Summary
Togoder Security scanned the npm package use-sidecar@1.1.3 on Oct 6, 2026. An AI review of 27 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/es2015/config.js | safe | No malicious patterns detected |
| dist/es2015/env.js | safe | No malicious patterns detected; the code simply re-exports a node-detection flag and a cache toggle with no risky behavior. |
| dist/es2015/exports.js | safe | This is a legitimate React sidecar pattern implementation with no malicious patterns, untrusted dynamic execution, network access, or filesystem manipulation. |
| dist/es2015/hoc.js | safe | No malicious patterns detected |
| dist/es2015/hook.js | safe | No malicious patterns detected; the code is a standard React hook for dynamically importing and caching sidecar modules. |
| dist/es2015/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2015/medium.js | safe | No malicious patterns detected; the code implements a small pub/sub medium utility with no network, file system, process execution, or dynamic code evaluation. |
| dist/es2015/renderProp.js | safe | No malicious patterns detected |
| dist/es2015/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/config.js | safe | No malicious patterns detected |
| dist/es2019/env.js | safe | No malicious patterns detected |
| dist/es2019/exports.js | safe | No malicious patterns detected |
| dist/es2019/hoc.js | safe | No malicious patterns detected; the file is a standard React higher-order component that dynamically imports a component via a custom hook and renders an error fallback if needed. |
| dist/es2019/hook.js | safe | No malicious patterns detected; the code is a standard React hook for dynamically loading modules with caching and error handling. |
| dist/es2019/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es2019/medium.js | safe | No malicious patterns detected; the code implements a simple event medium with no network, filesystem, process, or dynamic code execution concerns. |
| dist/es2019/renderProp.js | safe | The file contains only a standard React render-prop utility pattern with no malicious or suspicious behavior. |
| dist/es2019/types.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/es5/config.js | safe | No malicious patterns detected |
| dist/es5/env.js | safe | No malicious patterns detected |
| dist/es5/exports.js | safe | The code is a standard React sidecar export utility with no malicious patterns detected. |
| dist/es5/hoc.js | safe | No malicious patterns detected |
| dist/es5/hook.js | safe | No malicious patterns detected |
| dist/es5/index.js | safe | No malicious patterns detected |
| dist/es5/medium.js | safe | No malicious patterns detected; the code implements a simple event medium with no network, filesystem, process, or dynamic execution behavior. |
Show 2 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/es5/renderProp.js | safe | No malicious patterns detected; the code is a standard React render-prop utility with no network, filesystem, process, or credential access. |
| dist/es5/types.js | safe | No malicious patterns detected |
Scanned versions of use-sidecar
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.1.3 | No issues | 27 | Oct 6, 2026 |
Frequently asked questions
Is use-sidecar safe to use?
Our AI source review of use-sidecar@1.1.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does use-sidecar contain malware?
No malware was identified in use-sidecar@1.1.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was use-sidecar checked?
Togoder Security downloaded the published npm package and had an AI model read its 27 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan use-sidecar together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in use-sidecar@1.1.3, cost nothing.