The full stack toolkit to build onchain app UX.
82%
Total Score
100
100
89
63
100
One of 15 workflows uses pull_request_target, but there are no untrusted checkouts or detected script injections; the isolated workflow warrants awareness rather than a severe concern.
The repository name does not match this package and its README does not mention it, so the package-to-repository relationship is less transparent; the organization backing and large monorepo-style file tree partly compensate.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting expectations unclear for a package with substantial integrations.
Seven workflows omit top-level token permissions and four declare top-level write access, creating avoidable CI permission risk despite other workflows using read-only or job-level permissions.
Version 1.8.24 is a stable major and not a prerelease, although the recent prerelease share is high at 95%, which adds some release-process caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lit Version 3.3.0 | — | — |
@reown/appkit-ui Version 1.8.24 | — | — |
@reown/appkit-pay Version 1.8.24 | — | — |
@reown/appkit-utils Version 1.8.24 | — | — |
@reown/appkit-common Version 1.8.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.