# @wagmi/core@2.22.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:19:07.000Z
- Files reviewed: 326
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@wagmi/core
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @wagmi/core@2.22.1 on Oct 4, 2026. An AI review of 326 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Suspicious network requests

Finding ID: `NPS-2767A4A8D258`

File: `dist/esm/connectors/mock.js`

The mock connector makes real HTTP RPC requests to the chain's default RPC URL using `rpc.http(url, ...)` when handling `wallet_sendCalls` and `wallet_getCallsStatus`. While this is intended to simulate transaction submission and receipt retrieval for the mock connector, it means that calls to these methods will actually broadcast transactions to a live RPC endpoint if the default chain URL points to production infrastructure. This is unexpected behavior for a 'mock' connector and could lead to real on-chain transactions and unintended fund movement during testing.

### [medium] Weak Randomness for Identifier Generation

Finding ID: `NPS-C10BE1F4762F`

File: `src/utils/uid.ts:10`

The uid() function uses Math.random() to generate identifiers. Math.random() is not cryptographically secure and is predictable, which is unsuitable for security-sensitive uses such as tokens, session IDs, CSRF nonces, or password reset links. If this utility is used for such purposes, it could allow attackers to predict or brute-force generated values. This is a code-quality/security weakness rather than an active malicious pattern.

### [low] deprecated API usage

Finding ID: `NPS-CDAFBEE10460`

File: `dist/esm/actions/getToken.js:4`

The getToken function is marked as deprecated but does not introduce security risks.

### [low] code quality issue

Finding ID: `NPS-9F1602FE9276`

File: `dist/esm/actions/writeContract.js:10`

The condition `typeof account === 'object' && account?.type === 'local'` checks the wrong variable (should likely be `connector`). However, this is a logic error, not a security vulnerability. The code does not exhibit any malicious patterns such as data exfiltration, credential harvesting, obfuscation, mining, backdoors, suspicious network requests, file system manipulation, process spawning, or dynamic imports with external input.

### [low] Hardcoded address allowlist

Finding ID: `NPS-3670BB82DE8C`

File: `dist/esm/connectors/mock.js`

The `wallet_getCapabilities` handler hardcodes a specific checksummed Ethereum address (`0x95132632579b073D12a6673e18Ab05777a6B86f8`) and returns paymaster support only for that address. This is likely a test fixture rather than a malicious backdoor, but it is an unusual hardcoded credential-like value embedded in production code.

### [low] Top-level code execution

Finding ID: `NPS-C04AE3F285FA`

File: `dist/esm/connectors/mock.js`

The module executes `mock.type = 'mock'` at top-level import time. This is a benign property assignment and does not introduce a security risk, included here for completeness of top-level execution analysis.

### [low] Mock Connector Simulating Wallet Behavior

Finding ID: `NPS-12381625EB78`

File: `src/connectors/mock.ts`

This file is explicitly a mock connector for a wallet library (viem). It simulates wallet RPC methods such as eth_requestAccounts, eth_signTypedData_v4, personal_sign, wallet_sendCalls, etc. While it contains network requests (rpc.http) and handles account data, these are expected for a connector mock used in testing. No exfiltration to hardcoded external servers, no credential harvesting, no obfuscation or dynamic code execution, and no suspicious processes were observed. The code appears to be legitimate testing infrastructure. However, the mock's behavior of forwarding transactions and signing operations could be misused if imported in production unexpectedly; it should remain strictly a test utility.

### [low] cookie security

Finding ID: `NPS-BA7BCF88AAAE`

File: `src/utils/cookie.ts:16`

Cookies are set without the 'secure' flag and only with 'samesite=Lax'. This could allow cookie theft over insecure connections (HTTP) via network eavesdropping or XSS. However, it is a common pattern and not inherently malicious.

## Files reviewed

- `dist/esm/connectors/mock.js` (medium): No malicious exfiltration, credential harvesting, obfuscation, backdoors, or process spawning detected, but the mock connector performs live RPC network calls for wallet_sendCalls/wallet_getCallsStatus and contains a hardcoded address allowlist, which warrants a warning.
- `src/connectors/mock.ts` (medium): This is a benign mock connector for the viem library used for testing wallet interactions, with no malicious patterns detected.
- `src/utils/uid.ts` (medium): No malicious behavior detected, but the uid() helper relies on non-cryptographic Math.random(), making it unsafe for security-sensitive identifier generation.
- `dist/esm/actions/call.js` (safe): No malicious patterns detected; code is a simple wrapper around the viem library's call action with no exfiltration, obfuscation, or dangerous operations.
- `dist/esm/actions/codegen/createReadContract.js` (safe): No malicious patterns detected
- `dist/esm/actions/codegen/createSimulateContract.js` (safe): No malicious patterns detected; the file is a straightforward contract simulation helper with no network, filesystem, process, or dynamic execution activity.
- `dist/esm/actions/codegen/createWatchContractEvent.js` (safe): No malicious patterns detected; the code is a benign wrapper for watchContractEvent in a blockchain library.
- `dist/esm/actions/codegen/createWriteContract.js` (safe): No malicious patterns detected; the file is a standard viem-style helper for creating contract write actions with no network, filesystem, process, or obfuscation concerns.
- `dist/esm/actions/connect.js` (safe): No malicious patterns detected; the code is a legitimate connector initialization routine for the wagmi library.
- `dist/esm/actions/deployContract.js` (safe): No malicious patterns detected; this is a standard wagmi wrapper for deploying contracts via viem with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/esm/actions/disconnect.js` (safe): No malicious patterns detected
- `dist/esm/actions/estimateFeesPerGas.js` (safe): No malicious patterns detected; the code is a straightforward wrapper around viem's estimateFeesPerGas with only unit formatting.
- `dist/esm/actions/estimateGas.js` (safe): No malicious patterns detected
- `dist/esm/actions/estimateMaxPriorityFeePerGas.js` (safe): No malicious patterns detected
- `dist/esm/actions/getAccount.js` (safe): No malicious patterns detected; the code is a straightforward state accessor from Wagmi's getAccount action with no network, filesystem, process, or dynamic execution behavior.
- `dist/esm/actions/getBalance.js` (safe): No malicious patterns detected; the code is a standard blockchain balance retrieval action with no exfiltration, obfuscation, or credential harvesting.
- `dist/esm/actions/getBlock.js` (safe): No malicious patterns detected
- `dist/esm/actions/getBlockNumber.js` (safe): The code is a simple wrapper for a viem action to fetch block numbers, with no malicious patterns, network exfiltration, dynamic code execution, or suspicious behavior.
- `dist/esm/actions/getBlockTransactionCount.js` (safe): No malicious patterns detected; the file is a thin wrapper around viem's getBlockTransactionCount action with no exfiltration, obfuscation, or process execution.
- `dist/esm/actions/getBytecode.js` (safe): No malicious patterns detected
- `dist/esm/actions/getCallsStatus.js` (safe): No malicious patterns detected
- `dist/esm/actions/getCapabilities.js` (safe): No malicious patterns detected; the file is a straightforward wrapper around viem's getCapabilities action with no exfiltration, dynamic execution, or other red flags.
- `dist/esm/actions/getChainId.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/actions/getChains.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/actions/getClient.js` (safe): No malicious patterns detected
- `dist/esm/actions/getConnections.js` (safe): No malicious patterns detected
- `dist/esm/actions/getConnectorClient.js` (safe): No malicious patterns detected; the code is a standard wagmi connector client action with no exfiltration, credential harvesting, dynamic execution, or process spawning.
- `dist/esm/actions/getConnectors.js` (safe): No malicious patterns detected
- `dist/esm/actions/getEnsAddress.js` (safe): No malicious patterns detected; the file is a standard wrapper around viem's getEnsAddress action with no exfiltration, code execution, or filesystem access.
- `dist/esm/actions/getEnsAvatar.js` (safe): No malicious patterns detected; the file is a straightforward wrapper around viem's getEnsAvatar action with no network, filesystem, environment, or dynamic code execution concerns.
- `dist/esm/actions/getEnsName.js` (safe): No malicious patterns detected; the file is a straightforward wrapper around viem's getEnsName action with no network, filesystem, process, or dynamic code execution concerns.
- `dist/esm/actions/getEnsResolver.js` (safe): No malicious patterns detected; the code is a standard wagmi action wrapper for viem's getEnsResolver with no exfiltration, dynamic execution, or suspicious behavior.
- `dist/esm/actions/getEnsText.js` (safe): No malicious patterns detected
- `dist/esm/actions/getFeeHistory.js` (safe): No malicious patterns detected
- `dist/esm/actions/getGasPrice.js` (safe): This is a standard wagmi action wrapper for fetching gas price via viem, with no malicious patterns detected.
- `dist/esm/actions/getProof.js` (safe): No malicious patterns detected
- `dist/esm/actions/getPublicClient.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/actions/getStorageAt.js` (safe): No malicious patterns detected; the file is a thin wagmi action wrapper around viem's getStorageAt with no network, filesystem, process, or dynamic execution concerns.
- `dist/esm/actions/getToken.js` (safe): No malicious patterns detected; the code appears to be a legitimate utility for fetching ERC-20 token metadata via blockchain reads.
- `dist/esm/actions/getTransaction.js` (safe): No malicious patterns detected
- `dist/esm/actions/getTransactionConfirmations.js` (safe): No malicious patterns detected
- `dist/esm/actions/getTransactionCount.js` (safe): No malicious patterns detected; the code is a straightforward wrapper around viem's getTransactionCount action.
- `dist/esm/actions/getTransactionReceipt.js` (safe): No malicious patterns detected in this simple wrapper around viem's getTransactionReceipt action.
- `dist/esm/actions/getWalletClient.js` (safe): No malicious patterns detected; the code is a straightforward wrapper around viem's wallet client extension without external data flows or dynamic execution.
- `dist/esm/actions/multicall.js` (safe): No malicious patterns detected; the file is a thin wrapper around viem's multicall action with no exfiltration, code execution, or filesystem/network abuse.
- `dist/esm/actions/prepareTransactionRequest.js` (safe): No malicious patterns detected; the code is a standard wagmi action wrapper for preparing Ethereum transaction requests via viem.
- `dist/esm/actions/readContract.js` (safe): No malicious patterns detected
- `dist/esm/actions/readContracts.js` (safe): No malicious patterns detected; the code is a standard blockchain contract reading utility with no exfiltration, credential harvesting, obfuscation, or system-level abuse.
- `dist/esm/actions/reconnect.js` (safe): No malicious patterns detected; the code is a legitimate wagmi reconnect action for managing wallet connector state.
- `dist/esm/actions/sendCalls.js` (safe): No malicious patterns detected
- `dist/esm/actions/sendCallsSync.js` (safe): No malicious patterns detected; the code is a standard wagmi action wrapper for sending synchronous calls via viem.
- `dist/esm/actions/sendTransaction.js` (safe): No malicious patterns detected
- `dist/esm/actions/sendTransactionSync.js` (safe): No malicious patterns detected; the file contains standard wagmi/viem transaction sending logic with no data exfiltration, obfuscation, credential harvesting, or process spawning.
- `dist/esm/actions/showCallsStatus.js` (safe): No malicious patterns detected; this is a simple wrapper around viem's showCallsStatus action with standard connector client retrieval.
- `dist/esm/actions/signMessage.js` (safe): No malicious patterns detected
- `dist/esm/actions/signTypedData.js` (safe): No malicious patterns detected
- `dist/esm/actions/simulateContract.js` (safe): No malicious patterns detected; this is a standard wagmi contract simulation action that only interacts with viem actions and local configuration.
- `dist/esm/actions/switchAccount.js` (safe): No malicious patterns detected; the code performs a legitimate account switch operation using stored connection data and local state management.
- `dist/esm/actions/switchChain.js` (safe): No malicious patterns detected; the file contains legitimate wagmi library logic for switching blockchain chains and throwing appropriate errors.
- `dist/esm/actions/verifyMessage.js` (safe): No malicious patterns detected; the file is a straightforward wrapper around viem's verifyMessage action with no dynamic code execution, network calls, or credential access.
- `dist/esm/actions/verifyTypedData.js` (safe): No malicious patterns detected
- `dist/esm/actions/waitForCallsStatus.js` (safe): This file is a thin wrapper around viem's waitForCallsStatus action using the project's internal getConnectorClient, with no obfuscation, network calls, file system access, process spawning, or other malicious patterns.
- `dist/esm/actions/waitForTransactionReceipt.js` (safe): No malicious patterns detected
- `dist/esm/actions/watchAccount.js` (safe): No malicious patterns detected; the file is a benign wagmi watchAccount helper using local imports and a subscription callback.
- `dist/esm/actions/watchAsset.js` (safe): No malicious patterns detected; the code is a straightforward wagmi action wrapper for viem's watchAsset.
- `dist/esm/actions/watchBlockNumber.js` (safe): No malicious patterns detected; this is a standard wagmi utility for watching block number changes using viem actions.
- `dist/esm/actions/watchBlocks.js` (safe): No malicious patterns detected; the code is a standard viem/wagmi block watching utility with no exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/esm/actions/watchChainId.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/actions/watchChains.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/actions/watchClient.js` (safe): No malicious patterns detected; the code is a simple wagmi utility for watching client changes via config subscription.
- `dist/esm/actions/watchConnections.js` (safe): No malicious patterns detected; the file only imports local utilities and exports a standard wagmi action for watching connection changes.
- `dist/esm/actions/watchConnectors.js` (safe): No malicious patterns detected; the code is a straightforward subscription helper for connector changes in wagmi, with no network, filesystem, process, or dynamic execution behavior.
- `dist/esm/actions/watchContractEvent.js` (safe): No malicious patterns detected
- `dist/esm/actions/watchPendingTransactions.js` (safe): No malicious patterns detected; the code is a standard wagmi action wrapper for viem's watchPendingTransactions without any security concerns.
- `dist/esm/actions/watchPublicClient.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/actions/writeContract.js` (safe): No malicious patterns detected; the code is safe with a minor logic error.
- `dist/esm/connectors/createConnector.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/connectors/injected.js` (safe): No malicious patterns detected; this is a standard wagmi injected wallet connector implementing EIP-1193 provider interaction without exfiltration, dynamic code execution, or suspicious network/file operations.
- `dist/esm/createConfig.js` (safe): No malicious patterns detected; the file is a legitimate configuration module for a Web3 wallet connector library.
- `dist/esm/createEmitter.js` (safe): No malicious patterns detected; the file is a simple event emitter wrapper with no network, filesystem, process, or dynamic execution behavior.
- `dist/esm/createStorage.js` (safe): No malicious patterns detected; the code is a straightforward storage abstraction wrapper with no data exfiltration, dynamic execution, or suspicious behavior.
- `dist/esm/errors/base.js` (safe): No malicious patterns detected
- `dist/esm/errors/config.js` (safe): No malicious patterns detected
- `dist/esm/errors/connector.js` (safe): No malicious patterns detected; the file only defines two simple error classes extending BaseError with no network, filesystem, process, or dynamic execution behavior.
- `dist/esm/experimental/actions/writeContracts.js` (safe): No malicious patterns detected in the provided JavaScript file; it is a standard wrapper for the viem writeContracts action.
- `dist/esm/experimental/query/writeContracts.js` (safe): No malicious patterns detected; the file only defines a React Query mutation options factory that delegates to an imported writeContracts action.
- `dist/esm/exports/actions.js` (safe): This file is a pure barrel/entrypoint module that only re-exports action functions from other local modules, with no executable code, network calls, dynamic imports, or other suspicious patterns.
- `dist/esm/exports/chains.js` (safe): No malicious patterns detected
- `dist/esm/exports/codegen.js` (safe): No malicious patterns detected
- `dist/esm/exports/experimental.js` (safe): No malicious patterns detected; the file is a standard barrel export of deprecated experimental actions with no executable code, network activity, or obfuscation.
- `dist/esm/exports/index.js` (safe): No malicious patterns detected; the file is a standard barrel export module for a well-known Ethereum library (wagmi).
- `dist/esm/exports/internal.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/exports/query.js` (safe): This file is a pure barrel export module re-exporting TanStack Query options/keys from local modules with no executable logic, network calls, or suspicious patterns.
- `dist/esm/hydrate.js` (safe): No malicious patterns detected; the code is a standard hydration utility for a Web3 wallet connection library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `dist/esm/query/call.js` (safe): No malicious patterns detected; the file contains standard React Query query option builders with no network, filesystem, process, or obfuscation concerns.
- `dist/esm/query/connect.js` (safe): No malicious patterns detected
- `dist/esm/query/deployContract.js` (safe): No malicious patterns detected
- `dist/esm/query/disconnect.js` (safe): No malicious patterns detected; the file is a simple, benign React Query mutation options wrapper.
- `dist/esm/query/estimateFeesPerGas.js` (safe): No malicious patterns detected
- `dist/esm/query/estimateGas.js` (safe): No malicious patterns detected; the code is a standard viem-style estimateGas query options module with no network exfiltration, obfuscation, credential harvesting, or process execution.
- `dist/esm/query/estimateMaxPriorityFeePerGas.js` (safe): No malicious patterns detected
- `dist/esm/query/getBalance.js` (safe): No malicious patterns detected
- `dist/esm/query/getBlock.js` (safe): No malicious patterns detected
- `dist/esm/query/getBlockNumber.js` (safe): No malicious patterns detected; this is a standard query options module for fetching block numbers with no network, filesystem, or dynamic code execution concerns.
- `dist/esm/query/getBlockTransactionCount.js` (safe): No malicious patterns detected; the file contains standard query option helpers for fetching block transaction counts with no exfiltration, exec, or credential harvesting behavior.
- `dist/esm/query/getBytecode.js` (safe): No malicious patterns detected
- `dist/esm/query/getCallsStatus.js` (safe): The file contains only standard query option configuration for a calls status function, with no malicious patterns such as data exfiltration, dynamic code execution, or suspicious network activity.
- `dist/esm/query/getCapabilities.js` (safe): No malicious patterns detected; the file contains only standard query option configuration for a capabilities API.
- `dist/esm/query/getConnectorClient.js` (safe): No malicious patterns detected; the code is a standard React Query option factory for a connector client.
- `dist/esm/query/getEnsAddress.js` (safe): No malicious patterns detected
- `dist/esm/query/getEnsAvatar.js` (safe): No malicious patterns detected; the code is a straightforward query options helper for ENS avatar resolution with no network, filesystem, credential, or dynamic execution activity.
- `dist/esm/query/getEnsName.js` (safe): No malicious patterns detected; the code is a standard query options wrapper for ENS name resolution with no network, filesystem, or process manipulation.
- `dist/esm/query/getEnsResolver.js` (safe): No malicious patterns detected
- `dist/esm/query/getEnsText.js` (safe): No malicious patterns detected
- `dist/esm/query/getFeeHistory.js` (safe): No malicious patterns detected; the code is a standard React Query options helper for fetching fee history via an existing internal action module.
- `dist/esm/query/getGasPrice.js` (safe): No malicious patterns detected in the provided source file; it is a straightforward query options helper for fetching gas price data.
- `dist/esm/query/getProof.js` (safe): No malicious patterns detected
- `dist/esm/query/getStorageAt.js` (safe): No malicious patterns detected
- `dist/esm/query/getToken.js` (safe): No malicious patterns detected; the file contains only standard query option builders for token data with no network, filesystem, or process execution behavior.
- `dist/esm/query/getTransaction.js` (safe): No malicious patterns detected; the code only builds query options and delegates to a local getTransaction action with no external calls, process spawning, or obfuscation.
- `dist/esm/query/getTransactionConfirmations.js` (safe): No malicious patterns detected; the code is a straightforward React Query options builder for transaction confirmations with no network, filesystem, process, or obfuscation concerns.
- `dist/esm/query/getTransactionCount.js` (safe): The code defines standard query options for fetching transaction counts and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning.
- `dist/esm/query/getTransactionReceipt.js` (safe): No malicious patterns detected; the code is a straightforward query options builder for fetching transaction receipts.
- `dist/esm/query/getWalletClient.js` (safe): No malicious patterns detected
- `dist/esm/query/infiniteReadContracts.js` (safe): No malicious patterns detected; the file contains standard query option builders for wagmi-style contract reads with no network, fs, process, or dynamic execution concerns.
- `dist/esm/query/prepareTransactionRequest.js` (safe): No malicious patterns detected; the file contains ordinary query option and query key helpers for blockchain transaction preparation.
- `dist/esm/query/readContract.js` (safe): No malicious patterns detected; the file contains standard React Query options for reading smart contracts via viem.
- `dist/esm/query/readContracts.js` (safe): No malicious patterns detected; the file contains standard query option construction for a blockchain read-contracts action without network, filesystem, process, or dynamic code execution behavior.
- `dist/esm/query/reconnect.js` (safe): No malicious patterns detected
- `dist/esm/query/sendCalls.js` (safe): No malicious patterns detected; the file only defines a thin wrapper around an imported sendCalls action with no network, filesystem, process, or dynamic execution behavior.
- `dist/esm/query/sendCallsSync.js` (safe): No malicious patterns detected; the file is a simple wrapper around an internal action function with no external calls, dynamic execution, or suspicious behavior.
- `dist/esm/query/sendTransaction.js` (safe): No malicious patterns detected
- `dist/esm/query/sendTransactionSync.js` (safe): No malicious patterns detected
- `dist/esm/query/showCallsStatus.js` (safe): The file is a thin wrapper that delegates to showCallsStatus and contains no malicious patterns.
- `dist/esm/query/signMessage.js` (safe): This file only defines a React Query mutation wrapper around an imported signMessage action with no network, filesystem, process, eval, or credential-related behavior.
- `dist/esm/query/signTypedData.js` (safe): No malicious patterns detected
- `dist/esm/query/simulateContract.js` (safe): No malicious patterns detected
- `dist/esm/query/switchAccount.js` (safe): No malicious patterns detected in the switchAccount.js wrapper file.
- `dist/esm/query/switchChain.js` (safe): No malicious patterns detected in the provided file; it only defines a mutation wrapper around a local switchChain action.
- `dist/esm/query/types.js` (safe): No malicious patterns detected
- `dist/esm/query/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/query/verifyMessage.js` (safe): No malicious patterns detected; the file only defines query option builders for verifying messages using imported library functions.
- `dist/esm/query/verifyTypedData.js` (safe): No malicious patterns detected; the code is a standard typed-data verification query helper with input validation and no exfiltration, obfuscation, dynamic execution, or install-time behavior.
- `dist/esm/query/waitForCallsStatus.js` (safe): No malicious patterns detected; the code is a standard query options helper for waiting on call statuses with no network, filesystem, credential, or code execution concerns.
- `dist/esm/query/waitForTransactionReceipt.js` (safe): No malicious patterns detected
- `dist/esm/query/watchAsset.js` (safe): No malicious patterns detected
- `dist/esm/query/writeContract.js` (safe): No malicious patterns detected; the file is a simple wrapper that delegates to an imported writeContract action.
- `dist/esm/transports/connector.js` (safe): No malicious patterns detected
- `dist/esm/transports/fallback.js` (safe): No malicious patterns detected
- `dist/esm/types/chain.js` (safe): No malicious patterns detected
- `dist/esm/types/properties.js` (safe): No malicious patterns detected
- `dist/esm/types/register.js` (safe): No malicious patterns detected
- `dist/esm/types/unit.js` (safe): No malicious patterns detected
- `dist/esm/types/utils.js` (safe): No malicious patterns detected
- `dist/esm/utils/cookie.js` (safe): No malicious patterns detected; the code is a standard cookie-based storage utility for reading, writing, and removing client-side cookies.
- `dist/esm/utils/deepEqual.js` (safe): The file contains a standard deep equality comparison utility with no network, filesystem, process, or dynamic code execution activity.
- `dist/esm/utils/deserialize.js` (safe): No malicious patterns detected; the code is a standard JSON deserializer with custom reviver for BigInt and Map, with no exfiltration, code execution, or other suspicious behavior.
- `dist/esm/utils/extractRpcUrls.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/utils/getAction.js` (safe): No malicious patterns detected
- `dist/esm/utils/getUnit.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/utils/getVersion.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/utils/normalizeChainId.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/utils/serialize.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/utils/uid.js` (safe): No malicious patterns detected
- `dist/esm/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/actions/call.ts` (safe): No malicious patterns detected; the code is a straightforward wrapper around viem's call action with no data exfiltration, dynamic execution, or suspicious behavior.
- `src/actions/codegen/createReadContract.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/actions/codegen/createSimulateContract.ts` (safe): No malicious patterns detected; the file only contains type-safe wrappers for a viem contract simulation API without network, file system, environment, or process access.
- `src/actions/codegen/createWatchContractEvent.ts` (safe): No malicious patterns detected; the code is a standard Viem action creator for watching contract events with no network, filesystem, or process manipulation.
- `src/actions/codegen/createWriteContract.ts` (safe): No malicious patterns detected; the code is a type-safe wrapper for viem's writeContract with no external data exfiltration, dynamic execution, or suspicious behavior.
- `src/actions/connect.ts` (safe): No malicious patterns detected
- `src/actions/deployContract.ts` (safe): No malicious patterns detected; the code is a standard wagmi action wrapper for viem's deployContract with no exfiltration, obfuscation, or suspicious behavior.
- `src/actions/disconnect.ts` (safe): The code is a standard disconnect action for the wagmi library and contains no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
- `src/actions/estimateFeesPerGas.ts` (safe): No malicious patterns detected; the file contains standard viem-based fee estimation logic with no exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
- `src/actions/estimateGas.ts` (safe): No malicious patterns detected; the code is a standard viem/wagmi action wrapper for estimating gas.
- `src/actions/estimateMaxPriorityFeePerGas.ts` (safe): No malicious patterns detected; the code is a straightforward viem action wrapper with no suspicious behavior.
- `src/actions/getAccount.ts` (safe): This TypeScript file defines a typed getAccount action for a viem-based connector library and contains no malicious patterns, external calls, credential access, or dynamic code execution.
- `src/actions/getBalance.ts` (safe): No malicious patterns detected; the code is a straightforward wagmi/viem balance retrieval action with no network exfiltration, credential harvesting, or obfuscation.
- `src/actions/getBlock.ts` (safe): No malicious patterns detected; the code is a standard wagmi/viem wrapper for fetching blockchain blocks with no exfiltration, obfuscation, or process execution.
- `src/actions/getBlockNumber.ts` (safe): No malicious patterns detected
- `src/actions/getBlockTransactionCount.ts` (safe): No malicious patterns detected; the file is a standard wagmi action wrapper around viem's getBlockTransactionCount with no network, filesystem, or code execution side effects.
- `src/actions/getBytecode.ts` (safe): No malicious patterns detected
- `src/actions/getCallsStatus.ts` (safe): No malicious patterns detected; the code is a straightforward wagmi action wrapper that delegates to viem's getCallsStatus via a connector client.
- `src/actions/getCapabilities.ts` (safe): No malicious patterns detected
- `src/actions/getChainId.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/actions/getChains.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/actions/getClient.ts` (safe): No malicious patterns detected; the code is a standard typed wrapper around a viem client getter with no network, filesystem, process, or dynamic execution concerns.
- `src/actions/getConnections.ts` (safe): No malicious patterns detected in this small utility function that reads local state and caches previous connections.
- `src/actions/getConnectorClient.ts` (safe): This is legitimate wagmi connector client code that creates viem clients for wallet connectors without any malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or process spawning.
- `src/actions/getConnectors.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/actions/getEnsAddress.ts` (safe): No malicious patterns detected
- `src/actions/getEnsAvatar.ts` (safe): No malicious patterns detected; the code is a straightforward viem action wrapper for retrieving ENS avatars with no data exfiltration, credential access, obfuscation, or process/network anomalies.
- `src/actions/getEnsName.ts` (safe): No malicious patterns detected; the code is a straightforward wrapper around viem's getEnsName action with no exfiltration, obfuscation, process spawning, or suspicious behavior.
- `src/actions/getEnsResolver.ts` (safe): No malicious patterns detected; this is a standard wagmi action wrapper around viem's getEnsResolver with no exfiltration, exec, or obfuscated code.
- `src/actions/getEnsText.ts` (safe): No malicious patterns detected
- `src/actions/getFeeHistory.ts` (safe): No malicious patterns detected; this is a standard wagmi action wrapper around viem's getFeeHistory with no network, filesystem, or code execution concerns.
- `src/actions/getGasPrice.ts` (safe): No malicious patterns detected
- `src/actions/getProof.ts` (safe): No malicious patterns detected
- `src/actions/getPublicClient.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/actions/getStorageAt.ts` (safe): No malicious patterns detected; the file simply wraps viem's getStorageAt action for use with wagmi configuration.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
