Sourcemap Explorer
Stack · npm package

react-router

Declarative routing for React

latest 8.3.0· MIT· 1,175 versions publishedView on npm

About

Declarative routing for React

reactrouterrouteroutinghistorylink

What detecting react-router tells you about a site

react-router is the core routing engine for client-side React apps (react-router-dom is its web binding). Its presence tells you the app is a classic SPA handling its own routing rather than relying on a meta-framework's file-system router, and from v7 it doubles as the foundation of the React Router framework mode that absorbed Remix.

Why the exact react-router version matters

Version 6 was a near-total API rewrite and 6.4+ introduced the data router (loaders/actions); v7 merged the Remix line. The exact version places the app firmly in one routing paradigm and migration era.

react-router in a real-world stack

When you find react-router in a bundle, it rarely travels alone. react-router-dom on the web, react and react-dom; in data-router setups, often a fetching library too.

Quick facts

Latest version8.3.0
LicenseMIT
AuthorRemix Software
Installnpm install react-router
Direct dependencies1
Peer dependenciesreact, react-dom

Common pairings

Packages this one expects to find in the same project. Each is also a Sourcemap Explorer detection target.

What react-router pulls in

react-router declares 1 direct dependency — each one also rides into any bundle that ships react-router, so they are detection targets too. Reading them is a quick way to understand the package's real footprint .

cookie-es

How Sourcemap Explorer detects react-router

react-router ships as v8.3.0, published 2026-07-28 and carries 1 direct dependency, 2 peer dependencies (react, react-dom), 1,175 versions on the registry. Those exact numbers are the footprint Sourcemap Explorer matches when react-router rides inside a deployed bundle — here is how the detection works.

We catch react-router from two complementary signals: bundled source paths and the embedded package.json. Modern bundlers (webpack, Vite, esbuild, Rollup, Turbopack) preserve the original node_modules/react-router/ paths inside the JavaScript sourcemap's sources[] array — that's the canonical signal. When the matching package.json is also captured in sourcesContent[], we read the exact version field — patch number included. No regex guessing, no version inference.

  1. 1

    Confirm the site exposes sourcemaps

    In DevTools Network, check the response headers of any application script for `SourceMap` or `X-SourceMap`. Failing that, fetch the script's last 4 KB and look for a `//# sourceMappingURL=` comment — that map is where the `react-router` paths live.

  2. 2

    Find the package in the bundle

    Open DevTools → Network → reload. Click any application script and look at its sourcemap. Inside, search `sources[]` for entries matching `node_modules/react-router/` — every match confirms the package is bundled. The matching `sourcesContent[i]` for `node_modules/react-router/package.json` gives you the exact installed version.

  3. 3

    Read the version directly from package.json

    Run `jq -r '. as $m | $m.sources | to_entries[] | select(.value | endswith("node_modules/react-router/package.json")) | $m.sourcesContent[.key] | fromjson | .version' bundle.js.map`. Sourcemap Explorer automates the same query in the popup.

Major releases of react-router

When each major version first landed. Major bumps are where breaking changes live, so this timeline is the fastest way to date the react-router version a site actually ships against the ecosystem.

Major
First release
Date
v8
8.0.0
2026-06-17
v7
7.0.0
2024-11-22
v6
6.0.0
2021-11-03
v5
5.0.0
2019-03-18
v4
4.0.0
2017-03-11
v3
3.0.0
2016-10-25

Recent security advisories for react-router

The 5 most recent advisories affecting some versions of react-router, aggregated from OSV.dev (GitHub Advisory + CVE data). A listing here doesn't mean the version a given site ships is affected — each advisory applies to a specific version range. Sourcemap Explorer reads the exact bundled version so you can check it against these ranges.

  1. HIGHGHSA-qwww-vcr4-c8h2· 2026-07-24

    React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response

  2. HIGHCVE-2026-55685· 2026-07-24

    React Router: Unauthenticated Denial of Service via Inefficient Route Matching

  3. MODERATECVE-2026-53669· 2026-07-23

    React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)

  4. MODERATECVE-2026-53668· 2026-07-23

    React Router: Open redirect leading to XSS

  5. MODERATECVE-2026-53667· 2026-07-23

    React Router: RSCErrorHandler Missing Protocol Validation (XSS)

Recent versions

Version
Released
8.3.0
2026-07-22
8.2.0
2026-07-08
8.1.0
2026-06-29
8.0.1
2026-06-18
8.0.0
2026-06-17
7.18.2
2026-07-28
7.18.1
2026-06-29
7.18.0
2026-06-16

react-router README

Live mirror of the GitHub README, for reference. Updated whenever the repo's default branch changes.

react-router is the primary package in the React Router project.

Installation

npm i react-router

FAQ

What is react-router used for?

Declarative routing for React

How can I tell if a website is using react-router?

Open the page in Chrome with the Sourcemap Explorer extension installed and read the Stack tab. We catch `react-router` from two complementary signals: `node_modules/react-router/` paths inside the JavaScript sourcemap, and the embedded `package.json` we read for exact-version detection. Without the extension you can do the same lookup manually in DevTools — the steps are listed in the "How Sourcemap Explorer detects" section above.

How do I find out which version of react-router a website is running?

Read it straight from the site's JavaScript sourcemap. When a build ships source maps, the bundled `react-router/package.json` carries the exact `version` string — Sourcemap Explorer extracts it in one click on the Stack tab, and you can do it by hand in DevTools by opening the `.map` file and searching for `node_modules/react-router/package.json`. That is far more reliable than inferring the version from an asset-hash or a `?ver=` query string, which is all surface-level detectors have to go on. The current npm release is 8.3.0, but real deployments frequently run an older pinned version — which is exactly why reading the bundled number matters.

What is the latest version of react-router?

8.3.0, as published on the npm registry. The "Recent versions" table on this page lists the most recent 8 releases with their release dates. Sourcemap Explorer reports the version actually bundled into a site, which can lag the latest release by months on real-world deployments.

Is react-router actively maintained?

Very actively maintained — the last release shipped within the past three months. The last published release was 2026-07-28. Source code: https://github.com/remix-run/react-router.

Does react-router have known security vulnerabilities?

5 recent advisories affecting some versions of react-router are listed in the "Recent security advisories" section above, aggregated from OSV.dev (GitHub Advisory + CVE data). Whether a particular site is exposed depends entirely on the exact version it ships — each advisory applies to a specific version range, not to the package as a whole. That is why the precise bundled version matters: Sourcemap Explorer reads the version a site actually runs, so you can check it against the affected ranges instead of assuming the latest release is what's deployed.

Where can I read more?

Source code: https://github.com/remix-run/react-router. Published on npm: https://www.npmjs.com/package/react-router. Licensed as MIT.

Keep reading on Sourcemap Explorer

Detected by Sourcemap Explorer

When a bundle ships sourcemaps, we read the embedded package.json for react-router and report the precise version (the registry's latest is v8.3.0, published 2026-07-28; the bundled copy is often older). Without sourcemaps, an import / require in the page's scripts is enough to flag it.

Install free on Chrome