The full stack toolkit to build onchain app UX.
84%
Total Score
100
100
89
63
100
One of 15 workflows uses pull_request_target, which warrants review because it can handle elevated repository context, but there are no untrusted checkouts or script-injection findings.
The repository name does not match the package name and its README does not mention @reown/appkit-wallet, so the package-to-source relationship is not explicitly transparent; this may still be normal for a monorepo.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting guidance unclear.
Seven workflows lack top-level permissions and four declare top-level write access, which is weaker least-privilege hygiene even though other workflows use read-only or job-level permissions.
Version 1.8.24 is a stable, non-prerelease release, although 95% of recent releases being prereleases indicates a fast-moving release process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zod Version 3.22.4 | — | — |
@reown/appkit-common Version 1.8.24 | — | — |
@walletconnect/logger Version 3.0.2 | — | — |
@reown/appkit-polyfills Version 1.8.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.