# @walletconnect/heartbeat@1.2.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:19:49.000Z
- Files reviewed: 3
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@walletconnect/heartbeat
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/heartbeat@1.2.2 on Oct 4, 2026. An AI review of 3 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] no malicious patterns

Finding ID: `NPS-FAF29E0BA880`

File: `dist/index.es.js`

The code implements a simple HeartBeat class using EventEmitter and setInterval. No data exfiltration, credential harvesting, obfuscation, dynamic code execution, cryptocurrency mining, backdoor, suspicious network requests, file system manipulation, process spawning, or dynamic imports were found. The setInterval is used only for emitting heartbeat pulses.

## Files reviewed

- `dist/index.cjs.js` (safe): The code implements a simple heartbeat event emitter using standard Node.js events and WalletConnect libraries, with no malicious patterns detected.
- `dist/index.es.js` (safe): No malicious patterns detected in the provided JavaScript file.
- `dist/index.umd.js` (safe): No malicious patterns detected; the code implements a standard EventEmitter-based heartbeat utility for WalletConnect without any data exfiltration, obfuscation, dynamic execution, or suspicious network/file/process activity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
