# zustand@5.0.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:47:33.000Z
- Files reviewed: 18
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/zustand@5.0.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package zustand@5.0.3 on Oct 4, 2026. An AI review of 18 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] devtools extension integration

Finding ID: `NPS-F10956819E9B`

File: `esm/middleware.mjs:30`

The code connects to the Redux DevTools browser extension (window.__REDUX_DEVTOOLS_EXTENSION__) if available, which is a legitimate development tool. However, in production environments without the devtools extension, this code will not connect to any external service. The devtools connection is only active in non-production modes or when explicitly enabled. This is expected functionality for the zustand devtools middleware.

### [low] localStorage access

Finding ID: `NPS-F32AF55A6D70`

File: `esm/middleware.mjs:330`

The persist middleware uses localStorage by default for state persistence. localStorage is a browser API restricted to same-origin context and does not constitute data exfiltration. This is standard behavior for state persistence.

## Files reviewed

- `esm/index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/middleware.mjs` (safe): This is legitimate zustand middleware code with no malicious patterns; it uses standard browser APIs for devtools integration and state persistence.
- `esm/middleware/immer.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/react.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/react/shallow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/shallow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/traditional.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `esm/vanilla.mjs` (safe): No malicious patterns detected; this is a standard Zustand-like state management store implementation with no external I/O, obfuscation, or system access.
- `esm/vanilla/shallow.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): No malicious patterns detected
- `middleware.js` (safe): No malicious patterns detected; the code implements standard Zustand middleware (devtools, persist, redux, subscribeWithSelector) without exfiltration, credential harvesting, obfuscation, or suspicious system interactions.
- `middleware/immer.js` (safe): The code is a legitimate Zustand middleware integration for Immer with no malicious patterns detected.
- `react.js` (safe): No malicious patterns detected; the code is a standard Zustand React binding with no exfiltration, obfuscation, or dangerous operations.
- `react/shallow.js` (safe): Cleared by Jev triage; no further analysis needed
- `shallow.js` (safe): No malicious patterns detected; the file only re-exports shallow and useShallow from zustand submodules.
- `traditional.js` (safe): Cleared by Jev triage; no further analysis needed
- `vanilla.js` (safe): No malicious patterns detected; this is a standard Zustand-style vanilla store implementation with no network, filesystem, or dynamic execution activity.
- `vanilla/shallow.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of zustand are flagged high or critical. The latest scanned version, 5.0.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.0.0 – 5.0.3 (`>=5.0.0 <=5.0.3`): clean

## Scanned versions

- [5.0.3](https://security.togoder.click/npm/zustand@5.0.3): safe, 2026-10-04T16:47:33.000Z
- [5.0.0](https://security.togoder.click/npm/zustand@5.0.0): safe, 2026-10-04T16:19:12.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
