Summary
Togoder Security scanned the npm package zustand@5.0.3 on Oct 4, 2026. An AI review of 18 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
devtools extension integration
NPS-F10956819E9B
The code connects to the Redux DevTools browser extension (window.__REDUX_DEVTOOLS_EXTENSION__) if available, which is a legitimate development tool. However, in production environments without the devtools extension, this code will not connect to any external service. The devtools connection is only active in non-production modes or when explicitly enabled. This is expected functionality for the zustand devtools middleware.
localStorage access
NPS-F32AF55A6D70
The persist middleware uses localStorage by default for state persistence. localStorage is a browser API restricted to same-origin context and does not constitute data exfiltration. This is standard behavior for state persistence.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/middleware.mjs | safe | This is legitimate zustand middleware code with no malicious patterns; it uses standard browser APIs for devtools integration and state persistence. |
| esm/middleware/immer.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/react.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/react/shallow.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/shallow.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/traditional.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/vanilla.mjs | safe | No malicious patterns detected; this is a standard Zustand-like state management store implementation with no external I/O, obfuscation, or system access. |
| esm/vanilla/shallow.mjs | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | No malicious patterns detected |
| middleware.js | safe | No malicious patterns detected; the code implements standard Zustand middleware (devtools, persist, redux, subscribeWithSelector) without exfiltration, credential harvesting, obfuscation, or suspicious system interactions. |
| middleware/immer.js | safe | The code is a legitimate Zustand middleware integration for Immer with no malicious patterns detected. |
| react.js | safe | No malicious patterns detected; the code is a standard Zustand React binding with no exfiltration, obfuscation, or dangerous operations. |
| react/shallow.js | safe | Cleared by Jev triage; no further analysis needed |
| shallow.js | safe | No malicious patterns detected; the file only re-exports shallow and useShallow from zustand submodules. |
| traditional.js | safe | Cleared by Jev triage; no further analysis needed |
| vanilla.js | safe | No malicious patterns detected; this is a standard Zustand-style vanilla store implementation with no network, filesystem, or dynamic execution activity. |
| vanilla/shallow.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of zustand are flagged high or critical. The latest scanned version, 5.0.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of zustand
Frequently asked questions
Is zustand safe to use?
Our AI source review of zustand@5.0.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does zustand contain malware?
No malware was identified in zustand@5.0.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was zustand checked?
Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan zustand together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zustand@5.0.3, cost nothing.