# react-dom@19.3.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:51.000Z
- Files reviewed: 24
- Findings: no findings
- Report: https://security.togoder.click/npm/react-dom
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package react-dom@19.3.0 on Oct 6, 2026. An AI review of 24 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `cjs/react-dom-test-utils.development.js` (safe): No malicious patterns detected; the file is a legitimate React development build that only wraps React.act with a deprecation warning and performs no suspicious network, filesystem, or process activity.
- `cjs/react-dom-test-utils.production.js` (safe): No malicious patterns detected
- `cjs/react-dom.development.js` (safe): This is the official React DOM development build with no malicious patterns; all code is standard React internals for portals, resource hints, hooks, and development warnings.
- `cjs/react-dom.production.js` (safe): This is the legitimate React DOM production build with no malicious patterns detected.
- `cjs/react-dom.react-server.development.js` (safe): This is the legitimate React DOM server development build containing only argument validation, console warnings, and delegation to React internals with no malicious patterns detected.
- `cjs/react-dom.react-server.production.js` (safe): This is the official React DOM server-side rendering build with no malicious patterns; it only exports resource hint APIs and internal stubs.
- `client.js` (safe): No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check.
- `client.react-server.js` (safe): No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components.
- `index.js` (safe): This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns.
- `profiling.js` (safe): No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export.
- `profiling.react-server.js` (safe): No malicious patterns detected
- `react-dom.react-server.js` (safe): No malicious patterns detected
- `server.browser.js` (safe): This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected.
- `server.bun.js` (safe): No malicious patterns detected; this is a standard React DOM server environment-based module loader.
- `server.edge.js` (safe): No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV.
- `server.js` (safe): No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds.
- `server.node.js` (safe): No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV.
- `server.react-server.js` (safe): No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components.
- `static.browser.js` (safe): No malicious patterns detected; the file is a standard React DOM server conditional export wrapper.
- `static.edge.js` (safe): This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected.
- `static.js` (safe): Cleared by Jev triage; no further analysis needed
- `static.node.js` (safe): No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs.
- `static.react-server.js` (safe): The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected.
- `test-utils.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
