# use-sync-external-store@1.4.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:42:11.000Z
- Files reviewed: 15
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/use-sync-external-store@1.4.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package use-sync-external-store@1.4.0 on Oct 4, 2026. An AI review of 15 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Environment-based conditional module loading

Finding ID: `NPS-3B2ECA9A31BD`

File: `shim/index.js:4`

The code conditionally loads either a production or development build based on NODE_ENV. This is a standard pattern for shimming React's useSyncExternalStore. Dynamic require() with relative paths is expected here and does not involve external input.

## Files reviewed

- `cjs/use-sync-external-store-shim.development.js` (safe): This file is the official React use-sync-external-store development shim from Meta, containing only standard React hook logic and development warnings with no malicious patterns.
- `cjs/use-sync-external-store-shim.native.development.js` (safe): No malicious patterns detected; the file is a legitimate React development shim for useSyncExternalStore with no exfiltration, obfuscation, or suspicious behavior.
- `cjs/use-sync-external-store-shim.native.production.js` (safe): This is the official React use-sync-external-store shim with no malicious patterns, network activity, credential access, or dynamic code execution.
- `cjs/use-sync-external-store-shim.production.js` (safe): This is the official React use-sync-external-store shim with no malicious patterns, external network calls, credential access, or dynamic code execution.
- `cjs/use-sync-external-store-shim/with-selector.development.js` (safe): No malicious patterns detected in this standard React shim implementation
- `cjs/use-sync-external-store-shim/with-selector.production.js` (safe): No malicious patterns detected; the file is a standard React useSyncExternalStoreWithSelector shim implementation.
- `cjs/use-sync-external-store-with-selector.development.js` (safe): No malicious patterns detected; this is a legitimate React development build of the use-sync-external-store-with-selector shim.
- `cjs/use-sync-external-store-with-selector.production.js` (safe): This is the official React use-sync-external-store-with-selector shim with no malicious patterns, no network, filesystem, process, or dynamic code execution.
- `cjs/use-sync-external-store.development.js` (safe): No malicious patterns detected
- `cjs/use-sync-external-store.production.js` (safe): No malicious patterns detected; the file is a trivial production re-export of React's useSyncExternalStore with no suspicious behavior.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `shim/index.js` (safe): This is a standard shim file that selects between production and development builds based on NODE_ENV; no malicious patterns were detected.
- `shim/index.native.js` (safe): No malicious patterns detected
- `shim/with-selector.js` (safe): No malicious patterns detected; the file is a standard conditional CommonJS shim that only loads sibling package files based on NODE_ENV.
- `with-selector.js` (safe): No malicious patterns detected

## Version ranges

None of the 3 scanned versions of use-sync-external-store are flagged high or critical. The latest scanned version, 1.6.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.2.0 – 1.6.0 (`>=1.2.0 <=1.6.0`): clean

## Scanned versions

- [1.6.0](https://security.togoder.click/npm/use-sync-external-store@1.6.0): safe, 2026-10-06T14:24:49.000Z
- [1.4.0](https://security.togoder.click/npm/use-sync-external-store@1.4.0): safe, 2026-10-04T16:42:11.000Z
- [1.2.0](https://security.togoder.click/npm/use-sync-external-store@1.2.0): safe, 2026-10-04T16:42:39.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
