# react@19.3.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:51.000Z
- Files reviewed: 24
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/react
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package react@19.3.0 on Oct 6, 2026. An AI review of 24 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Code runs at import time

Finding ID: `NPS-4A3976384572`

File: `cjs/react-compiler-runtime.development.js:13`

The file immediately executes an IIFE at module load time (guarded only by NODE_ENV !== 'production') that calls require('react') and accesses React internals. This means importing the package has immediate side effects rather than merely exporting functions. While this is standard React development runtime behavior and not inherently malicious, it is a top-level side-effect on import worth noting.

### [low] Access to private/internal React internals

Finding ID: `NPS-603510462F9C`

File: `cjs/react-compiler-runtime.development.js:15`

Accesses '__CLIENT_INTERNALS_DO_NOT_USE_OR_WARN_USERS_THEY_CANNOT_UPGRADE', an explicitly private/unsupported React internal. Not malicious per se, but code relying on undocumented internals is fragile and could break or behave unexpectedly across React versions.

### [low] useMemoCache invocation of dispatcher

Finding ID: `NPS-B40D68989DE4`

File: `cjs/react-compiler-runtime.development.js:25`

Calls dispatcher.useMemoCache(size) which executes React's hook dispatcher. This is the intended functionality of react-compiler-runtime; no exfiltration, obfuscation, network, filesystem, or process-spawning behavior is present.

## Files reviewed

- `cjs/react-compiler-runtime.development.js` (medium): The file is the legitimate React compiler runtime development build with only standard import-time hook binding; no malicious patterns such as exfiltration, credential harvesting, obfuscation, network calls, filesystem manipulation, or process spawning were found.
- `cjs/react-compiler-runtime.production.js` (safe): No malicious patterns detected
- `cjs/react-compiler-runtime.profiling.js` (safe): No malicious patterns detected
- `cjs/react-jsx-dev-runtime.development.js` (safe): No malicious patterns detected; this is the standard React JSX development runtime with only debugging and validation logic.
- `cjs/react-jsx-dev-runtime.production.js` (safe): No malicious patterns detected
- `cjs/react-jsx-dev-runtime.profiling.js` (safe): This is a standard React JSX development runtime profiling file with no malicious patterns; it only defines the Fragment symbol and an undefined jsxDEV export.
- `cjs/react-jsx-dev-runtime.react-server.development.js` (safe): No malicious patterns detected; this is the legitimate React JSX development runtime for server components.
- `cjs/react-jsx-dev-runtime.react-server.production.js` (safe): This is a legitimate React Server Components JSX runtime production build with no malicious patterns detected.
- `cjs/react-jsx-runtime.development.js` (safe): No malicious patterns detected
- `cjs/react-jsx-runtime.production.js` (safe): No malicious patterns detected
- `cjs/react-jsx-runtime.profiling.js` (safe): No malicious patterns detected; this is a legitimate React JSX runtime profiling build with no network, filesystem, process, or dynamic execution activity.
- `cjs/react-jsx-runtime.react-server.development.js` (safe): This is the legitimate React JSX runtime development build from Meta/Facebook with no malicious patterns detected.
- `cjs/react-jsx-runtime.react-server.production.js` (safe): No malicious patterns detected in react-jsx-runtime.react-server.production.js; code is a standard production JSX runtime factory with only a benign environment check.
- `cjs/react.development.js` (safe): This is the legitimate React development build with no malicious patterns detected; all dynamic code execution, network, and environment interactions are standard React internals and guardrails.
- `cjs/react.production.js` (safe): No malicious patterns detected; this is the legitimate official React 19.3.0 production build with standard library functionality.
- `cjs/react.react-server.development.js` (safe): This is the legitimate React 19.3.0 server-side development build from Meta, containing only standard React internals with no malicious patterns, network activity, or code execution outside the React library's expected behavior.
- `cjs/react.react-server.production.js` (safe): No malicious patterns detected; this is a legitimate production build of React's react-server entry point.
- `compiler-runtime.js` (safe): No malicious patterns detected; the file only conditionally re-exports React runtime modules based on NODE_ENV.
- `index.js` (safe): This is a standard React environment-based module export switch with no malicious patterns detected.
- `jsx-dev-runtime.js` (safe): No malicious patterns detected; the file is a standard React JSX development runtime entry point that conditionally loads production or development builds based on NODE_ENV.
- `jsx-dev-runtime.react-server.js` (safe): No malicious patterns detected
- `jsx-runtime.js` (safe): This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV, with no malicious patterns detected.
- `jsx-runtime.react-server.js` (safe): This is a standard React JSX runtime entry point that conditionally loads production or development builds based on NODE_ENV; no malicious patterns detected.
- `react.react-server.js` (safe): No malicious patterns detected

## Version ranges

None of the 2 scanned versions of react are flagged high or critical. The latest scanned version, 19.3.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 19.3.0 (`19.3.0`): medium
- 19.0.0 – 19.2.8 (`>=19.0.0 <=19.2.8`): not scanned
- 18.3.1 (`18.3.1`): clean

## Scanned versions

- [19.3.0](https://security.togoder.click/npm/react@19.3.0): medium, 2026-10-06T14:23:51.000Z
- [18.3.1](https://security.togoder.click/npm/react@18.3.1): safe, 2026-10-04T16:54:46.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
