Togoder security

npm package security report

preact npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 10.29.8 Files reviewed 80 Size 318.8 KB Scanned

Summary

Togoder Security scanned the npm package preact@10.29.8 on Oct 6, 2026. An AI review of 80 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

debug/development tooling

NPS-0388FDBF0C4C

This file is the official Preact debug package (preact/debug) compiled to ESM. It only contains development-time warnings, prop-type validation, and DOM nesting checks. It does not perform network requests, spawn processes, read credentials, execute dynamic code, or manipulate the file system.

debug/dist/debug.mjs
low

debug/development tooling

NPS-0388FDBF0C4C

This file is the official Preact debug package (preact/debug) compiled to ESM. It only contains development-time warnings, prop-type validation, and DOM nesting checks. It does not perform network requests, spawn processes, read credentials, execute dynamic code, or manipulate the file system.

debug/dist/debug.module.js
low

Module import side effects

NPS-91D9BD86A312

The file imports 'preact/devtools' which is typically a development-only module. Importing devtools can attach global hooks (e.g., to window) and expose internal component state. In a production bundle this could unintentionally expose debug/devtools interfaces if not properly tree-shaken.

debug/src/index.js:2
low

Top-level code execution on import

NPS-AF323E193703

initDebug() is called at module import time, which runs code immediately when the module is loaded. While this is a common pattern for debug initialization, it means any side effects from initDebug execute during import without explicit user action.

debug/src/index.js:4

Files reviewed

FileVerdictWhat the reviewer saw
debug/src/index.js medium The file contains only legitimate Preact debug initialization and exports with no malicious patterns; minor concerns are import-time side effects typical of debug tooling.
compat/client.js safe Cleared by Jev triage; no further analysis needed
compat/client.mjs safe Cleared by Jev triage; no further analysis needed
compat/dist/compat.js safe This is the legitimate Preact compatibility layer for React, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized process execution.
compat/dist/compat.mjs safe This is the official preact/compat build (v18.3.1), containing only React compatibility shims and no malicious patterns.
compat/dist/compat.module.js safe This is the official preact/compat build (v18.3.1), containing only React compatibility shims and no malicious patterns.
compat/dist/compat.umd.js safe No malicious patterns detected; the file is a standard Preact compatibility layer for React-like APIs.
compat/jsx-dev-runtime.js safe No malicious patterns detected
compat/jsx-dev-runtime.mjs safe No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
compat/jsx-runtime.js safe No malicious patterns detected
compat/jsx-runtime.mjs safe No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
compat/scheduler.js safe Cleared by Jev triage; no further analysis needed
compat/scheduler.mjs safe Cleared by Jev triage; no further analysis needed
compat/server.browser.js safe Cleared by Jev triage; no further analysis needed
compat/server.js safe No malicious patterns detected; the file is a legitimate compatibility shim for Preact server-side rendering.
compat/server.mjs safe Cleared by Jev triage; no further analysis needed
compat/src/Children.js safe Cleared by Jev triage; no further analysis needed
compat/src/PureComponent.js safe No malicious patterns detected; the code is a standard PureComponent compatibility shim for Preact.
compat/src/forwardRef.js safe No malicious patterns detected; the code is a standard Preact forwardRef compatibility shim with no network, filesystem, process, or dynamic execution activity.
compat/src/hooks.js safe Cleared by Jev triage; no further analysis needed
compat/src/index.js safe Cleared by Jev triage; no further analysis needed
compat/src/memo.js safe Cleared by Jev triage; no further analysis needed
compat/src/portals.js safe No malicious patterns detected; the code is a standard Preact portal implementation with no exfiltration, credential harvesting, obfuscation, or other security concerns.
compat/src/render.js safe This is the Preact compatibility layer (preact/compat) implementing React API compatibility; no malicious patterns detected.
compat/src/suspense-list.js safe No malicious patterns detected; the code is a legitimate Preact SuspenseList implementation with no security concerns.
Show 55 more files
FileVerdictWhat the reviewer saw
compat/src/suspense.js safe This is legitimate Preact Suspense compatibility code with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
compat/src/util.js safe Cleared by Jev triage; no further analysis needed
compat/test-utils.js safe Cleared by Jev triage; no further analysis needed
compat/test-utils.mjs safe Cleared by Jev triage; no further analysis needed
debug/dist/debug.js safe This is the Preact debug build providing development-time warnings and validation—no malicious patterns, network calls, credential access, or dynamic code execution detected.
debug/dist/debug.mjs safe The file is the legitimate Preact debug module containing only development-time diagnostics and no malicious patterns.
debug/dist/debug.module.js safe The file is the legitimate Preact debug module containing only development-time diagnostics and no malicious patterns.
debug/dist/debug.umd.js safe No malicious patterns detected; the code is a legitimate Preact debug utility that only adds development warnings and does not perform data exfiltration, environment harvesting, code execution, or network requests.
debug/src/check-props.js safe Cleared by Jev triage; no further analysis needed
debug/src/component-stack.js safe No malicious patterns detected
debug/src/constants.js safe Cleared by Jev triage; no further analysis needed
debug/src/debug.js safe No malicious patterns detected in the debug module; the code only provides development-time validation, warnings, and error handling for the Preact framework.
debug/src/util.js safe Cleared by Jev triage; no further analysis needed
devtools/dist/devtools.js safe No malicious patterns detected
devtools/dist/devtools.mjs safe This is a minified Preact DevTools integration module that only registers a hook name and attaches to the global Preact DevTools object; no malicious patterns detected.
devtools/dist/devtools.module.js safe This is a minified Preact DevTools integration module that only registers a hook name and attaches to the global Preact DevTools object; no malicious patterns detected.
devtools/dist/devtools.umd.js safe No malicious patterns detected; the code is a standard Preact DevTools UMD bundle that only attaches a devtools hook and adds a hook name.
devtools/src/devtools.js safe The code is a standard Preact DevTools integration hook that only conditionally attaches devtools to a global object with no malicious patterns.
devtools/src/index.js safe No malicious patterns detected
dist/preact.js safe No malicious patterns detected; this is the standard minified Preact library with no data exfiltration, obfuscated payloads, or suspicious behavior.
dist/preact.min.module.js safe This is the official Preact library minified bundle; it contains no malicious patterns, network exfiltration, credential harvesting, obfuscated payloads, or suspicious process execution.
dist/preact.min.umd.js safe This is the minified UMD build of the Preact library, a legitimate JavaScript UI framework, with no malicious patterns detected.
dist/preact.mjs safe This is the minified distribution of the Preact library, containing only legitimate UI rendering logic with no malicious patterns or suspicious behavior.
dist/preact.module.js safe This is the minified distribution of the Preact library, containing only legitimate UI rendering logic with no malicious patterns or suspicious behavior.
dist/preact.umd.js safe This is the official Preact UMD distribution and contains only standard framework code with no malicious patterns detected.
hooks/dist/hooks.js safe No malicious patterns detected; this is a minified build of the Preact hooks library with no obfuscation, network calls, filesystem access, or process spawning.
hooks/dist/hooks.mjs safe No malicious patterns detected; the file is a standard Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
hooks/dist/hooks.module.js safe No malicious patterns detected; the file is a standard Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
hooks/dist/hooks.umd.js safe No malicious patterns detected
hooks/src/index.js safe This is the legitimate Preact hooks implementation from the official preact package, containing no malicious patterns such as data exfiltration, credential harvesting, code execution, or network activity.
jsx-runtime/dist/jsxRuntime.js safe No malicious patterns detected
jsx-runtime/dist/jsxRuntime.mjs safe No malicious patterns detected; the file is a standard Preact JSX runtime with only benign escaping, VNode creation, and attribute serialization helpers.
jsx-runtime/dist/jsxRuntime.module.js safe No malicious patterns detected; the file is a standard Preact JSX runtime with only benign escaping, VNode creation, and attribute serialization helpers.
jsx-runtime/dist/jsxRuntime.umd.js safe This is the Preact JSX runtime UMD bundle and contains no malicious patterns; all functionality is limited to JSX creation and attribute escaping.
jsx-runtime/src/index.js safe Cleared by Jev triage; no further analysis needed
jsx-runtime/src/utils.js safe Cleared by Jev triage; no further analysis needed
src/cjs.js safe No malicious patterns detected
src/clone-element.js safe Cleared by Jev triage; no further analysis needed
src/component.js safe Cleared by Jev triage; no further analysis needed
src/constants.js safe Cleared by Jev triage; no further analysis needed
src/create-context.js safe Cleared by Jev triage; no further analysis needed
src/create-element.js safe Cleared by Jev triage; no further analysis needed
src/diff/catch-error.js safe Cleared by Jev triage; no further analysis needed
src/diff/children.js safe Cleared by Jev triage; no further analysis needed
src/diff/index.js safe No malicious patterns detected
src/diff/props.js safe Cleared by Jev triage; no further analysis needed
src/index.js safe Cleared by Jev triage; no further analysis needed
src/options.js safe Cleared by Jev triage; no further analysis needed
src/render.js safe Cleared by Jev triage; no further analysis needed
src/util.js safe Cleared by Jev triage; no further analysis needed
test-utils/dist/testUtils.js safe No malicious patterns detected; code is a standard Preact test utility for controlling rendering timing.
test-utils/dist/testUtils.mjs safe No malicious patterns detected; the code is a Preact test utility that temporarily intercepts rendering and requestAnimationFrame, with no network, filesystem, process, or credential access.
test-utils/dist/testUtils.module.js safe No malicious patterns detected; the code is a Preact test utility that temporarily intercepts rendering and requestAnimationFrame, with no network, filesystem, process, or credential access.
test-utils/dist/testUtils.umd.js safe No malicious patterns detected; the code is a legitimate Preact test utility implementing act() and rerender helpers.
test-utils/src/index.js safe No malicious patterns detected; this is a legitimate Preact test utility for managing render queues and act() semantics.

Affected version ranges

None of the 2 scanned versions of preact are flagged high or critical. The latest scanned version, 10.29.8, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

10.24.210.29.8
VersionsVerdictCountRangeTop findings
10.29.8 Needs review 1 10.29.8
10.24.3 Not scanned 1 10.24.3
10.24.2 Needs review 1 10.24.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of preact

VersionVerdictFilesScanned
10.29.8 Needs review 80 Oct 6, 2026
10.24.2 Needs review 78 Oct 4, 2026

Frequently asked questions

Is preact safe to use?

No confirmed malware was found in preact@10.29.8, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does preact contain malware?

No malware was identified in preact@10.29.8 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was preact checked?

Togoder Security downloaded the published npm package and had an AI model read its 80 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan preact together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in preact@10.29.8, cost nothing.

Related security reports