npm package report

Is zustand safe?

Checked against the XYZ decision brain: known-malicious corpus, advisories, commit-level findings, dependencies and provenance.

cyberxyz.io/packages/npm/zustand
npm packagelast checked 2026-07-17

zustand · verdict ALLOW · no known risk

0.6/10
XYZ SCORE
SUMMARY

Verdict ALLOW · 25 graph-tracked dependencies · provenance: verified (sigstore)

Re-check live →

SIGNALS
Commit-Level AnalysisclearOK

3 unconfirmed pattern hit(s) in watched commit history; none verified as malicious.

DEPENDENCIES
@babel/core@7.3.4clean
@babel/plugin-proposal-class-properties@^7.4.4clean
@babel/plugin-transform-modules-commonjs@7.2.0clean
@babel/plugin-transform-parameters@7.3.3clean
@babel/plugin-transform-react-jsx@^7.3.0clean
@babel/plugin-transform-runtime@7.3.4clean
@babel/plugin-transform-template-literals@7.2.0clean
@babel/plugin-transform-typescript@^7.4.0clean
@babel/preset-env@7.3.4clean
@babel/preset-react@7.0.0clean
@babel/preset-typescript@^7.3.3clean
@babel/runtime@^7.4.3clean
copyfiles@^2.1.0clean
enzyme@^3.9.0clean
enzyme-adapter-react-16@^1.12.1clean
husky@^1.3.1clean
jest@^24.7.1clean
json@^9.0.6clean
lint-staged@^8.1.5clean
prettier@^1.16.4clean
PACKAGE zustandECOSYSTEM npmDECISION ALLOW

Baked snapshot · run a live check for the current verdict · browse all packages