# preact@10.24.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:39:15.000Z
- Files reviewed: 78
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/preact@10.24.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package preact@10.24.2 on Oct 4, 2026. An AI review of 78 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Code runs at import time

Finding ID: `NPS-6AF7802EF0C9`

File: `devtools/dist/devtools.umd.js:1`

The UMD wrapper executes immediately upon import/require. It reads globalThis/window/self and conditionally calls attachPreact from the global __PREACT_DEVTOOLS__ object. While typical for UMD bundles, top-level code execution on import is a notable behavior.

### [low] Global object mutation

Finding ID: `NPS-A60E84860036`

File: `devtools/dist/devtools.umd.js:1`

The module attaches itself to a global name (preactDevtools) and calls into a globally-named __PREACT_DEVTOOLS__ object. This is standard for devtools integration but does modify global scope.

## Files reviewed

- `devtools/dist/devtools.umd.js` (medium): Small Preact DevTools UMD bundle with no obvious malicious behavior; only standard UMD bootstrapping and global hook attachment, though it does execute at import time.
- `compat/client.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/client.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `compat/dist/compat.js` (safe): No malicious patterns detected; the file is a legitimate Preact compatibility layer for React APIs.
- `compat/dist/compat.mjs` (safe): No malicious patterns detected; this is the standard Preact compatibility layer for React.
- `compat/dist/compat.module.js` (safe): No malicious patterns detected; this is the standard Preact compatibility layer for React.
- `compat/dist/compat.umd.js` (safe): No malicious patterns detected; this is a legitimate Preact compatibility layer for React.
- `compat/jsx-dev-runtime.js` (safe): No malicious patterns detected
- `compat/jsx-dev-runtime.mjs` (safe): No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
- `compat/jsx-runtime.js` (safe): No malicious patterns detected
- `compat/jsx-runtime.mjs` (safe): No malicious patterns detected: the file only re-exports Preact's official jsx-runtime and imports its compat layer with no dynamic execution, network access, or filesystem manipulation.
- `compat/scheduler.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/scheduler.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `compat/server.browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/server.js` (safe): No malicious patterns detected; the file only wraps preact-render-to-string module exports.
- `compat/server.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/Children.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/PureComponent.js` (safe): No malicious patterns detected; the code is a standard PureComponent compatibility shim for Preact.
- `compat/src/forwardRef.js` (safe): No malicious patterns detected; the code is a legitimate Preact compatibility shim implementing React.forwardRef semantics.
- `compat/src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/memo.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/src/portals.js` (safe): No malicious patterns detected; the code is a legitimate Preact Portal implementation with no network, filesystem, process, or obfuscation concerns.
- `compat/src/render.js` (safe): No malicious patterns detected; the file is a standard Preact-React compatibility layer with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `compat/src/suspense-list.js` (safe): No malicious patterns detected; the code is a legitimate Preact SuspenseList implementation with no security concerns.
- `compat/src/suspense.js` (safe): No malicious patterns detected; the code is a legitimate Preact compat module implementing Suspense/lazy functionality.
- `compat/src/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `compat/test-utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `debug/dist/debug.js` (safe): No malicious patterns detected; the code is a standard Preact debug utility that adds development-time warnings and does not exfiltrate data or execute untrusted code.
- `debug/dist/debug.mjs` (safe): No malicious patterns detected; the code is a legitimate Preact debug utility that only performs console warnings and error checks.
- `debug/dist/debug.module.js` (safe): No malicious patterns detected; the code is a legitimate Preact debug utility that only performs console warnings and error checks.
- `debug/dist/debug.umd.js` (safe): No malicious patterns detected; this is a legitimate Preact debug utility that warns about common React/Preact development mistakes.
- `debug/src/check-props.js` (safe): Cleared by Jev triage; no further analysis needed
- `debug/src/component-stack.js` (safe): No malicious patterns detected
- `debug/src/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `debug/src/debug.js` (safe): No malicious patterns detected
- `debug/src/index.js` (safe): No malicious patterns detected; the file only imports debug utilities and Preact devtools, then exports a reset function.
- `debug/src/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `devtools/dist/devtools.js` (safe): No malicious patterns detected
- `devtools/dist/devtools.mjs` (safe): No malicious patterns detected
- `devtools/dist/devtools.module.js` (safe): No malicious patterns detected
- `devtools/src/devtools.js` (safe): No malicious patterns detected; the code only integrates with a pre-existing global Preact DevTools hook.
- `devtools/src/index.js` (safe): No malicious patterns detected
- `dist/preact.js` (safe): No malicious patterns detected; this is a minified build of the Preact library with standard rendering and event handling code.
- `dist/preact.min.module.js` (safe): This is the minified Preact library (expected v10.x) implementing a virtual DOM renderer; no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, dynamic code execution, or process spawning were detected.
- `dist/preact.min.umd.js` (safe): This is a minified UMD build of Preact, a legitimate JavaScript library, with no malicious patterns detected.
- `dist/preact.mjs` (safe): This is the minified distribution build of Preact, a legitimate JavaScript UI library; no malicious patterns, obfuscation, exfiltration, or suspicious behavior were detected.
- `dist/preact.module.js` (safe): This is the minified distribution build of Preact, a legitimate JavaScript UI library; no malicious patterns, obfuscation, exfiltration, or suspicious behavior were detected.
- `dist/preact.umd.js` (safe): No malicious patterns detected
- `hooks/dist/hooks.js` (safe): No malicious patterns detected; the code is a standard Preact hooks implementation without data exfiltration, obfuscation, credential harvesting, or suspicious system/network activity.
- `hooks/dist/hooks.mjs` (safe): No malicious patterns detected; the code is a minified Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
- `hooks/dist/hooks.module.js` (safe): No malicious patterns detected; the code is a minified Preact hooks implementation with no network, filesystem, process, or dynamic code execution activity.
- `hooks/dist/hooks.umd.js` (safe): No malicious patterns detected; this is the standard Preact Hooks UMD library.
- `hooks/src/index.js` (safe): No malicious patterns detected
- `jsx-runtime/dist/jsxRuntime.js` (safe): This file is the standard Preact JSX runtime implementation and contains no malicious patterns, network calls, process spawning, or credential harvesting.
- `jsx-runtime/dist/jsxRuntime.mjs` (safe): No malicious patterns detected; the code is a standard Preact JSX runtime implementation with no network, filesystem, process, or dynamic code execution activity.
- `jsx-runtime/dist/jsxRuntime.module.js` (safe): No malicious patterns detected; the code is a standard Preact JSX runtime implementation with no network, filesystem, process, or dynamic code execution activity.
- `jsx-runtime/dist/jsxRuntime.umd.js` (safe): No malicious patterns detected; this is the standard Preact JSX runtime UMD build with only benign escaping and vnode creation logic.
- `jsx-runtime/src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `jsx-runtime/src/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/cjs.js` (safe): No malicious patterns detected
- `src/clone-element.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/component.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/create-context.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/create-element.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/diff/catch-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/diff/children.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/diff/index.js` (safe): No malicious patterns detected
- `src/diff/props.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/options.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/render.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/util.js` (safe): Cleared by Jev triage; no further analysis needed
- `test-utils/dist/testUtils.js` (safe): No malicious patterns detected
- `test-utils/dist/testUtils.mjs` (safe): This is legitimate Preact testing utility code that provides act() and setupRerender() functions for test environments, with no malicious patterns detected.
- `test-utils/dist/testUtils.module.js` (safe): This is legitimate Preact testing utility code that provides act() and setupRerender() functions for test environments, with no malicious patterns detected.
- `test-utils/dist/testUtils.umd.js` (safe): No malicious patterns detected
- `test-utils/src/index.js` (safe): No malicious patterns detected; the code is a legitimate Preact test utility for flushing renders and effects.

## Version ranges

None of the 2 scanned versions of preact are flagged high or critical. The latest scanned version, 10.29.8, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 10.29.8 (`10.29.8`): medium
- 10.24.3 (`10.24.3`): not scanned
- 10.24.2 (`10.24.2`): medium

## Scanned versions

- [10.29.8](https://security.togoder.click/npm/preact@10.29.8): medium, 2026-10-06T14:23:49.000Z
- [10.24.2](https://security.togoder.click/npm/preact@10.24.2): medium, 2026-10-04T16:39:15.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
