# @walletconnect/sign-client@2.21.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:44.000Z
- Files reviewed: 2
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/sign-client@2.21.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/sign-client@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Deeplink handling

Finding ID: `NPS-E10C3433B41C`

File: `dist/index.cjs.js`

The code reads and processes deep links via getDeepLink and handleDeeplinkRedirect, which can redirect users to external apps. This is a standard WalletConnect feature but could be abused for phishing if the input is not properly validated.

### [low] External network communication

Finding ID: `NPS-45B7E72BD9F2`

File: `dist/index.cjs.js`

The package makes network connections to a hardcoded WebSocket relay URL 'wss://relay.walletconnect.org' and potentially other external services. This is expected for WalletConnect, but it means data (session metadata, encrypted payloads) is sent externally.

### [low] Dynamic code execution

Finding ID: `NPS-9C0BD34D3426`

File: `dist/index.cjs.js`

The code uses global.Linking.openURL to open URLs dynamically, which could be exploited if an attacker controls the URL. However, this is part of the intended link-mode feature and URLs are constructed from internal data.

## Files reviewed

- `dist/index.cjs.js` (medium): This is the official WalletConnect SignClient library. While it performs external network communication and dynamic URL opening as part of its intended functionality, no malicious patterns such as credential harvesting, obfuscation, backdoors, or unauthorized file system access were detected.
- `dist/index.es.js` (safe): No malicious patterns detected; this is a legitimate WalletConnect SignClient library with standard cryptographic and relay communication code.

## Version ranges

None of the 2 scanned versions of @walletconnect/sign-client are flagged high or critical. The latest scanned version, 2.21.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.21.0 – 2.21.1 (`>=2.21.0 <=2.21.1`): medium (Deeplink handling)
- 2.19.0 – 2.19.1 (`>=2.19.0 <=2.19.1`): not scanned

## Scanned versions

- [2.21.1](https://security.togoder.click/npm/@walletconnect/sign-client@2.21.1): medium, 2026-10-04T16:54:44.000Z
- [2.21.0](https://security.togoder.click/npm/@walletconnect/sign-client@2.21.0): medium, 2026-10-04T16:54:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
