Togoder security

npm package security report

lit npm package: is it safe?

No malicious code found.

No issues Version 3.3.0 Files reviewed 77 Size 16.4 KB Scanned

Summary

Togoder Security scanned the npm package lit@3.3.0 on Oct 4, 2026. An AI review of 77 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
async-directive.js safe No malicious patterns detected
decorators.js safe No malicious patterns detected
decorators/custom-element.js safe Cleared by Jev triage; no further analysis needed
decorators/event-options.js safe The file simply re-exports a Lit decorator module with no malicious patterns or dynamic behavior.
decorators/property.js safe Cleared by Jev triage; no further analysis needed
decorators/query-all.js safe This file is a simple re-export of a Lit decorator module with no malicious patterns or execution at import time.
decorators/query-assigned-elements.js safe Cleared by Jev triage; no further analysis needed
decorators/query-assigned-nodes.js safe Cleared by Jev triage; no further analysis needed
decorators/query-async.js safe Cleared by Jev triage; no further analysis needed
decorators/query.js safe This file is a simple re-export shim for Lit's reactive-element query decorator with no malicious patterns detected.
decorators/state.js safe Cleared by Jev triage; no further analysis needed
development/async-directive.js safe Cleared by Jev triage; no further analysis needed
development/decorators.js safe Cleared by Jev triage; no further analysis needed
development/decorators/custom-element.js safe Cleared by Jev triage; no further analysis needed
development/decorators/event-options.js safe Cleared by Jev triage; no further analysis needed
development/decorators/property.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-all.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-assigned-elements.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-assigned-nodes.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query-async.js safe Cleared by Jev triage; no further analysis needed
development/decorators/query.js safe Cleared by Jev triage; no further analysis needed
development/decorators/state.js safe Cleared by Jev triage; no further analysis needed
development/directive-helpers.js safe Cleared by Jev triage; no further analysis needed
development/directive.js safe Cleared by Jev triage; no further analysis needed
development/directives/async-append.js safe Cleared by Jev triage; no further analysis needed
Show 52 more files
FileVerdictWhat the reviewer saw
development/directives/async-replace.js safe Cleared by Jev triage; no further analysis needed
development/directives/cache.js safe Cleared by Jev triage; no further analysis needed
development/directives/choose.js safe Cleared by Jev triage; no further analysis needed
development/directives/class-map.js safe Cleared by Jev triage; no further analysis needed
development/directives/guard.js safe Cleared by Jev triage; no further analysis needed
development/directives/if-defined.js safe Cleared by Jev triage; no further analysis needed
development/directives/join.js safe Cleared by Jev triage; no further analysis needed
development/directives/keyed.js safe Cleared by Jev triage; no further analysis needed
development/directives/live.js safe Cleared by Jev triage; no further analysis needed
development/directives/map.js safe Cleared by Jev triage; no further analysis needed
development/directives/range.js safe Cleared by Jev triage; no further analysis needed
development/directives/ref.js safe Cleared by Jev triage; no further analysis needed
development/directives/repeat.js safe Cleared by Jev triage; no further analysis needed
development/directives/style-map.js safe Cleared by Jev triage; no further analysis needed
development/directives/template-content.js safe Cleared by Jev triage; no further analysis needed
development/directives/unsafe-html.js safe Cleared by Jev triage; no further analysis needed
development/directives/unsafe-mathml.js safe Cleared by Jev triage; no further analysis needed
development/directives/unsafe-svg.js safe Cleared by Jev triage; no further analysis needed
development/directives/until.js safe Cleared by Jev triage; no further analysis needed
development/directives/when.js safe Cleared by Jev triage; no further analysis needed
development/html.js safe Cleared by Jev triage; no further analysis needed
development/index.all.js safe No malicious patterns detected
development/index.js safe No malicious patterns detected
development/polyfill-support.js safe The file is a simple re-export of lit-element/polyfill-support.js with no malicious patterns detected.
development/static-html.js safe Cleared by Jev triage; no further analysis needed
directive-helpers.js safe No malicious patterns detected
directive.js safe No malicious patterns detected
directives/async-append.js safe This file is a simple re-export of the 'lit-html/directives/async-append.js' module with a source map reference; no malicious patterns or suspicious behavior detected.
directives/async-replace.js safe This file is a simple re-export of lit-html's async-replace directive with no malicious patterns.
directives/cache.js safe No malicious patterns detected
directives/choose.js safe No malicious patterns detected; the file is a simple re-export of lit-html's choose directive.
directives/class-map.js safe No malicious patterns detected; the file is a simple re-export of a well-known lit-html directive with no executable or suspicious code.
directives/guard.js safe No malicious patterns detected; this file is a simple re-export of the lit-html guard directive.
directives/if-defined.js safe No malicious patterns detected; this is a simple re-export of a lit-html directive with a source map reference.
directives/join.js safe No malicious patterns detected
directives/keyed.js safe The file is a simple re-export of the lit-html keyed directive with no malicious patterns.
directives/live.js safe No malicious patterns detected
directives/map.js safe No malicious patterns detected; the file simply re-exports a lit-html directive.
directives/range.js safe The file is a simple re-export shim for lit-html's range directive and contains no malicious patterns.
directives/ref.js safe The file is a simple re-export of lit-html's ref directive with no malicious patterns detected.
directives/repeat.js safe This file is a simple re-export of an existing lit-html directive with no malicious patterns detected.
directives/style-map.js safe This file only re-exports the legitimate lit-html style-map directive with no malicious patterns detected.
directives/template-content.js safe The file is a simple re-export of the lit-html template-content directive with no malicious patterns detected.
directives/unsafe-html.js safe This is a simple re-export of the standard lit-html unsafe-html directive with no malicious patterns detected.
directives/unsafe-mathml.js safe No malicious patterns detected
directives/unsafe-svg.js safe No malicious patterns detected
directives/until.js safe No malicious patterns detected
directives/when.js safe No malicious patterns detected; the file is a simple re-export of a lit-html directive with no executable or suspicious code.
html.js safe No malicious patterns detected
index.js safe No malicious patterns detected
polyfill-support.js safe No malicious patterns detected; this is legitimate Google Lit/ShadyCSS polyfill support code.
static-html.js safe No malicious patterns detected

Scanned versions of lit

VersionVerdictFilesScanned
3.3.0 No issues 77 Oct 4, 2026

Frequently asked questions

Is lit safe to use?

Our AI source review of lit@3.3.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does lit contain malware?

No malware was identified in lit@3.3.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was lit checked?

Togoder Security downloaded the published npm package and had an AI model read its 77 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan lit together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in lit@3.3.0, cost nothing.

Related security reports