Togoder security

npm package security report

zustand@5.0.0 security report

No malicious code found.

No issues Version 5.0.0 Files reviewed 18 Size 38.9 KB Scanned

Summary

Togoder Security scanned the npm package zustand@5.0.0 on Oct 4, 2026. An AI review of 18 source files produced 5 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
5
low

Findings 5

low

Environment-based conditional logging

NPS-16C77D51089F

Uses process.env.NODE_ENV to conditionally enable devtools and warning messages. This is standard Node.js practice, not credential harvesting.

middleware.js:45
low

Legitimate Redux DevTools browser extension integration

NPS-F0FFE251D4D0

The code accesses window.__REDUX_DEVTOOLS_EXTENSION__ to connect to the Redux DevTools browser extension, a standard development tool. This is expected functionality for the zustand devtools middleware and does not constitute data exfiltration.

middleware.js:46
low

Dynamic property assignment for dispatch wrapping

NPS-C1AC7EE019D4

The code overrides api.dispatch with a wrapper function. This is part of the devtools middleware functionality for intercepting actions, not a backdoor.

middleware.js:135
low

JSON parsing of DevTools messages

NPS-4A70A04F42BC

parseJsonThen uses JSON.parse on messages received from the Redux DevTools browser extension. This is expected behavior for the integration, though it processes external input. No dynamic code execution (eval/new Function) is involved.

middleware.js:225
low

localStorage usage for state persistence

NPS-E495FA15735E

createJSONStorage defaults to using localStorage for persisting state. This is client-side browser storage within the same origin, not exfiltration.

middleware.js:253

Files reviewed

FileVerdictWhat the reviewer saw
esm/index.mjs safe Cleared by Jev triage; no further analysis needed
esm/middleware.mjs safe No malicious patterns detected; the code implements standard Zustand middleware (redux, devtools, subscribeWithSelector, persist) with expected Redux DevTools integration and localStorage persistence, without exfiltration, obfuscation, process spawning, or install-time execution.
esm/middleware/immer.mjs safe Cleared by Jev triage; no further analysis needed
esm/react.mjs safe Cleared by Jev triage; no further analysis needed
esm/react/shallow.mjs safe Cleared by Jev triage; no further analysis needed
esm/shallow.mjs safe Cleared by Jev triage; no further analysis needed
esm/traditional.mjs safe Cleared by Jev triage; no further analysis needed
esm/vanilla.mjs safe No malicious patterns detected; this is a standard Zustand-like state management store implementation with no external I/O, obfuscation, or system access.
esm/vanilla/shallow.mjs safe Cleared by Jev triage; no further analysis needed
index.js safe No malicious patterns detected
middleware.js safe This appears to be a legitimate copy of the zustand state management library middleware (devtools, persist, subscribeWithSelector, redux, combine) with no malicious patterns; the observed behaviors are all expected for Redux DevTools integration and browser storage persistence.
middleware/immer.js safe The code is a legitimate Zustand middleware integration for Immer with no malicious patterns detected.
react.js safe No malicious patterns detected; the code is a standard Zustand React binding with no exfiltration, obfuscation, or dangerous operations.
react/shallow.js safe Cleared by Jev triage; no further analysis needed
shallow.js safe No malicious patterns detected; the file only re-exports shallow and useShallow from zustand submodules.
traditional.js safe Cleared by Jev triage; no further analysis needed
vanilla.js safe No malicious patterns detected; this is a standard Zustand-style vanilla store implementation with no network, filesystem, or dynamic execution activity.
vanilla/shallow.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of zustand are flagged high or critical. The latest scanned version, 5.0.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.0.05.0.3
VersionsVerdictCountRangeTop findings
5.0.0 โ€“ 5.0.3 No issues 2 >=5.0.0 <=5.0.3

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of zustand

VersionVerdictFilesScanned
5.0.3 No issues 18 Oct 4, 2026
5.0.0 No issues 18 Oct 4, 2026

Frequently asked questions

Is zustand safe to use?

Our AI source review of zustand@5.0.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does zustand contain malware?

No malware was identified in zustand@5.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was zustand checked?

Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan zustand together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zustand@5.0.0, cost nothing.

Related security reports