# zustand@5.0.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:19:12.000Z
- Files reviewed: 18
- Findings: 5 low severity findings
- Report: https://security.togoder.click/npm/zustand@5.0.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package zustand@5.0.0 on Oct 4, 2026. An AI review of 18 source files produced 5 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Environment-based conditional logging

Finding ID: `NPS-16C77D51089F`

File: `middleware.js:45`

Uses process.env.NODE_ENV to conditionally enable devtools and warning messages. This is standard Node.js practice, not credential harvesting.

### [low] Legitimate Redux DevTools browser extension integration

Finding ID: `NPS-F0FFE251D4D0`

File: `middleware.js:46`

The code accesses window.__REDUX_DEVTOOLS_EXTENSION__ to connect to the Redux DevTools browser extension, a standard development tool. This is expected functionality for the zustand devtools middleware and does not constitute data exfiltration.

### [low] Dynamic property assignment for dispatch wrapping

Finding ID: `NPS-C1AC7EE019D4`

File: `middleware.js:135`

The code overrides api.dispatch with a wrapper function. This is part of the devtools middleware functionality for intercepting actions, not a backdoor.

### [low] JSON parsing of DevTools messages

Finding ID: `NPS-4A70A04F42BC`

File: `middleware.js:225`

parseJsonThen uses JSON.parse on messages received from the Redux DevTools browser extension. This is expected behavior for the integration, though it processes external input. No dynamic code execution (eval/new Function) is involved.

### [low] localStorage usage for state persistence

Finding ID: `NPS-E495FA15735E`

File: `middleware.js:253`

createJSONStorage defaults to using localStorage for persisting state. This is client-side browser storage within the same origin, not exfiltration.

## Files reviewed

- `esm/index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/middleware.mjs` (safe): No malicious patterns detected; the code implements standard Zustand middleware (redux, devtools, subscribeWithSelector, persist) with expected Redux DevTools integration and localStorage persistence, without exfiltration, obfuscation, process spawning, or install-time execution.
- `esm/middleware/immer.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/react.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/react/shallow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/shallow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/traditional.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/vanilla.mjs` (safe): No malicious patterns detected; this is a standard Zustand-like state management store implementation with no external I/O, obfuscation, or system access.
- `esm/vanilla/shallow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): No malicious patterns detected
- `middleware.js` (safe): This appears to be a legitimate copy of the zustand state management library middleware (devtools, persist, subscribeWithSelector, redux, combine) with no malicious patterns; the observed behaviors are all expected for Redux DevTools integration and browser storage persistence.
- `middleware/immer.js` (safe): The code is a legitimate Zustand middleware integration for Immer with no malicious patterns detected.
- `react.js` (safe): No malicious patterns detected; the code is a standard Zustand React binding with no exfiltration, obfuscation, or dangerous operations.
- `react/shallow.js` (safe): Cleared by Jev triage; no further analysis needed
- `shallow.js` (safe): No malicious patterns detected; the file only re-exports shallow and useShallow from zustand submodules.
- `traditional.js` (safe): Cleared by Jev triage; no further analysis needed
- `vanilla.js` (safe): No malicious patterns detected; this is a standard Zustand-style vanilla store implementation with no network, filesystem, or dynamic execution activity.
- `vanilla/shallow.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of zustand are flagged high or critical. The latest scanned version, 5.0.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.0.0 – 5.0.3 (`>=5.0.0 <=5.0.3`): clean

## Scanned versions

- [5.0.3](https://security.togoder.click/npm/zustand@5.0.3): safe, 2026-10-04T16:47:33.000Z
- [5.0.0](https://security.togoder.click/npm/zustand@5.0.0): safe, 2026-10-04T16:19:12.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
