patterns detected
dist/esm/actions/estimateFeesPerGas.js safe No malicious patterns detected; the code is a straightforward wrapper around viem's estimateFeesPerGas with only unit formatting.
dist/esm/actions/estimateGas.js safe No malicious patterns detected
dist/esm/actions/estimateMaxPriorityFeePerGas.js safe No malicious patterns detected
dist/esm/actions/getAccount.js safe No malicious patterns detected; the code is a straightforward state accessor from Wagmi's getAccount action with no network, filesystem, process, or dynamic execution behavior.
dist/esm/actions/getBalance.js safe No malicious patterns detected; the code is a standard blockchain balance retrieval action with no exfiltration, obfuscation, or credential harvesting.
dist/esm/actions/getBlock.js safe No malicious patterns detected
dist/esm/actions/getBlockNumber.js safe The code is a simple wrapper for a viem action to fetch block numbers, with no malicious patterns, network exfiltration, dynamic code execution, or suspicious behavior.
dist/esm/actions/getBlockTransactionCount.js safe No malicious patterns detected; the file is a thin wrapper around viem's getBlockTransactionCount action with no exfiltration, obfuscation, or process execution.
dist/esm/actions/getBytecode.js safe No malicious patterns detected
dist/esm/actions/getCallsStatus.js safe No malicious patterns detected
dist/esm/actions/getCapabilities.js safe No malicious patterns detected; the file is a straightforward wrapper around viem's getCapabilities action with no exfiltration, dynamic execution, or other red flags.
dist/esm/actions/getChainId.js safe Cleared by Jev triage; no further analysis needed
dist/esm/actions/getChains.js safe Cleared by Jev triage; no further analysis needed
dist/esm/actions/getClient.js safe No malicious patterns detected
Show 301 more files
FileVerdictWhat the reviewer saw
dist/esm/actions/getConnections.js safe No malicious patterns detected
dist/esm/actions/getConnectorClient.js safe No malicious patterns detected; the code is a standard wagmi connector client action with no exfiltration, credential harvesting, dynamic execution, or process spawning.
dist/esm/actions/getConnectors.js safe No malicious patterns detected
dist/esm/actions/getEnsAddress.js safe No malicious patterns detected; the file is a standard wrapper around viem's getEnsAddress action with no exfiltration, code execution, or filesystem access.
dist/esm/actions/getEnsAvatar.js safe No malicious patterns detected; the file is a straightforward wrapper around viem's getEnsAvatar action with no network, filesystem, environment, or dynamic code execution concerns.
dist/esm/actions/getEnsName.js safe No malicious patterns detected; the file is a straightforward wrapper around viem's getEnsName action with no network, filesystem, process, or dynamic code execution concerns.
dist/esm/actions/getEnsResolver.js safe No malicious patterns detected; the code is a standard wagmi action wrapper for viem's getEnsResolver with no exfiltration, dynamic execution, or suspicious behavior.
dist/esm/actions/getEnsText.js safe No malicious patterns detected
dist/esm/actions/getFeeHistory.js safe No malicious patterns detected
dist/esm/actions/getGasPrice.js safe This is a standard wagmi action wrapper for fetching gas price via viem, with no malicious patterns detected.
dist/esm/actions/getProof.js safe No malicious patterns detected
dist/esm/actions/getPublicClient.js safe Cleared by Jev triage; no further analysis needed
dist/esm/actions/getStorageAt.js safe No malicious patterns detected; the file is a thin wagmi action wrapper around viem's getStorageAt with no network, filesystem, process, or dynamic execution concerns.
dist/esm/actions/getToken.js safe No malicious patterns detected; the code appears to be a legitimate utility for fetching ERC-20 token metadata via blockchain reads.
dist/esm/actions/getTransaction.js safe No malicious patterns detected
dist/esm/actions/getTransactionConfirmations.js safe No malicious patterns detected
dist/esm/actions/getTransactionCount.js safe No malicious patterns detected; the code is a straightforward wrapper around viem's getTransactionCount action.
dist/esm/actions/getTransactionReceipt.js safe No malicious patterns detected in this simple wrapper around viem's getTransactionReceipt action.
dist/esm/actions/getWalletClient.js safe No malicious patterns detected; the code is a straightforward wrapper around viem's wallet client extension without external data flows or dynamic execution.
dist/esm/actions/multicall.js safe No malicious patterns detected; the file is a thin wrapper around viem's multicall action with no exfiltration, code execution, or filesystem/network abuse.
dist/esm/actions/prepareTransactionRequest.js safe No malicious patterns detected; the code is a standard wagmi action wrapper for preparing Ethereum transaction requests via viem.
dist/esm/actions/readContract.js safe No malicious patterns detected
dist/esm/actions/readContracts.js safe No malicious patterns detected; the code is a standard blockchain contract reading utility with no exfiltration, credential harvesting, obfuscation, or system-level abuse.
dist/esm/actions/reconnect.js safe No malicious patterns detected; the code is a legitimate wagmi reconnect action for managing wallet connector state.
dist/esm/actions/sendCalls.js safe No malicious patterns detected
dist/esm/actions/sendCallsSync.js safe No malicious patterns detected; the code is a standard wagmi action wrapper for sending synchronous calls via viem.
dist/esm/actions/sendTransaction.js safe No malicious patterns detected
dist/esm/actions/sendTransactionSync.js safe No malicious patterns detected; the file contains standard wagmi/viem transaction sending logic with no data exfiltration, obfuscation, credential harvesting, or process spawning.
dist/esm/actions/showCallsStatus.js safe No malicious patterns detected; this is a simple wrapper around viem's showCallsStatus action with standard connector client retrieval.
dist/esm/actions/signMessage.js safe No malicious patterns detected
dist/esm/actions/signTypedData.js safe No malicious patterns detected
dist/esm/actions/simulateContract.js safe No malicious patterns detected; this is a standard wagmi contract simulation action that only interacts with viem actions and local configuration.
dist/esm/actions/switchAccount.js safe No malicious patterns detected; the code performs a legitimate account switch operation using stored connection data and local state management.
dist/esm/actions/switchChain.js safe No malicious patterns detected; the file contains legitimate wagmi library logic for switching blockchain chains and throwing appropriate errors.
dist/esm/actions/verifyMessage.js safe No malicious patterns detected; the file is a straightforward wrapper around viem's verifyMessage action with no dynamic code execution, network calls, or credential access.
dist/esm/actions/verifyTypedData.js safe No malicious patterns detected
dist/esm/actions/waitForCallsStatus.js safe This file is a thin wrapper around viem's waitForCallsStatus action using the project's internal getConnectorClient, with no obfuscation, network calls, file system access, process spawning, or other malicious patterns.
dist/esm/actions/waitForTransactionReceipt.js safe No malicious patterns detected
dist/esm/actions/watchAccount.js safe No malicious patterns detected; the file is a benign wagmi watchAccount helper using local imports and a subscription callback.
dist/esm/actions/watchAsset.js safe No malicious patterns detected; the code is a straightforward wagmi action wrapper for viem's watchAsset.
dist/esm/actions/watchBlockNumber.js safe No malicious patterns detected; this is a standard wagmi utility for watching block number changes using viem actions.
dist/esm/actions/watchBlocks.js safe No malicious patterns detected; the code is a standard viem/wagmi block watching utility with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/actions/watchChainId.js safe Cleared by Jev triage; no further analysis needed
dist/esm/actions/watchChains.js safe Cleared by Jev triage; no further analysis needed
dist/esm/actions/watchClient.js safe No malicious patterns detected; the code is a simple wagmi utility for watching client changes via config subscription.
dist/esm/actions/watchConnections.js safe No malicious patterns detected; the file only imports local utilities and exports a standard wagmi action for watching connection changes.
dist/esm/actions/watchConnectors.js safe No malicious patterns detected; the code is a straightforward subscription helper for connector changes in wagmi, with no network, filesystem, process, or dynamic execution behavior.
dist/esm/actions/watchContractEvent.js safe No malicious patterns detected
dist/esm/actions/watchPendingTransactions.js safe No malicious patterns detected; the code is a standard wagmi action wrapper for viem's watchPendingTransactions without any security concerns.
dist/esm/actions/watchPublicClient.js safe Cleared by Jev triage; no further analysis needed
dist/esm/actions/writeContract.js safe No malicious patterns detected; the code is safe with a minor logic error.
dist/esm/connectors/createConnector.js safe Cleared by Jev triage; no further analysis needed
dist/esm/connectors/injected.js safe No malicious patterns detected; this is a standard wagmi injected wallet connector implementing EIP-1193 provider interaction without exfiltration, dynamic code execution, or suspicious network/file operations.
dist/esm/createConfig.js safe No malicious patterns detected; the file is a legitimate configuration module for a Web3 wallet connector library.
dist/esm/createEmitter.js safe No malicious patterns detected; the file is a simple event emitter wrapper with no network, filesystem, process, or dynamic execution behavior.
dist/esm/createStorage.js safe No malicious patterns detected; the code is a straightforward storage abstraction wrapper with no data exfiltration, dynamic execution, or suspicious behavior.
dist/esm/errors/base.js safe No malicious patterns detected
dist/esm/errors/config.js safe No malicious patterns detected
dist/esm/errors/connector.js safe No malicious patterns detected; the file only defines two simple error classes extending BaseError with no network, filesystem, process, or dynamic execution behavior.
dist/esm/experimental/actions/writeContracts.js safe No malicious patterns detected in the provided JavaScript file; it is a standard wrapper for the viem writeContracts action.
dist/esm/experimental/query/writeContracts.js safe No malicious patterns detected; the file only defines a React Query mutation options factory that delegates to an imported writeContracts action.
dist/esm/exports/actions.js safe This file is a pure barrel/entrypoint module that only re-exports action functions from other local modules, with no executable code, network calls, dynamic imports, or other suspicious patterns.
dist/esm/exports/chains.js safe No malicious patterns detected
dist/esm/exports/codegen.js safe No malicious patterns detected
dist/esm/exports/experimental.js safe No malicious patterns detected; the file is a standard barrel export of deprecated experimental actions with no executable code, network activity, or obfuscation.
dist/esm/exports/index.js safe No malicious patterns detected; the file is a standard barrel export module for a well-known Ethereum library (wagmi).
dist/esm/exports/internal.js safe Cleared by Jev triage; no further analysis needed
dist/esm/exports/query.js safe This file is a pure barrel export module re-exporting TanStack Query options/keys from local modules with no executable logic, network calls, or suspicious patterns.
dist/esm/hydrate.js safe No malicious patterns detected; the code is a standard hydration utility for a Web3 wallet connection library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
dist/esm/query/call.js safe No malicious patterns detected; the file contains standard React Query query option builders with no network, filesystem, process, or obfuscation concerns.
dist/esm/query/connect.js safe No malicious patterns detected
dist/esm/query/deployContract.js safe No malicious patterns detected
dist/esm/query/disconnect.js safe No malicious patterns detected; the file is a simple, benign React Query mutation options wrapper.
dist/esm/query/estimateFeesPerGas.js safe No malicious patterns detected
dist/esm/query/estimateGas.js safe No malicious patterns detected; the code is a standard viem-style estimateGas query options module with no network exfiltration, obfuscation, credential harvesting, or process execution.
dist/esm/query/estimateMaxPriorityFeePerGas.js safe No malicious patterns detected
dist/esm/query/getBalance.js safe No malicious patterns detected
dist/esm/query/getBlock.js safe No malicious patterns detected
dist/esm/query/getBlockNumber.js safe No malicious patterns detected; this is a standard query options module for fetching block numbers with no network, filesystem, or dynamic code execution concerns.
dist/esm/query/getBlockTransactionCount.js safe No malicious patterns detected; the file contains standard query option helpers for fetching block transaction counts with no exfiltration, exec, or credential harvesting behavior.
dist/esm/query/getBytecode.js safe No malicious patterns detected
dist/esm/query/getCallsStatus.js safe The file contains only standard query option configuration for a calls status function, with no malicious patterns such as data exfiltration, dynamic code execution, or suspicious network activity.
dist/esm/query/getCapabilities.js safe No malicious patterns detected; the file contains only standard query option configuration for a capabilities API.
dist/esm/query/getConnectorClient.js safe No malicious patterns detected; the code is a standard React Query option factory for a connector client.
dist/esm/query/getEnsAddress.js safe No malicious patterns detected
dist/esm/query/getEnsAvatar.js safe No malicious patterns detected; the code is a straightforward query options helper for ENS avatar resolution with no network, filesystem, credential, or dynamic execution activity.
dist/esm/query/getEnsName.js safe No malicious patterns detected; the code is a standard query options wrapper for ENS name resolution with no network, filesystem, or process manipulation.
dist/esm/query/getEnsResolver.js safe No malicious patterns detected
dist/esm/query/getEnsText.js safe No malicious patterns detected
dist/esm/query/getFeeHistory.js safe No malicious patterns detected; the code is a standard React Query options helper for fetching fee history via an existing internal action module.
dist/esm/query/getGasPrice.js safe No malicious patterns detected in the provided source file; it is a straightforward query options helper for fetching gas price data.
dist/esm/query/getProof.js safe No malicious patterns detected
dist/esm/query/getStorageAt.js safe No malicious patterns detected
dist/esm/query/getToken.js safe No malicious patterns detected; the file contains only standard query option builders for token data with no network, filesystem, or process execution behavior.
dist/esm/query/getTransaction.js safe No malicious patterns detected; the code only builds query options and delegates to a local getTransaction action with no external calls, process spawning, or obfuscation.
dist/esm/query/getTransactionConfirmations.js safe No malicious patterns detected; the code is a straightforward React Query options builder for transaction confirmations with no network, filesystem, process, or obfuscation concerns.
dist/esm/query/getTransactionCount.js safe The code defines standard query options for fetching transaction counts and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning.
dist/esm/query/getTransactionReceipt.js safe No malicious patterns detected; the code is a straightforward query options builder for fetching transaction receipts.
dist/esm/query/getWalletClient.js safe No malicious patterns detected
dist/esm/query/infiniteReadContracts.js safe No malicious patterns detected; the file contains standard query option builders for wagmi-style contract reads with no network, fs, process, or dynamic execution concerns.
dist/esm/query/prepareTransactionRequest.js safe No malicious patterns detected; the file contains ordinary query option and query key helpers for blockchain transaction preparation.
dist/esm/query/readContract.js safe No malicious patterns detected; the file contains standard React Query options for reading smart contracts via viem.
dist/esm/query/readContracts.js safe No malicious patterns detected; the file contains standard query option construction for a blockchain read-contracts action without network, filesystem, process, or dynamic code execution behavior.
dist/esm/query/reconnect.js safe No malicious patterns detected
dist/esm/query/sendCalls.js safe No malicious patterns detected; the file only defines a thin wrapper around an imported sendCalls action with no network, filesystem, process, or dynamic execution behavior.
dist/esm/query/sendCallsSync.js safe No malicious patterns detected; the file is a simple wrapper around an internal action function with no external calls, dynamic execution, or suspicious behavior.
dist/esm/query/sendTransaction.js safe No malicious patterns detected
dist/esm/query/sendTransactionSync.js safe No malicious patterns detected
dist/esm/query/showCallsStatus.js safe The file is a thin wrapper that delegates to showCallsStatus and contains no malicious patterns.
dist/esm/query/signMessage.js safe This file only defines a React Query mutation wrapper around an imported signMessage action with no network, filesystem, process, eval, or credential-related behavior.
dist/esm/query/signTypedData.js safe No malicious patterns detected
dist/esm/query/simulateContract.js safe No malicious patterns detected
dist/esm/query/switchAccount.js safe No malicious patterns detected in the switchAccount.js wrapper file.
dist/esm/query/switchChain.js safe No malicious patterns detected in the provided file; it only defines a mutation wrapper around a local switchChain action.
dist/esm/query/types.js safe No malicious patterns detected
dist/esm/query/utils.js safe Cleared by Jev triage; no further analysis needed
dist/esm/query/verifyMessage.js safe No malicious patterns detected; the file only defines query option builders for verifying messages using imported library functions.
dist/esm/query/verifyTypedData.js safe No malicious patterns detected; the code is a standard typed-data verification query helper with input validation and no exfiltration, obfuscation, dynamic execution, or install-time behavior.
dist/esm/query/waitForCallsStatus.js safe No malicious patterns detected; the code is a standard query options helper for waiting on call statuses with no network, filesystem, credential, or code execution concerns.
dist/esm/query/waitForTransactionReceipt.js safe No malicious patterns detected
dist/esm/query/watchAsset.js safe No malicious patterns detected
dist/esm/query/writeContract.js safe No malicious patterns detected; the file is a simple wrapper that delegates to an imported writeContract action.
dist/esm/transports/connector.js safe No malicious patterns detected
dist/esm/transports/fallback.js safe No malicious patterns detected
dist/esm/types/chain.js safe No malicious patterns detected
dist/esm/types/properties.js safe No malicious patterns detected
dist/esm/types/register.js safe No malicious patterns detected
dist/esm/types/unit.js safe No malicious patterns detected
dist/esm/types/utils.js safe No malicious patterns detected
dist/esm/utils/cookie.js safe No malicious patterns detected; the code is a standard cookie-based storage utility for reading, writing, and removing client-side cookies.
dist/esm/utils/deepEqual.js safe The file contains a standard deep equality comparison utility with no network, filesystem, process, or dynamic code execution activity.
dist/esm/utils/deserialize.js safe No malicious patterns detected; the code is a standard JSON deserializer with custom reviver for BigInt and Map, with no exfiltration, code execution, or other suspicious behavior.
dist/esm/utils/extractRpcUrls.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/getAction.js safe No malicious patterns detected
dist/esm/utils/getUnit.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/getVersion.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/normalizeChainId.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/serialize.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/uid.js safe No malicious patterns detected
dist/esm/version.js safe Cleared by Jev triage; no further analysis needed
src/actions/call.ts safe No malicious patterns detected; the code is a straightforward wrapper around viem's call action with no data exfiltration, dynamic execution, or suspicious behavior.
src/actions/codegen/createReadContract.ts safe Cleared by Jev triage; no further analysis needed
src/actions/codegen/createSimulateContract.ts safe No malicious patterns detected; the file only contains type-safe wrappers for a viem contract simulation API without network, file system, environment, or process access.
src/actions/codegen/createWatchContractEvent.ts safe No malicious patterns detected; the code is a standard Viem action creator for watching contract events with no network, filesystem, or process manipulation.
src/actions/codegen/createWriteContract.ts safe No malicious patterns detected; the code is a type-safe wrapper for viem's writeContract with no external data exfiltration, dynamic execution, or suspicious behavior.
src/actions/connect.ts safe No malicious patterns detected
src/actions/deployContract.ts safe No malicious patterns detected; the code is a standard wagmi action wrapper for viem's deployContract with no exfiltration, obfuscation, or suspicious behavior.
src/actions/disconnect.ts safe The code is a standard disconnect action for the wagmi library and contains no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
src/actions/estimateFeesPerGas.ts safe No malicious patterns detected; the file contains standard viem-based fee estimation logic with no exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
src/actions/estimateGas.ts safe No malicious patterns detected; the code is a standard viem/wagmi action wrapper for estimating gas.
src/actions/estimateMaxPriorityFeePerGas.ts safe No malicious patterns detected; the code is a straightforward viem action wrapper with no suspicious behavior.
src/actions/getAccount.ts safe This TypeScript file defines a typed getAccount action for a viem-based connector library and contains no malicious patterns, external calls, credential access, or dynamic code execution.
src/actions/getBalance.ts safe No malicious patterns detected; the code is a straightforward wagmi/viem balance retrieval action with no network exfiltration, credential harvesting, or obfuscation.
src/actions/getBlock.ts safe No malicious patterns detected; the code is a standard wagmi/viem wrapper for fetching blockchain blocks with no exfiltration, obfuscation, or process execution.
src/actions/getBlockNumber.ts safe No malicious patterns detected
src/actions/getBlockTransactionCount.ts safe No malicious patterns detected; the file is a standard wagmi action wrapper around viem's getBlockTransactionCount with no network, filesystem, or code execution side effects.
src/actions/getBytecode.ts safe No malicious patterns detected
src/actions/getCallsStatus.ts safe No malicious patterns detected; the code is a straightforward wagmi action wrapper that delegates to viem's getCallsStatus via a connector client.
src/actions/getCapabilities.ts safe No malicious patterns detected
src/actions/getChainId.ts safe Cleared by Jev triage; no further analysis needed
src/actions/getChains.ts safe Cleared by Jev triage; no further analysis needed
src/actions/getClient.ts safe No malicious patterns detected; the code is a standard typed wrapper around a viem client getter with no network, filesystem, process, or dynamic execution concerns.
src/actions/getConnections.ts safe No malicious patterns detected in this small utility function that reads local state and caches previous connections.
src/actions/getConnectorClient.ts safe This is legitimate wagmi connector client code that creates viem clients for wallet connectors without any malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning.
src/actions/getConnectors.ts safe Cleared by Jev triage; no further analysis needed
src/actions/getEnsAddress.ts safe No malicious patterns detected
src/actions/getEnsAvatar.ts safe No malicious patterns detected; the code is a straightforward viem action wrapper for retrieving ENS avatars with no data exfiltration, credential access, obfuscation, or process/network anomalies.
src/actions/getEnsName.ts safe No malicious patterns detected; the code is a straightforward wrapper around viem's getEnsName action with no exfiltration, obfuscation, process spawning, or suspicious behavior.
src/actions/getEnsResolver.ts safe No malicious patterns detected; this is a standard wagmi action wrapper around viem's getEnsResolver with no exfiltration, exec, or obfuscated code.
src/actions/getEnsText.ts safe No malicious patterns detected
src/actions/getFeeHistory.ts safe No malicious patterns detected; this is a standard wagmi action wrapper around viem's getFeeHistory with no network, filesystem, or code execution concerns.
src/actions/getGasPrice.ts safe No malicious patterns detected
src/actions/getProof.ts safe No malicious patterns detected
src/actions/getPublicClient.ts safe Cleared by Jev triage; no further analysis needed
src/actions/getStorageAt.ts safe No malicious patterns detected; the file simply wraps viem's getStorageAt action for use with wagmi configuration.
src/actions/getToken.ts safe No malicious patterns detected
src/actions/getTransaction.ts safe No malicious patterns detected
src/actions/getTransactionConfirmations.ts safe No malicious patterns detected
src/actions/getTransactionCount.ts safe No malicious patterns detected; the file is a straightforward wrapper around viem's getTransactionCount action with no suspicious behavior.
src/actions/getTransactionReceipt.ts safe No malicious patterns detected
src/actions/getWalletClient.ts safe No malicious patterns detected in the getWalletClient TypeScript file; it is a legitimate viem wallet client utility.
src/actions/multicall.ts safe No malicious patterns detected
src/actions/prepareTransactionRequest.ts safe This is a legitimate wagmi library action for preparing Ethereum transaction requests; no malicious patterns, network exfiltration, obfuscation, or credential harvesting were detected.
src/actions/readContract.ts safe No malicious patterns detected
src/actions/readContracts.ts safe No malicious patterns detected; the code is a standard blockchain contract-reading utility with no exfiltration, credential harvesting, obfuscation, or other security concerns.
src/actions/reconnect.ts safe No malicious patterns detected; the code is a legitimate wallet connector reconnection utility with no data exfiltration, credential harvesting, obfuscation, or process spawning.
src/actions/sendCalls.ts safe This is legitimate wagmi/viem library code for sending RPC calls to a connected wallet connector; no malicious patterns detected.
src/actions/sendCallsSync.ts safe No malicious patterns detected; the file is a standard wagmi/viem action wrapper for sending batch calls, with no network exfiltration, credential harvesting, obfuscation, or process execution.
src/actions/sendTransaction.ts safe No malicious patterns detected; the code is a standard viem/wagmi transaction sending action with no exfiltration, credential harvesting, or dynamic execution.
src/actions/sendTransactionSync.ts safe No malicious patterns detected; the code is a standard viem/wagmi transaction-sending action with no exfiltration, obfuscation, or suspicious behavior.
src/actions/showCallsStatus.ts safe No malicious patterns detected; the code is a straightforward wrapper around viem's showCallsStatus action with no exfiltration, obfuscation, or dangerous side effects.
src/actions/signMessage.ts safe No malicious patterns detected; this is a standard wagmi/viem message signing action that delegates to the user's configured client/connector without exfiltration, obfuscation, or suspicious behavior.
src/actions/signTypedData.ts safe No malicious patterns detected
src/actions/simulateContract.ts safe No malicious patterns detected; the file is a standard viem/wagmi contract simulation action with no exfiltration, credential harvesting, code execution, or suspicious network behavior.
src/actions/switchAccount.ts safe No malicious patterns detected; the code is a straightforward wagmi action for switching accounts without any exfiltration, obfuscation, or system manipulation.
src/actions/switchChain.ts safe No malicious patterns detected
src/actions/verifyMessage.ts safe No malicious patterns detected; the code is a straightforward wrapper around viem's verifyMessage action with no data exfiltration, credential harvesting, dynamic code execution, or process spawning.
src/actions/verifyTypedData.ts safe No malicious patterns detected; the code is a standard wrapper around viem's verifyTypedData action with no external network, filesystem, or process manipulation.
src/actions/waitForCallsStatus.ts safe No malicious patterns detected
src/actions/waitForTransactionReceipt.ts safe No malicious patterns detected; the code is a standard viem-based Ethereum transaction receipt waiter that decodes revert reasons locally without network exfiltration or filesystem access.
src/actions/watchAccount.ts safe No malicious patterns detected
src/actions/watchAsset.ts safe No malicious patterns detected
src/actions/watchBlockNumber.ts safe No malicious patterns detected; the file is a legitimate wagmi action wrapper around viem's watchBlockNumber with no data exfiltration, credential access, dynamic code execution, or other security concerns.
src/actions/watchBlocks.ts safe No malicious patterns detected
src/actions/watchChainId.ts safe Cleared by Jev triage; no further analysis needed
src/actions/watchChains.ts safe Cleared by Jev triage; no further analysis needed
src/actions/watchClient.ts safe Cleared by Jev triage; no further analysis needed
src/actions/watchConnections.ts safe No malicious patterns detected
src/actions/watchConnectors.ts safe No malicious patterns detected
src/actions/watchContractEvent.ts safe This is a legitimate wagmi library action wrapper for watching contract events; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
src/actions/watchPendingTransactions.ts safe No malicious patterns detected; the code is a legitimate viem-based action for watching pending transactions.
src/actions/watchPublicClient.ts safe Cleared by Jev triage; no further analysis needed
src/actions/writeContract.ts safe No malicious patterns detected; the file is a standard viem-based writeContract action implementation with no data exfiltration, code execution, or filesystem/process manipulation.
src/connectors/createConnector.ts safe No malicious patterns detected
src/connectors/injected.ts safe No malicious patterns detected; code is a standard wallet connector implementation for wagmi/viem.
src/createConfig.ts safe No malicious patterns detected; the file is a legitimate wallet/connector configuration module with no data exfiltration, credential harvesting, obfuscation, or process execution.
src/createEmitter.ts safe Cleared by Jev triage; no further analysis needed
src/createStorage.ts safe No malicious patterns detected; the code is a legitimate storage abstraction for wagmi with standard serialization and localStorage usage.
src/errors/base.ts safe Cleared by Jev triage; no further analysis needed
src/errors/config.ts safe No malicious patterns detected; the file only defines typed error classes with static messages and does not perform any I/O, network, process, or dynamic code execution.
src/errors/connector.ts safe No malicious patterns detected
src/experimental/actions/writeContracts.ts safe No malicious patterns detected; this is a legitimate wagmi library file that wraps viem's writeContracts action with connector client handling.
src/experimental/query/writeContracts.ts safe No malicious patterns detected; the file only defines TypeScript types and a mutation options factory for a writeContracts action.
src/exports/actions.ts safe No malicious patterns detected; this is a pure re-export barrel file for blockchain action modules with no executable side effects.
src/exports/chains.ts safe Cleared by Jev triage; no further analysis needed
src/exports/codegen.ts safe This file is a simple barrel export module that re-exports functions and types from other local modules, with no malicious patterns, side effects, or suspicious behavior.
src/exports/experimental.ts safe No malicious patterns detected
src/exports/index.ts safe This is a standard barrel export file for a Web3/blockchain library (wagmi-like), containing only static re-exports of functions, types, and utilities with no executable code, network calls, or malicious patterns.
src/exports/internal.ts safe Cleared by Jev triage; no further analysis needed
src/exports/query.ts safe This is a pure barrel export file re-exporting types and functions from TanStack Query blockchain utility modules; no malicious patterns, dynamic code execution, network calls, or filesystem access were detected.
src/hydrate.ts safe No malicious patterns detected; the code performs expected state hydration and connector setup for a web3 wallet library without exfiltration, credential harvesting, obfuscation, or dynamic code execution.
src/query/call.ts safe No malicious patterns detected; the code is a straightforward TanStack Query wrapper for an RPC call action with no network, filesystem, process, or dynamic execution concerns.
src/query/connect.ts safe No malicious patterns detected
src/query/deployContract.ts safe No malicious patterns detected; the file contains only type definitions and a thin wrapper around a deployContract action with no network, filesystem, process, or dynamic code execution behavior.
src/query/disconnect.ts safe No malicious patterns detected; the code is a standard TanStack Query mutation options factory for a disconnect action with no network, filesystem, or code-execution risks.
src/query/estimateFeesPerGas.ts safe No malicious patterns detected; the code is a standard TanStack Query wrapper for estimating fees per gas using viem, with no network, filesystem, process, or dynamic execution concerns.
src/query/estimateGas.ts safe No malicious patterns detected; the code is a standard TanStack Query integration for estimating gas in a TypeScript library.
src/query/estimateMaxPriorityFeePerGas.ts safe No malicious patterns detected; the file contains standard TanStack Query option builders for an Ethereum fee estimation action.
src/query/getBalance.ts safe No malicious patterns detected; the file contains standard TanStack Query option builders for a blockchain balance action with no network, filesystem, process, or dynamic code execution activity.
src/query/getBlock.ts safe No malicious patterns detected
src/query/getBlockNumber.ts safe No malicious patterns detected
src/query/getBlockTransactionCount.ts safe No malicious patterns detected; this is a standard TanStack Query options wrapper delegating to an internal blockchain action.
src/query/getBytecode.ts safe No malicious patterns detected
src/query/getCallsStatus.ts safe No malicious patterns detected
src/query/getCapabilities.ts safe No malicious patterns detected; the code is a standard TanStack Query options wrapper for a wallet capabilities action with no network, filesystem, process, or dynamic execution behavior.
src/query/getConnectorClient.ts safe No malicious patterns detected; the code is a standard TanStack Query options/queryKey factory for connector clients with no network, filesystem, process, eval, or credential access.
src/query/getEnsAddress.ts safe No malicious patterns detected; the file is a standard TanStack Query options builder for an ENS address action with no exfiltration, credential harvesting, or dynamic execution.
src/query/getEnsAvatar.ts safe No malicious patterns detected; the file contains standard query option definitions for ENS avatar resolution without any suspicious network, filesystem, or execution behavior.
src/query/getEnsName.ts safe No malicious patterns detected; the code is a standard TanStack Query options wrapper for fetching ENS names with no network, filesystem, process, or dynamic code execution concerns.
src/query/getEnsResolver.ts safe No malicious patterns detected; the file is a standard TanStack Query options factory for ENS resolver lookups.
src/query/getEnsText.ts safe No malicious patterns detected; the file is a benign TanStack Query options wrapper for ENS text resolution with no network, filesystem, process, or dynamic execution behavior.
src/query/getFeeHistory.ts safe No malicious patterns detected
src/query/getGasPrice.ts safe No malicious patterns detected
src/query/getProof.ts safe No malicious patterns detected
src/query/getStorageAt.ts safe No malicious patterns detected; the file contains standard TanStack Query option builders for a getStorageAt action with no network, filesystem, process, or dynamic code execution concerns.
src/query/getToken.ts safe No malicious patterns detected
src/query/getTransaction.ts safe No malicious patterns detected
src/query/getTransactionConfirmations.ts safe No malicious patterns detected
src/query/getTransactionCount.ts safe No malicious patterns detected
src/query/getTransactionReceipt.ts safe No malicious patterns detected
src/query/getWalletClient.ts safe No malicious patterns detected
src/query/infiniteReadContracts.ts safe No malicious patterns detected in the TypeScript query options file; it only provides typed wrappers for infinite read contracts using viem and contains no network, filesystem, process, or obfuscated code.
src/query/prepareTransactionRequest.ts safe No malicious patterns detected; the file contains standard TanStack Query options and query key definitions for viem transaction preparation.
src/query/readContract.ts safe No malicious patterns detected
src/query/readContracts.ts safe This file contains standard TanStack Query integration code for wagmi's readContracts action, with no malicious patterns, network requests, credential harvesting, or dynamic code execution.
src/query/reconnect.ts safe No malicious patterns detected; the file only defines type-safe mutation options for a reconnect action with no side effects, network calls, or dynamic code execution.
src/query/sendCalls.ts safe No malicious patterns detected
src/query/sendCallsSync.ts safe No malicious patterns detected; the file is a standard TanStack Query mutation wrapper for a sendCallsSync action with only type imports and no runtime side effects or suspicious operations.
src/query/sendTransaction.ts safe No malicious patterns detected
src/query/sendTransactionSync.ts safe No malicious patterns detected
src/query/showCallsStatus.ts safe No malicious patterns detected; the file is a standard TanStack Query mutation options wrapper for a showCallsStatus action with no network, filesystem, process, or dynamic code execution behavior.
src/query/signMessage.ts safe The code defines a TanStack Query mutation for signing messages; it contains no network, filesystem, process execution, obfuscation, or credential-harvesting patterns.
src/query/signTypedData.ts safe No malicious patterns detected; the file only defines typed mutation options and TypeScript types for signing typed data via viem, with no network, filesystem, process, eval, or install-time behavior.
src/query/simulateContract.ts safe No malicious patterns detected; the code is a standard TanStack Query wrapper for viem contract simulation with no network, filesystem, or dynamic execution concerns.
src/query/switchAccount.ts safe No malicious patterns detected
src/query/switchChain.ts safe No malicious patterns detected in this TypeScript file, which contains only standard type definitions and mutation options for a blockchain wallet chain-switching action.
src/query/types.ts safe Cleared by Jev triage; no further analysis needed
src/query/utils.ts safe Cleared by Jev triage; no further analysis needed
src/query/verifyMessage.ts safe No malicious patterns detected
src/query/verifyTypedData.ts safe No malicious patterns detected; the file is a standard TanStack Query utility for verifying typed data signatures with no network exfiltration, credential harvesting, obfuscation, or command execution.
src/query/waitForCallsStatus.ts safe No malicious patterns detected
src/query/waitForTransactionReceipt.ts safe No malicious patterns detected; this is a standard TanStack Query options factory for waiting on blockchain transaction receipts.
src/query/watchAsset.ts safe No malicious patterns detected
src/query/writeContract.ts safe No malicious patterns detected
src/transports/connector.ts safe No malicious patterns detected
src/transports/fallback.ts safe This is a thin wrapper around viem's fallback transport with no malicious patterns detected.
src/types/chain.ts safe Cleared by Jev triage; no further analysis needed
src/types/properties.ts safe Cleared by Jev triage; no further analysis needed
src/types/register.ts safe Cleared by Jev triage; no further analysis needed
src/types/unit.ts safe Cleared by Jev triage; no further analysis needed
src/types/utils.ts safe Cleared by Jev triage; no further analysis needed
src/utils/cookie.ts safe The code implements cookie storage and parsing without any malicious patterns; the only minor security concern is the absence of the 'secure' cookie flag.
src/utils/deepEqual.ts safe Cleared by Jev triage; no further analysis needed
src/utils/deserialize.ts safe No malicious patterns detected
src/utils/extractRpcUrls.ts safe Cleared by Jev triage; no further analysis needed
src/utils/getAction.ts safe No malicious patterns detected; the code is a simple utility function that retrieves and falls back to client actions with no network, filesystem, or code execution concerns.
src/utils/getUnit.ts safe Cleared by Jev triage; no further analysis needed
src/utils/getVersion.ts safe Cleared by Jev triage; no further analysis needed
src/utils/normalizeChainId.ts safe Cleared by Jev triage; no further analysis needed
src/utils/serialize.ts safe Cleared by Jev triage; no further analysis needed
src/version.ts safe Cleared by Jev triage; no further analysis needed

Scanned versions of @wagmi/core

VersionVerdictFilesScanned
2.22.1 Needs review 326 Oct 4, 2026

Frequently asked questions

Is @wagmi/core safe to use?

No confirmed malware was found in @wagmi/core@2.22.1, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @wagmi/core contain malware?

No malware was identified in @wagmi/core@2.22.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @wagmi/core checked?

Togoder Security downloaded the published npm package and had an AI model read its 326 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @wagmi/core together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @wagmi/core@2.22.1, cost nothing.

Related security reports