Togoder security

npm package security report

react-dom@19.3.0 security report

No malicious code found.

No issues Version 19.3.0 Files reviewed 24 Size 5.4 MB Scanned

Summary

Togoder Security scanned the npm package react-dom@19.3.0 on Oct 6, 2026. An AI review of 24 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
cjs/react-dom-test-utils.development.js safe No malicious patterns detected; the file is a legitimate React development build that only wraps React.act with a deprecation warning and performs no suspicious network, filesystem, or process activity.
cjs/react-dom-test-utils.production.js safe No malicious patterns detected
cjs/react-dom.development.js safe This is the official React DOM development build with no malicious patterns; all code is standard React internals for portals, resource hints, hooks, and development warnings.
cjs/react-dom.production.js safe This is the legitimate React DOM production build with no malicious patterns detected.
cjs/react-dom.react-server.development.js safe This is the legitimate React DOM server development build containing only argument validation, console warnings, and delegation to React internals with no malicious patterns detected.
cjs/react-dom.react-server.production.js safe This is the official React DOM server-side rendering build with no malicious patterns; it only exports resource hint APIs and internal stubs.
client.js safe No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check.
client.react-server.js safe No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components.
index.js safe This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns.
profiling.js safe No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export.
profiling.react-server.js safe No malicious patterns detected
react-dom.react-server.js safe No malicious patterns detected
server.browser.js safe This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected.
server.bun.js safe No malicious patterns detected; this is a standard React DOM server environment-based module loader.
server.edge.js safe No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV.
server.js safe No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds.
server.node.js safe No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV.
server.react-server.js safe No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components.
static.browser.js safe No malicious patterns detected; the file is a standard React DOM server conditional export wrapper.
static.edge.js safe This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected.
static.js safe Cleared by Jev triage; no further analysis needed
static.node.js safe No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs.
static.react-server.js safe The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected.
test-utils.js safe No malicious patterns detected

Frequently asked questions

Is react-dom safe to use?

Our AI source review of react-dom@19.3.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does react-dom contain malware?

No malware was identified in react-dom@19.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was react-dom checked?

Togoder Security downloaded the published npm package and had an AI model read its 24 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan react-dom together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react-dom@19.3.0, cost nothing.

Related security reports