# use-sidecar@1.1.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:24:55.000Z
- Files reviewed: 27
- Findings: no findings
- Report: https://security.togoder.click/npm/use-sidecar
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package use-sidecar@1.1.3 on Oct 6, 2026. An AI review of 27 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/es2015/config.js` (safe): No malicious patterns detected
- `dist/es2015/env.js` (safe): No malicious patterns detected; the code simply re-exports a node-detection flag and a cache toggle with no risky behavior.
- `dist/es2015/exports.js` (safe): This is a legitimate React sidecar pattern implementation with no malicious patterns, untrusted dynamic execution, network access, or filesystem manipulation.
- `dist/es2015/hoc.js` (safe): No malicious patterns detected
- `dist/es2015/hook.js` (safe): No malicious patterns detected; the code is a standard React hook for dynamically importing and caching sidecar modules.
- `dist/es2015/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/es2015/medium.js` (safe): No malicious patterns detected; the code implements a small pub/sub medium utility with no network, file system, process execution, or dynamic code evaluation.
- `dist/es2015/renderProp.js` (safe): No malicious patterns detected
- `dist/es2015/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/es2019/config.js` (safe): No malicious patterns detected
- `dist/es2019/env.js` (safe): No malicious patterns detected
- `dist/es2019/exports.js` (safe): No malicious patterns detected
- `dist/es2019/hoc.js` (safe): No malicious patterns detected; the file is a standard React higher-order component that dynamically imports a component via a custom hook and renders an error fallback if needed.
- `dist/es2019/hook.js` (safe): No malicious patterns detected; the code is a standard React hook for dynamically loading modules with caching and error handling.
- `dist/es2019/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/es2019/medium.js` (safe): No malicious patterns detected; the code implements a simple event medium with no network, filesystem, process, or dynamic code execution concerns.
- `dist/es2019/renderProp.js` (safe): The file contains only a standard React render-prop utility pattern with no malicious or suspicious behavior.
- `dist/es2019/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/es5/config.js` (safe): No malicious patterns detected
- `dist/es5/env.js` (safe): No malicious patterns detected
- `dist/es5/exports.js` (safe): The code is a standard React sidecar export utility with no malicious patterns detected.
- `dist/es5/hoc.js` (safe): No malicious patterns detected
- `dist/es5/hook.js` (safe): No malicious patterns detected
- `dist/es5/index.js` (safe): No malicious patterns detected
- `dist/es5/medium.js` (safe): No malicious patterns detected; the code implements a simple event medium with no network, filesystem, process, or dynamic execution behavior.
- `dist/es5/renderProp.js` (safe): No malicious patterns detected; the code is a standard React render-prop utility with no network, filesystem, process, or credential access.
- `dist/es5/types.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
