# preact@10.29.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:49.000Z
- Files reviewed: 80
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/preact
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package preact@10.29.8 on Oct 6, 2026. An AI review of 80 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] debug/development tooling

Finding ID: `NPS-0388FDBF0C4C`

File: `debug/dist/debug.mjs`

This file is the official Preact debug package (preact/debug) compiled to ESM. It only contains development-time warnings, prop-type validation, and DOM nesting checks. It does not perform network requests, spawn processes, read credentials, execute dynamic code, or manipulate the file system.

### [low] debug/development tooling

Finding ID: `NPS-0388FDBF0C4C`

File: `debug/dist/debug.module.js`

This file is the official Preact debug package (preact/debug) compiled to ESM. It only contains development-time warnings, prop-type validation, and DOM nesting checks. It does not perform network requests, spawn processes, read credentials, execute dynamic code, or manipulate the file system.

### [low] Module import side effects

Finding ID: `NPS-91D9BD86A312`

File: `debug/src/index.js:2`

The file imports 'preact/devtools' which is typically a development-only module. Importing devtools can attach global hooks (e.g., to window) and expose internal component state. In a production bundle this could unintentionally expose debug/devtools interfaces if not properly tree-shaken.

### [low] Top-level code execution on import

Finding ID: `NPS-AF323E193703`

File: `debug/src/index.js:4`

initDebug() is called at module import time, which runs code immediately when the module is loaded. While this is a common pattern for debug initialization, it means any side effects from initDebug execute during import without explicit user action.

## Files reviewed

- `debug/src/index.js` (medium): The file contains only legitimate Preact debug initialization and exports with no malicious patterns; minor concerns are import-time side effects typical of debug tooling.
- `compat/client.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/client.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `compat/dist/compat.js` (safe): This is the legitimate Preact compatibility layer for React, containing no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or unauthorized process execution.
- `compat/dist/compat.mjs` (safe): This is the official preact/compat build (v18.3.1), containing only React compatibility shims and no malicious patterns.
- `compat/dist/compat.module.js` (safe): This is the official preact/compat build (v18.3.1), containing only React compatibility shims and no malicious patterns.
- `compat/dist/compat.umd.js` (safe): No malicious patterns detected; the file is a standard Preact compatibility layer for React-like APIs.
- `compat/jsx-dev-runtime.js` (safe): No malicious patterns detected
- `compat/jsx-dev-runtime.mjs` (safe): No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
- `compat/jsx-runtime.js` (safe): No malicious patterns detected
- `compat/jsx-runtime.mjs` (safe): No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
- `compat/scheduler.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/scheduler.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `compat/server.browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/server.js` (safe): No malicious patterns detected; the file is a legitimate compatibility shim for Preact server-side rendering.
- `compat/server.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/Children.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/PureComponent.js` (safe): No malicious patterns detected; the code is a standard PureComponent compatibility shim for Preact.
- `compat/src/forwardRef.js` (safe): No malicious patterns detected; the code is a standard Preact forwardRef compatibility shim with no network, filesystem, process, or dynamic execution activity.
- `compat/src/hooks.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/memo.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/portals.js` (safe): No malicious patterns detected; the code is a standard Preact portal implementation with no exfiltration, credential harvesting, obfuscation, or other security concerns.
- `compat/src/render.js` (safe): This is the Preact compatibility layer (preact/compat) implementing React API compatibility; no malicious patterns detected.
- `compat/src/suspense-list.js` (safe): No malicious patterns detected; the code is a legitimate Preact SuspenseList implementation with no security concerns.
- `compat/src/suspense.js` (safe): This is legitimate Preact Suspense compatibility code with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `compat/src/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/test-utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/test-utils.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `debug/dist/debug.js` (safe): This is the Preact debug build providing development-time warnings and validation—no malicious patterns, network calls, credential access, or dynamic code execution detected.
- `debug/dist/debug.mjs` (safe): The file is the legitimate Preact debug module containing only development-time diagnostics and no malicious patterns.
- `debug/dist/debug.module.js` (safe): The file is the legitimate Preact debug module containing only development-time diagnostics and no malicious patterns.
- `debug/dist/debug.umd.js` (safe): No malicious patterns detected; the code is a legitimate Preact debug utility that only adds development warnings and does not perform data exfiltration, environment harvesting, code execution, or network requests.
- `debug/src/check-props.js` (safe): Cleared by Jev triage; no further analysis needed
- `debug/src/component-stack.js` (safe): No malicious patterns detected
- `debug/src/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `debug/src/debug.js` (safe): No malicious patterns detected in the debug module; the code only provides development-time validation, warnings, and error handling for the Preact framework.
- `debug/src/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `devtools/dist/devtools.js` (safe): No malicious patterns detected
- `devtools/dist/devtools.mjs` (safe): This is a minified Preact DevTools integration module that only registers a hook name and attaches to the global Preact DevTools object; no malicious patterns detected.
- `devtools/dist/devtools.module.js` (safe): This is a minified Preact DevTools integration module that only registers a hook name and attaches to the global Preact DevTools object; no malicious patterns detected.
- `devtools/dist/devtools.umd.js` (safe): No malicious patterns detected; the code is a standard Preact DevTools UMD bundle that only attaches a devtools hook and adds a hook name.
- `devtools/src/devtools.js` (safe): The code is a standard Preact DevTools integration hook that only conditionally attaches devtools to a global object with no malicious patterns.
- `devtools/src/index.js` (safe): No malicious patterns detected
- `dist/preact.js` (safe): No malicious patterns detected; this is the standard minified Preact library with no data exfiltration, obfuscated payloads, or suspicious behavior.
- `dist/preact.min.module.js` (safe): This is the official Preact library minified bundle; it contains no malicious patterns, network exfiltration, credential harvesting, obfuscated payloads, or suspicious process execution.
- `dist/preact.min.umd.js` (safe): This is the minified UMD build of the Preact library, a legitimate JavaScript UI framework, with no malicious patterns detected.
- `dist/preact.mjs` (safe): This is the minified distribution of the Preact library, containing only legitimate UI rendering logic with no malicious patterns or suspicious behavior.
- `dist/preact.module.js` (safe): This is the minified distribution of the Preact library, containing only legitimate UI rendering logic with no malicious patterns or suspicious behavior.
- `dist/preact.umd.js` (safe): This is the official Preact UMD distribution and contains only standard framework code with no malicious patterns detected.
- `hooks/dist/hooks.js` (safe): No malicious patterns detected; this is a minified build of the Preact hooks library with no obfuscation, network calls, filesystem access, or process spawning.
- `hooks/dist/hooks.mjs` (safe): No malicious patterns detected; the file is a standard Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
- `hooks/dist/hooks.module.js` (safe): No malicious patterns detected; the file is a standard Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
- `hooks/dist/hooks.umd.js` (safe): No malicious patterns detected
- `hooks/src/index.js` (safe): This is the legitimate Preact hooks implementation from the official preact package, containing no malicious patterns such as data exfiltration, credential harvesting, code execution, or network activity.
- `jsx-runtime/dist/jsxRuntime.js` (safe): No malicious patterns detected
- `jsx-runtime/dist/jsxRuntime.mjs` (safe): No malicious patterns detected; the file is a standard Preact JSX runtime with only benign escaping, VNode creation, and attribute serialization helpers.
- `jsx-runtime/dist/jsxRuntime.module.js` (safe): No malicious patterns detected; the file is a standard Preact JSX runtime with only benign escaping, VNode creation, and attribute serialization helpers.
- `jsx-runtime/dist/jsxRuntime.umd.js` (safe): This is the Preact JSX runtime UMD bundle and contains no malicious patterns; all functionality is limited to JSX creation and attribute escaping.
- `jsx-runtime/src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `jsx-runtime/src/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/cjs.js` (safe): No malicious patterns detected
- `src/clone-element.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/component.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/create-context.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/create-element.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/diff/catch-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/diff/children.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/diff/index.js` (safe): No malicious patterns detected
- `src/diff/props.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/options.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/render.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `test-utils/dist/testUtils.js` (safe): No malicious patterns detected; code is a standard Preact test utility for controlling rendering timing.
- `test-utils/dist/testUtils.mjs` (safe): No malicious patterns detected; the code is a Preact test utility that temporarily intercepts rendering and requestAnimationFrame, with no network, filesystem, process, or credential access.
- `test-utils/dist/testUtils.module.js` (safe): No malicious patterns detected; the code is a Preact test utility that temporarily intercepts rendering and requestAnimationFrame, with no network, filesystem, process, or credential access.
- `test-utils/dist/testUtils.umd.js` (safe): No malicious patterns detected; the code is a legitimate Preact test utility implementing act() and rerender helpers.
- `test-utils/src/index.js` (safe): No malicious patterns detected; this is a legitimate Preact test utility for managing render queues and act() semantics.

## Version ranges

None of the 2 scanned versions of preact are flagged high or critical. The latest scanned version, 10.29.8, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 10.29.8 (`10.29.8`): medium
- 10.24.3 (`10.24.3`): not scanned
- 10.24.2 (`10.24.2`): medium

## Scanned versions

- [10.29.8](https://security.togoder.click/npm/preact@10.29.8): medium, 2026-10-06T14:23:49.000Z
- [10.24.2](https://security.togoder.click/npm/preact@10.24.2): medium, 2026-10-04T16:39:15.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
