Togoder security

npm package security report

use-sidecar npm package: is it safe?

No malicious code found.

No issues Version 1.1.3 Files reviewed 27 Size 23.8 KB Scanned

Summary

Togoder Security scanned the npm package use-sidecar@1.1.3 on Oct 6, 2026. An AI review of 27 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
dist/es2015/config.js safe No malicious patterns detected
dist/es2015/env.js safe No malicious patterns detected; the code simply re-exports a node-detection flag and a cache toggle with no risky behavior.
dist/es2015/exports.js safe This is a legitimate React sidecar pattern implementation with no malicious patterns, untrusted dynamic execution, network access, or filesystem manipulation.
dist/es2015/hoc.js safe No malicious patterns detected
dist/es2015/hook.js safe No malicious patterns detected; the code is a standard React hook for dynamically importing and caching sidecar modules.
dist/es2015/index.js safe Cleared by Jev triage; no further analysis needed
dist/es2015/medium.js safe No malicious patterns detected; the code implements a small pub/sub medium utility with no network, file system, process execution, or dynamic code evaluation.
dist/es2015/renderProp.js safe No malicious patterns detected
dist/es2015/types.js safe Cleared by Jev triage; no further analysis needed
dist/es2019/config.js safe No malicious patterns detected
dist/es2019/env.js safe No malicious patterns detected
dist/es2019/exports.js safe No malicious patterns detected
dist/es2019/hoc.js safe No malicious patterns detected; the file is a standard React higher-order component that dynamically imports a component via a custom hook and renders an error fallback if needed.
dist/es2019/hook.js safe No malicious patterns detected; the code is a standard React hook for dynamically loading modules with caching and error handling.
dist/es2019/index.js safe Cleared by Jev triage; no further analysis needed
dist/es2019/medium.js safe No malicious patterns detected; the code implements a simple event medium with no network, filesystem, process, or dynamic code execution concerns.
dist/es2019/renderProp.js safe The file contains only a standard React render-prop utility pattern with no malicious or suspicious behavior.
dist/es2019/types.js safe Cleared by Jev triage; no further analysis needed
dist/es5/config.js safe No malicious patterns detected
dist/es5/env.js safe No malicious patterns detected
dist/es5/exports.js safe The code is a standard React sidecar export utility with no malicious patterns detected.
dist/es5/hoc.js safe No malicious patterns detected
dist/es5/hook.js safe No malicious patterns detected
dist/es5/index.js safe No malicious patterns detected
dist/es5/medium.js safe No malicious patterns detected; the code implements a simple event medium with no network, filesystem, process, or dynamic execution behavior.
Show 2 more files
FileVerdictWhat the reviewer saw
dist/es5/renderProp.js safe No malicious patterns detected; the code is a standard React render-prop utility with no network, filesystem, process, or credential access.
dist/es5/types.js safe No malicious patterns detected

Scanned versions of use-sidecar

VersionVerdictFilesScanned
1.1.3 No issues 27 Oct 6, 2026

Frequently asked questions

Is use-sidecar safe to use?

Our AI source review of use-sidecar@1.1.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does use-sidecar contain malware?

No malware was identified in use-sidecar@1.1.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was use-sidecar checked?

Togoder Security downloaded the published npm package and had an AI model read its 27 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan use-sidecar together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in use-sidecar@1.1.3, cost nothing.

Related security reports