Togoder security

npm package security report

zustand npm package: is it safe?

No malicious code found.

No issues Version 5.0.3 Files reviewed 18 Size 39.3 KB Scanned

Summary

Togoder Security scanned the npm package zustand@5.0.3 on Oct 4, 2026. An AI review of 18 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

devtools extension integration

NPS-F10956819E9B

The code connects to the Redux DevTools browser extension (window.__REDUX_DEVTOOLS_EXTENSION__) if available, which is a legitimate development tool. However, in production environments without the devtools extension, this code will not connect to any external service. The devtools connection is only active in non-production modes or when explicitly enabled. This is expected functionality for the zustand devtools middleware.

esm/middleware.mjs:30
low

localStorage access

NPS-F32AF55A6D70

The persist middleware uses localStorage by default for state persistence. localStorage is a browser API restricted to same-origin context and does not constitute data exfiltration. This is standard behavior for state persistence.

esm/middleware.mjs:330

Files reviewed

FileVerdictWhat the reviewer saw
esm/index.mjs safe Cleared by Jev triage; no further analysis needed
esm/middleware.mjs safe This is legitimate zustand middleware code with no malicious patterns; it uses standard browser APIs for devtools integration and state persistence.
esm/middleware/immer.mjs safe Cleared by Jev triage; no further analysis needed
esm/react.mjs safe Cleared by Jev triage; no further analysis needed
esm/react/shallow.mjs safe Cleared by Jev triage; no further analysis needed
esm/shallow.mjs safe Cleared by Jev triage; no further analysis needed
esm/traditional.mjs safe Cleared by Jev triage; no further analysis needed
esm/vanilla.mjs safe No malicious patterns detected; this is a standard Zustand-like state management store implementation with no external I/O, obfuscation, or system access.
esm/vanilla/shallow.mjs safe Cleared by Jev triage; no further analysis needed
index.js safe No malicious patterns detected
middleware.js safe No malicious patterns detected; the code implements standard Zustand middleware (devtools, persist, redux, subscribeWithSelector) without exfiltration, credential harvesting, obfuscation, or suspicious system interactions.
middleware/immer.js safe The code is a legitimate Zustand middleware integration for Immer with no malicious patterns detected.
react.js safe No malicious patterns detected; the code is a standard Zustand React binding with no exfiltration, obfuscation, or dangerous operations.
react/shallow.js safe Cleared by Jev triage; no further analysis needed
shallow.js safe No malicious patterns detected; the file only re-exports shallow and useShallow from zustand submodules.
traditional.js safe Cleared by Jev triage; no further analysis needed
vanilla.js safe No malicious patterns detected; this is a standard Zustand-style vanilla store implementation with no network, filesystem, or dynamic execution activity.
vanilla/shallow.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of zustand are flagged high or critical. The latest scanned version, 5.0.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.0.05.0.3
VersionsVerdictCountRangeTop findings
5.0.0 โ€“ 5.0.3 No issues 2 >=5.0.0 <=5.0.3

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of zustand

VersionVerdictFilesScanned
5.0.3 No issues 18 Oct 4, 2026
5.0.0 No issues 18 Oct 4, 2026

Frequently asked questions

Is zustand safe to use?

Our AI source review of zustand@5.0.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does zustand contain malware?

No malware was identified in zustand@5.0.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was zustand checked?

Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan zustand together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zustand@5.0.3, cost nothing.

Related security reports