Summary
Togoder Security scanned the npm package react-dom@19.3.0 on Oct 6, 2026. An AI review of 24 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cjs/react-dom-test-utils.development.js | safe | No malicious patterns detected; the file is a legitimate React development build that only wraps React.act with a deprecation warning and performs no suspicious network, filesystem, or process activity. |
| cjs/react-dom-test-utils.production.js | safe | No malicious patterns detected |
| cjs/react-dom.development.js | safe | This is the official React DOM development build with no malicious patterns; all code is standard React internals for portals, resource hints, hooks, and development warnings. |
| cjs/react-dom.production.js | safe | This is the legitimate React DOM production build with no malicious patterns detected. |
| cjs/react-dom.react-server.development.js | safe | This is the legitimate React DOM server development build containing only argument validation, console warnings, and delegation to React internals with no malicious patterns detected. |
| cjs/react-dom.react-server.production.js | safe | This is the official React DOM server-side rendering build with no malicious patterns; it only exports resource hint APIs and internal stubs. |
| client.js | safe | No malicious patterns detected; the code is a standard React DOM client entry point with a DevTools dead code elimination check. |
| client.react-server.js | safe | No malicious patterns detected; the file only throws an error to indicate react-dom/client is unsupported in React Server Components. |
| index.js | safe | This is a standard ReactDOM entry point performing a benign DCE check and conditional module export with no malicious patterns. |
| profiling.js | safe | No malicious patterns detected; this is a standard React DOM profiling entry point that only performs a DevTools dead-code-elimination check and conditional module export. |
| profiling.react-server.js | safe | No malicious patterns detected |
| react-dom.react-server.js | safe | No malicious patterns detected |
| server.browser.js | safe | This file is a standard React DOM server entry point that conditionally re-exports modules based on NODE_ENV, with no malicious patterns detected. |
| server.bun.js | safe | No malicious patterns detected; this is a standard React DOM server environment-based module loader. |
| server.edge.js | safe | No malicious patterns detected; this is a standard React DOM server entry point that conditionally loads CJS bundles based on NODE_ENV. |
| server.js | safe | No malicious patterns detected; the file is a simple re-export of the Node.js server bundle, a standard pattern in React DOM builds. |
| server.node.js | safe | No malicious patterns detected; this is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV. |
| server.react-server.js | safe | No malicious patterns detected; the file only throws an error to indicate unsupported use of react-dom/server in React Server Components. |
| static.browser.js | safe | No malicious patterns detected; the file is a standard React DOM server conditional export wrapper. |
| static.edge.js | safe | This is a standard React DOM server entry point that conditionally requires production or development builds based on NODE_ENV; no malicious patterns detected. |
| static.js | safe | Cleared by Jev triage; no further analysis needed |
| static.node.js | safe | No malicious patterns detected; the file is a standard React DOM server entry point that conditionally requires internal modules based on NODE_ENV and re-exports public APIs. |
| static.react-server.js | safe | The file only throws a static error message for an unsupported React Server Components entry point, with no malicious patterns detected. |
| test-utils.js | safe | No malicious patterns detected |
Frequently asked questions
Is react-dom safe to use?
Our AI source review of react-dom@19.3.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does react-dom contain malware?
No malware was identified in react-dom@19.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was react-dom checked?
Togoder Security downloaded the published npm package and had an AI model read its 24 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan react-dom together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in react-dom@19.3.0, cost nothing.