Togoder security

npm package security report

use-sync-external-store@1.2.0 security report

No malicious code found.

No issues Version 1.2.0 Files reviewed 10 Size 30.9 KB Scanned

Summary

Togoder Security scanned the npm package use-sync-external-store@1.2.0 on Oct 4, 2026. An AI review of 10 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
4
low

Findings 4

low

environment variable usage

NPS-B4DCCE038CD9

The code checks process.env.NODE_ENV to determine development vs production mode, which is a standard practice in React packages.

cjs/use-sync-external-store-shim.development.js:10
low

devtools hook access

NPS-8434CF299D25

Accesses __REACT_DEVTOOLS_GLOBAL_HOOK__ for integration with React DevTools, a standard debugging interface, not a security concern.

cjs/use-sync-external-store-shim.development.js:18
low

internal React API access

NPS-46A0989B6A57

Uses React.__SECRET_INTERNALS_DO_NOT_USE_OR_YOU_WILL_BE_FIRED for accessing ReactDebugCurrentFrame for stack traces in warnings, which is an internal React API but not malicious.

cjs/use-sync-external-store-shim.development.js:25
low

console output

NPS-FD763111ADCA

Uses console.error/warning for development warnings via Function.prototype.apply.call, which is standard for React warnings.

cjs/use-sync-external-store-shim.development.js:51

Files reviewed

FileVerdictWhat the reviewer saw
cjs/use-sync-external-store-shim.development.js safe The code is the official React use-sync-external-store shim for development, containing only standard React development warnings and no malicious patterns.
cjs/use-sync-external-store-shim.native.development.js safe This is the official React use-sync-external-store shim library for React Native; it contains no malicious patterns, network calls, or dynamic code execution.
cjs/use-sync-external-store-shim/with-selector.development.js safe Cleared by Jev triage; no further analysis needed
cjs/use-sync-external-store-with-selector.development.js safe No malicious patterns detected
cjs/use-sync-external-store.development.js safe No malicious patterns detected; the code is a legitimate React development build for use-sync-external-store with only console warnings and safe module-level hooks.
index.js safe Standard conditional module export based on NODE_ENV with no malicious patterns detected
shim/index.js safe No malicious patterns detected
shim/index.native.js safe No malicious patterns detected; the file is a standard conditional module export for React's use-sync-external-store shim.
shim/with-selector.js safe No malicious patterns detected; the file is a standard environment-based module re-export shim for a well-known React use-sync-external-store package.
with-selector.js safe The wrapper file simply re-exports a production or development build based on NODE_ENV, with no malicious patterns.

Affected version ranges

None of the 3 scanned versions of use-sync-external-store are flagged high or critical. The latest scanned version, 1.6.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.2.01.6.0
VersionsVerdictCountRangeTop findings
1.2.0 โ€“ 1.6.0 No issues 3 >=1.2.0 <=1.6.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of use-sync-external-store

VersionVerdictFilesScanned
1.6.0 No issues 15 Oct 6, 2026
1.4.0 No issues 15 Oct 4, 2026
1.2.0 No issues 10 Oct 4, 2026

Frequently asked questions

Is use-sync-external-store safe to use?

Our AI source review of use-sync-external-store@1.2.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does use-sync-external-store contain malware?

No malware was identified in use-sync-external-store@1.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was use-sync-external-store checked?

Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan use-sync-external-store together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in use-sync-external-store@1.2.0, cost nothing.

Related security reports