# next-themes@0.4.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:22:43.000Z
- Files reviewed: 2
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/next-themes
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package next-themes@0.4.6 on Oct 6, 2026. An AI review of 2 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] dynamic code execution

Finding ID: `NPS-B13F43EB0CD9`

File: `dist/index.mjs`

The code injects the stringified source of the theme initialization function M into a <script> tag using dangerouslySetInnerHTML with __html. While this is a common pattern for preventing flash-of-unstyled-content in SSR frameworks like Next.js, it constitutes dynamic script injection and could be exploited if the function source were altered in a compromised package.

### [low] browser storage access

Finding ID: `NPS-7880F61B80AD`

File: `dist/index.mjs`

Reads and writes to localStorage using the configurable storageKey (default 'theme'), which is expected behavior for a theme provider but represents client-side persistence outside typical React state.

### [low] DOM manipulation

Finding ID: `NPS-AC2D4737B7E8`

File: `dist/index.mjs`

Directly manipulates document.documentElement attributes/classes and injects a <style> element to disable transitions. This is within the intended scope of a theme provider but crosses typical component boundaries.

## Files reviewed

- `dist/index.mjs` (medium): No clear malicious intent; the code is a standard Next.js theme provider using dynamic script injection and DOM/localStorage manipulation for legitimate theme handling.
- `dist/index.js` (safe): No malicious patterns detected; this is the legitimate next-themes library with expected theme-management behavior including localStorage and DOM manipulation.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
