Togoder security

npm package security report

wagmi@2.19.5 security report

No malicious code found.

No issues Version 2.19.5 Files reviewed 174 Size 252.2 KB Scanned

Summary

Togoder Security scanned the npm package wagmi@2.19.5 on Oct 4, 2026. An AI review of 174 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/context.js safe No malicious patterns detected
dist/esm/errors/base.js safe No malicious patterns detected; the file only defines a simple error class extending a core library error.
dist/esm/errors/context.js safe Cleared by Jev triage; no further analysis needed
dist/esm/experimental/hooks/useWriteContracts.js safe No malicious patterns detected
dist/esm/exports/actions.js safe No malicious patterns detected
dist/esm/exports/actions/experimental.js safe The file is a harmless barrel re-export that forwards all exports from the legitimate @wagmi/core/experimental package with no malicious patterns, obfuscation, or external operations.
dist/esm/exports/chains.js safe No malicious patterns detected
dist/esm/exports/codegen.js safe The file is a simple barrel module that re-exports hooks and the @wagmi/core/codegen entrypoint with no malicious patterns detected.
dist/esm/exports/connectors.js safe The file is a simple barrel re-export of the @wagmi/connectors package with no suspicious or malicious patterns detected.
dist/esm/exports/experimental.js safe No malicious patterns detected; the file only contains re-exports of React hooks with deprecation notices.
dist/esm/exports/index.js safe This is a standard barrel export file for the wagmi library that re-exports React hooks and utilities with no dynamic code execution, network calls, filesystem access, or other malicious patterns.
dist/esm/exports/internal.js safe No malicious patterns detected
dist/esm/exports/query.js safe No malicious patterns detected; the file only re-exports query utilities from @wagmi/core and a local module.
dist/esm/hooks/codegen/createUseReadContract.js safe No malicious patterns detected; the code is a standard React hook factory for reading smart contracts via wagmi-like utilities.
dist/esm/hooks/codegen/createUseSimulateContract.js safe No malicious patterns detected; the code is a standard React hook factory for wagmi's useSimulateContract with no network, filesystem, or process activity.
dist/esm/hooks/codegen/createUseWatchContractEvent.js safe No malicious patterns detected; the code is a standard React hook factory for watching contract events.
dist/esm/hooks/codegen/createUseWriteContract.js safe No malicious patterns detected
dist/esm/hooks/useAccount.js safe No malicious patterns detected; the file is a standard wagmi React hook that reads account state and subscribes to account changes.
dist/esm/hooks/useAccountEffect.js safe No malicious patterns detected
dist/esm/hooks/useBalance.js safe No malicious patterns detected; the file is a standard React hook wrapper around wagmi's balance query with no exfiltration, dynamic execution, or suspicious behavior.
dist/esm/hooks/useBlock.js safe No malicious patterns detected; this is a legitimate wagmi React hook for fetching and watching blockchain blocks.
dist/esm/hooks/useBlockNumber.js safe This is a standard wagmi React hook for fetching block numbers; no malicious patterns, obfuscation, exfiltration, or dangerous operations were detected.
dist/esm/hooks/useBlockTransactionCount.js safe No malicious patterns detected
dist/esm/hooks/useBytecode.js safe No malicious patterns detected; the file is a standard React hook wrapper for wagmi bytecode querying with no exfiltration, obfuscation, or dynamic execution.
dist/esm/hooks/useCall.js safe The code is a standard React hook wrapper for wagmi's useCall, with no malicious patterns, external data flows, or dangerous operations detected.
Show 149 more files
FileVerdictWhat the reviewer saw
dist/esm/hooks/useCallsStatus.js safe No malicious patterns detected; the file is a standard wagmi React hook that delegates to internal query utilities without any suspicious behavior.
dist/esm/hooks/useCapabilities.js safe This is a standard React hook wrapper for wagmi's useCapabilities query with no malicious patterns detected.
dist/esm/hooks/useChainId.js safe No malicious patterns detected
dist/esm/hooks/useChains.js safe This is a legitimate Wagmi React hook for accessing blockchain chain configuration with no malicious patterns detected.
dist/esm/hooks/useClient.js safe No malicious patterns detected; this is a standard wagmi React hook that reads client state via useSyncExternalStore.
dist/esm/hooks/useConfig.js safe Cleared by Jev triage; no further analysis needed
dist/esm/hooks/useConnect.js safe No malicious patterns detected; the file is a standard React hook wrapper around @tanstack/react-query and @wagmi/core with no exfiltration, obfuscation, or dynamic execution.
dist/esm/hooks/useConnections.js safe No malicious patterns detected; the file is a standard React hook wrapper for wagmi's connection state management.
dist/esm/hooks/useConnectorClient.js safe No malicious patterns detected; the file is a standard React hook for Wagmi connector client management with no data exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/esm/hooks/useConnectors.js safe No malicious patterns detected; the file is a standard React hook wrapper around wagmi core connector APIs.
dist/esm/hooks/useDeployContract.js safe No malicious patterns detected
dist/esm/hooks/useDisconnect.js safe No malicious patterns detected; the file is a standard React hook wrapper for wagmi's disconnect mutation.
dist/esm/hooks/useEnsAddress.js safe No malicious patterns detected
dist/esm/hooks/useEnsAvatar.js safe No malicious patterns detected; the code is a standard React hook wrapper around wagmi's ENS avatar query logic with no exfiltration, obfuscation, or dangerous runtime behavior.
dist/esm/hooks/useEnsName.js safe No malicious patterns detected
dist/esm/hooks/useEnsResolver.js safe No malicious patterns detected
dist/esm/hooks/useEnsText.js safe No malicious patterns detected
dist/esm/hooks/useEstimateFeesPerGas.js safe No malicious patterns detected; the file is a standard Wagmi React hook for estimating gas fees with only normal imports and parameter composition.
dist/esm/hooks/useEstimateGas.js safe No malicious patterns detected
dist/esm/hooks/useEstimateMaxPriorityFeePerGas.js safe No malicious patterns detected
dist/esm/hooks/useFeeHistory.js safe No malicious patterns detected in the provided source code.
dist/esm/hooks/useGasPrice.js safe No malicious patterns detected
dist/esm/hooks/useInfiniteReadContracts.js safe No malicious patterns detected; the file is a straightforward React hook wrapper around wagmi's query utilities with no network, filesystem, process, or dynamic code execution concerns.
dist/esm/hooks/usePrepareTransactionRequest.js safe No malicious patterns detected
dist/esm/hooks/useProof.js safe No malicious patterns detected; the file is a standard React hook wrapper for wagmi's useProof query functionality.
dist/esm/hooks/usePublicClient.js safe Legitimate wagmi React hook that wraps @wagmi/core's public client with useSyncExternalStoreWithSelector; contains no malicious patterns, obfuscation, exfiltration, or dynamic execution.
dist/esm/hooks/useReadContract.js safe No malicious patterns detected
dist/esm/hooks/useReadContracts.js safe No malicious patterns detected; the code is a standard React hook wrapper for wagmi's useReadContracts with no suspicious behavior.
dist/esm/hooks/useReconnect.js safe No malicious patterns detected
dist/esm/hooks/useSendCalls.js safe This is a standard wagmi React hook wrapper around @tanstack/react-query with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
dist/esm/hooks/useSendCallsSync.js safe No malicious patterns detected in the reviewed source file.
dist/esm/hooks/useSendTransaction.js safe No malicious patterns detected; this is a standard React hook wrapper for wagmi's sendTransaction with no exfiltration, obfuscation, lifecycle execution, or suspicious network/file/process activity.
dist/esm/hooks/useSendTransactionSync.js safe This is a standard Wagmi React hook that wraps React Query's useMutation for sending transactions; no malicious patterns, data exfiltration, or suspicious behavior were detected.
dist/esm/hooks/useShowCallsStatus.js safe No malicious patterns detected
dist/esm/hooks/useSignMessage.js safe No malicious patterns detected
dist/esm/hooks/useSignTypedData.js safe No malicious patterns detected
dist/esm/hooks/useSimulateContract.js safe No malicious patterns detected
dist/esm/hooks/useStorageAt.js safe No malicious patterns detected; the file is a standard React hook wrapper around wagmi's storage query functionality with no data exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/esm/hooks/useSwitchAccount.js safe No malicious patterns detected
dist/esm/hooks/useSwitchChain.js safe No malicious patterns detected; this is a standard wagmi React hook for switching blockchain chains.
dist/esm/hooks/useSyncExternalStoreWithTracked.js safe No malicious patterns detected; the code is a legitimate React hook for optimized external store subscription.
dist/esm/hooks/useToken.js safe No malicious patterns detected
dist/esm/hooks/useTransaction.js safe No malicious patterns detected; the file is a standard React hook wrapper for wagmi transaction queries with no red flags.
dist/esm/hooks/useTransactionConfirmations.js safe No malicious patterns detected
dist/esm/hooks/useTransactionCount.js safe No malicious patterns detected; the file is a standard wagmi React hook for fetching transaction counts with no network, filesystem, process, or dynamic execution risks.
dist/esm/hooks/useTransactionReceipt.js safe No malicious patterns detected
dist/esm/hooks/useVerifyMessage.js safe No malicious patterns detected
dist/esm/hooks/useVerifyTypedData.js safe This is a standard React hook from the wagmi library that wraps ethers-style typed data verification; no malicious patterns, network exfiltration, credential harvesting, dynamic code execution, or lifecycle scripts were detected.
dist/esm/hooks/useWaitForCallsStatus.js safe No malicious patterns detected
dist/esm/hooks/useWaitForTransactionReceipt.js safe No malicious patterns detected
dist/esm/hooks/useWalletClient.js safe No malicious patterns detected; the file is a standard wagmi React hook implementation for retrieving a wallet client with no data exfiltration, credential harvesting, or suspicious behavior.
dist/esm/hooks/useWatchAsset.js safe Standard React hook wrapper for wagmi's watchAsset feature with no malicious patterns detected
dist/esm/hooks/useWatchBlockNumber.js safe No malicious patterns detected; this is a standard React hook from the wagmi library for watching block numbers.
dist/esm/hooks/useWatchBlocks.js safe No malicious patterns detected; the code is a standard React hook wrapper around @wagmi/core's watchBlocks utility with no network exfiltration, credential harvesting, dynamic execution, or suspicious behavior.
dist/esm/hooks/useWatchContractEvent.js safe No malicious patterns detected; the code is a standard React hook wrapper for wagmi's watchContractEvent with no exfiltration, obfuscation, or unsafe operations.
dist/esm/hooks/useWatchPendingTransactions.js safe No malicious patterns detected; the file is a standard wagmi React hook for watching pending transactions with no data exfiltration, dynamic code execution, or suspicious behavior.
dist/esm/hooks/useWriteContract.js safe No malicious patterns detected
dist/esm/hydrate.js safe No malicious patterns detected; the code is a standard React hydration component using @wagmi/core with no suspicious behavior.
dist/esm/types/properties.js safe No malicious patterns detected
dist/esm/utils/getVersion.js safe Cleared by Jev triage; no further analysis needed
dist/esm/utils/query.js safe No malicious patterns detected; the file only provides thin wrappers around @tanstack/react-query hooks with a custom query key hash function.
dist/esm/version.js safe Cleared by Jev triage; no further analysis needed
src/context.ts safe Cleared by Jev triage; no further analysis needed
src/errors/base.ts safe Cleared by Jev triage; no further analysis needed
src/errors/context.ts safe Cleared by Jev triage; no further analysis needed
src/experimental/hooks/useWriteContracts.ts safe No malicious patterns detected; this is a standard wagmi React hook for writing contracts using @tanstack/react-query with no exfiltration, obfuscation, or dangerous operations.
src/exports/actions.ts safe No malicious patterns detected; the file is a simple barrel re-export of @wagmi/core/actions.
src/exports/actions/experimental.ts safe No malicious patterns detected
src/exports/chains.ts safe Cleared by Jev triage; no further analysis needed
src/exports/codegen.ts safe No malicious patterns detected
src/exports/connectors.ts safe No malicious patterns detected; this is a simple re-export barrel file for @wagmi/connectors.
src/exports/experimental.ts safe No malicious patterns detected
src/exports/index.ts safe No malicious patterns detected
src/exports/internal.ts safe Cleared by Jev triage; no further analysis needed
src/exports/query.ts safe Cleared by Jev triage; no further analysis needed
src/hooks/codegen/createUseReadContract.ts safe This is a legitimate wagmi React hook factory for reading smart contracts with no malicious patterns, network requests, dynamic code execution, or file system access.
src/hooks/codegen/createUseSimulateContract.ts safe No malicious patterns detected in this React hook factory for wagmi contract simulation; it only contains standard type definitions and hook composition logic.
src/hooks/codegen/createUseWatchContractEvent.ts safe No malicious patterns detected; the file is a legitimate React hook factory for watching contract events with no suspicious behavior.
src/hooks/codegen/createUseWriteContract.ts safe No malicious patterns detected; the code is a standard React hook factory for wagmi's useWriteContract with only type definitions and callback wrapping.
src/hooks/useAccount.ts safe No malicious patterns detected
src/hooks/useAccountEffect.ts safe No malicious patterns detected
src/hooks/useBalance.ts safe This is a standard wagmi React hook for fetching wallet balances with no malicious patterns, no network exfiltration, no credential access, and no dynamic code execution.
src/hooks/useBlock.ts safe No malicious patterns detected
src/hooks/useBlockNumber.ts safe No malicious patterns detected in this React hook for fetching block numbers from wagmi.
src/hooks/useBlockTransactionCount.ts safe No malicious patterns detected; the file is a standard wagmi React hook that delegates to @wagmi/core query utilities without any exfiltration, dynamic execution, filesystem, or process manipulation.
src/hooks/useBytecode.ts safe This is a standard wagmi React hook for reading contract bytecode; no malicious patterns, exfiltration, dynamic execution, or process spawning were detected.
src/hooks/useCall.ts safe No malicious patterns detected; the file is a standard wagmi React hook for contract calls with no network, filesystem, process, or dynamic execution behavior.
src/hooks/useCallsStatus.ts safe No malicious patterns detected; the file is a standard wagmi React hook that delegates to internal query utilities without external data transmission, credential access, dynamic code execution, or process spawning.
src/hooks/useCapabilities.ts safe No malicious patterns detected; this is a standard wagmi React hook that reads account capabilities via existing library utilities.
src/hooks/useChainId.ts safe No malicious patterns detected; the hook is a standard wagmi React wrapper for reading chain ID via useSyncExternalStore.
src/hooks/useChains.ts safe No malicious patterns detected
src/hooks/useClient.ts safe No malicious patterns detected; the code is a standard React hook from the wagmi library for accessing client state without any suspicious behavior.
src/hooks/useConfig.ts safe Cleared by Jev triage; no further analysis needed
src/hooks/useConnect.ts safe No malicious patterns detected in this standard wagmi React hook for wallet connection.
src/hooks/useConnections.ts safe No malicious patterns detected
src/hooks/useConnectorClient.ts safe No malicious patterns detected
src/hooks/useConnectors.ts safe No malicious patterns detected
src/hooks/useDeployContract.ts safe No malicious patterns detected; this is a standard wagmi React hook for deploying smart contracts with no network exfiltration, credential access, dynamic code execution, or file system manipulation.
src/hooks/useDisconnect.ts safe No malicious patterns detected; the code is a standard wagmi React hook for disconnecting wallet connectors.
src/hooks/useEnsAddress.ts safe No malicious patterns detected; the code is a standard wagmi React hook for ENS address resolution with only static internal and peer imports.
src/hooks/useEnsAvatar.ts safe No malicious patterns detected
src/hooks/useEnsName.ts safe No malicious patterns detected; the file is a standard wagmi React hook for resolving ENS names via existing project utilities and no external, obfuscated, or filesystem/network exfiltration logic is present.
src/hooks/useEnsResolver.ts safe No malicious patterns detected; this is a standard wagmi React hook that wraps useQuery for ENS resolver lookups with no network, filesystem, process, or dynamic code execution concerns.
src/hooks/useEnsText.ts safe No malicious patterns detected; the file is a standard wagmi React hook wrapper for ENS text resolution with no exfiltration, obfuscation, or side effects.
src/hooks/useEstimateFeesPerGas.ts safe No malicious patterns detected
src/hooks/useEstimateGas.ts safe No malicious patterns detected; this is a standard wagmi React hook for gas estimation with no data exfiltration, credential harvesting, or dynamic code execution.
src/hooks/useEstimateMaxPriorityFeePerGas.ts safe No malicious patterns detected; this is a standard React hook wrapper around wagmi's estimateMaxPriorityFeePerGas query with no exfiltration, obfuscation, or dynamic execution.
src/hooks/useFeeHistory.ts safe No malicious patterns detected
src/hooks/useGasPrice.ts safe No malicious patterns detected
src/hooks/useInfiniteReadContracts.ts safe No malicious patterns detected in the analyzed TypeScript hook; it is a standard wagmi React hook for reading smart contract data.
src/hooks/usePrepareTransactionRequest.ts safe No malicious patterns detected; the file is a standard wagmi React hook that prepares a transaction request using useQuery, with no network exfiltration, credential access, dynamic execution, or process spawning.
src/hooks/useProof.ts safe This is a standard wagmi React hook for fetching Ethereum proofs; no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution were detected.
src/hooks/usePublicClient.ts safe No malicious patterns detected in this standard wagmi React hook for accessing public blockchain clients.
src/hooks/useReadContract.ts safe No malicious patterns detected; the code is a standard wagmi React hook for reading smart contracts with no exfiltration, credential harvesting, dynamic execution, or suspicious network/file/process activity.
src/hooks/useReadContracts.ts safe No malicious patterns detected; this is a standard wagmi React hook for reading multiple smart contracts.
src/hooks/useReconnect.ts safe No malicious patterns detected
src/hooks/useSendCalls.ts safe No malicious patterns detected; this is a legitimate React hook wrapper around wagmi's sendCalls mutation.
src/hooks/useSendCallsSync.ts safe No malicious patterns detected in useSendCallsSync.ts; it is a standard React hook wrapper around wagmi's sendCallsSync mutation with no data exfiltration, eval, process spawning, or credential harvesting.
src/hooks/useSendTransaction.ts safe This file is a standard wagmi React hook wrapper around @tanstack/react-query's useMutation for sending blockchain transactions, with no suspicious patterns, external calls, or malicious behavior detected.
src/hooks/useSendTransactionSync.ts safe No malicious patterns detected in the React hook implementation for wagmi's sendTransactionSync.
src/hooks/useShowCallsStatus.ts safe No malicious patterns detected
src/hooks/useSignMessage.ts safe This is a legitimate wagmi React hook wrapper for signing messages with no malicious patterns detected
src/hooks/useSignTypedData.ts safe No malicious patterns detected
src/hooks/useSimulateContract.ts safe No malicious patterns detected; this is a standard wagmi React hook for simulating smart contract calls.
src/hooks/useStorageAt.ts safe No malicious patterns detected; this is a standard React hook from wagmi for reading contract storage.
src/hooks/useSwitchAccount.ts safe No malicious patterns detected
src/hooks/useSwitchChain.ts safe This is a standard wagmi React hook for switching blockchain networks with no malicious patterns detected.
src/hooks/useSyncExternalStoreWithTracked.ts safe No malicious patterns detected; the code is a legitimate React hook for external store synchronization with property tracking, containing no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
src/hooks/useToken.ts safe No malicious patterns detected
src/hooks/useTransaction.ts safe No malicious patterns detected; this is a standard wagmi React hook for querying blockchain transaction data.
src/hooks/useTransactionConfirmations.ts safe No malicious patterns detected
src/hooks/useTransactionCount.ts safe This is a standard wagmi React hook that reads transaction count for a given address; it contains no network exfiltration, credential harvesting, dynamic code execution, or other malicious patterns.
src/hooks/useTransactionReceipt.ts safe No malicious patterns detected; this is a standard Wagmi React hook for fetching transaction receipts with no data exfiltration, code execution, or suspicious network/file activity.
src/hooks/useVerifyMessage.ts safe No malicious patterns detected
src/hooks/useVerifyTypedData.ts safe No malicious patterns detected
src/hooks/useWaitForCallsStatus.ts safe No malicious patterns detected
src/hooks/useWaitForTransactionReceipt.ts safe No malicious patterns detected; this is a standard wagmi React hook for waiting on transaction receipts with no network, filesystem, or code-execution risks.
src/hooks/useWalletClient.ts safe No malicious patterns detected; this is a standard wagmi React hook for wallet client management with legitimate query caching and invalidation logic.
src/hooks/useWatchAsset.ts safe No malicious patterns detected
src/hooks/useWatchBlockNumber.ts safe No malicious patterns detected; this is a standard wagmi React hook for watching block numbers with no data exfiltration, credential harvesting, dynamic execution, or process spawning.
src/hooks/useWatchBlocks.ts safe No malicious patterns detected; the file is a standard React hook wrapper around wagmi's watchBlocks with no network, filesystem, process, or credential-access behavior.
src/hooks/useWatchContractEvent.ts safe No malicious patterns detected
src/hooks/useWatchPendingTransactions.ts safe The file is a standard wagmi React hook that watches pending transactions and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
src/hooks/useWriteContract.ts safe No malicious patterns detected; this is a standard wagmi React hook for contract writes with no exfiltration, obfuscation, or side effects.
src/hydrate.ts safe No malicious patterns detected; the code is a standard React hydration component for wagmi that performs no network, filesystem, or dynamic code execution.
src/types/properties.ts safe No malicious patterns detected; this file contains only TypeScript type definitions with no executable logic, network activity, file system access, or dynamic code evaluation.
src/utils/getVersion.ts safe Cleared by Jev triage; no further analysis needed
src/utils/query.ts safe No malicious patterns detected; the file only wraps @tanstack/react-query hooks with type helpers and a hash function, with no network, filesystem, process, or dynamic-execution behavior.
src/version.ts safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is wagmi safe to use?

Our AI source review of wagmi@2.19.5 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does wagmi contain malware?

No malware was identified in wagmi@2.19.5 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was wagmi checked?

Togoder Security downloaded the published npm package and had an AI model read its 174 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan wagmi together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in wagmi@2.19.5, cost nothing.

Related security reports