Summary
packages/scan/src/web/utils/check-react-grab-version.ts:14-37 (called from packages/scan/src/core/index.ts:470) fetches:
https://www.react-grab.com/api/version?source=react-scan&v=<bundled version>&t=<Date.now()>
on every start(). This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is no opt-out flag.
Mitigating factors
start() early-returns in production builds (core/index.ts:462-468) unless dangerouslyForceRunInProduction, so this mainly fires in dev.
- Payload is minimal (version + timestamp), but IP/UA are inherent to any HTTP request.
Suggested fix
- Gate behind the same telemetry/DO_NOT_TRACK conventions used elsewhere in the ecosystem (react-grab CLI honors
DO_NOT_TRACK; react-doctor has --no-telemetry).
- Document the ping in the README regardless.
Note: react-scan/lite already does this exactly right — event POSTing is strictly opt-in, and lite.test.ts:83-84 asserts lite never touches fetch/XHR. Applying the same philosophy to the version check would make the package consistent.
Summary
packages/scan/src/web/utils/check-react-grab-version.ts:14-37(called frompackages/scan/src/core/index.ts:470) fetches:on every
start(). This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is no opt-out flag.Mitigating factors
start()early-returns in production builds (core/index.ts:462-468) unlessdangerouslyForceRunInProduction, so this mainly fires in dev.Suggested fix
DO_NOT_TRACK; react-doctor has--no-telemetry).Note:
react-scan/litealready does this exactly right — event POSTing is strictly opt-in, andlite.test.ts:83-84asserts lite never touchesfetch/XHR. Applying the same philosophy to the version check would make the package consistent.