Summary
Togoder Security scanned the npm package next-themes@0.4.6 on Oct 6, 2026. An AI review of 2 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
dynamic code execution
NPS-B13F43EB0CD9
The code injects the stringified source of the theme initialization function M into a <script> tag using dangerouslySetInnerHTML with __html. While this is a common pattern for preventing flash-of-unstyled-content in SSR frameworks like Next.js, it constitutes dynamic script injection and could be exploited if the function source were altered in a compromised package.
browser storage access
NPS-7880F61B80AD
Reads and writes to localStorage using the configurable storageKey (default 'theme'), which is expected behavior for a theme provider but represents client-side persistence outside typical React state.
DOM manipulation
NPS-AC2D4737B7E8
Directly manipulates document.documentElement attributes/classes and injects a <style> element to disable transitions. This is within the intended scope of a theme provider but crosses typical component boundaries.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.mjs | medium | No clear malicious intent; the code is a standard Next.js theme provider using dynamic script injection and DOM/localStorage manipulation for legitimate theme handling. |
| dist/index.js | safe | No malicious patterns detected; this is the legitimate next-themes library with expected theme-management behavior including localStorage and DOM manipulation. |
Scanned versions of next-themes
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 0.4.6 | Needs review | 2 | Oct 6, 2026 |
Frequently asked questions
Is next-themes safe to use?
No confirmed malware was found in next-themes@0.4.6, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does next-themes contain malware?
No malware was identified in next-themes@0.4.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was next-themes checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan next-themes together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in next-themes@0.4.6, cost nothing.