
react-router-dom
Declarative routing for React web applications
About
Declarative routing for React web applications
What detecting react-router-dom tells you about a site
react-router-dom is the routing layer for a client-side React app that isn't using a meta-framework's built-in router. Its presence tells you the app is a classic SPA (often Vite- or CRA-built) rather than a Next.js/Remix app where routing is file-system based.
Why the exact react-router-dom version matters
React Router 6 was a near-total API rewrite (Routes/element instead of Switch/component), and 6.4+ introduced the data router (loaders/actions) that became the foundation for Remix. Version 7 merged the Remix and React Router lines. The exact bundled version tells you which routing paradigm — and which migration era — the app belongs to.
react-router-dom in a real-world stack
When you find react-router-dom in a bundle, it rarely travels alone. react and react-dom; in data-router setups, often a fetching library too.
Quick facts
npm install react-router-domCommon pairings
Packages this one expects to find in the same project. Each is also a Sourcemap Explorer detection target.
What react-router-dom pulls in
react-router-dom declares 1 direct dependency — each one also rides into any bundle that ships react-router-dom, so they are detection targets too. Reading them is a quick way to understand the package's real footprint .
How Sourcemap Explorer detects react-router-dom
react-router-dom ships as v7.18.2, published 2026-07-28 and carries 1 direct dependency, 2 peer dependencies (react, react-dom), 1,059 versions on the registry. Those exact numbers are the footprint Sourcemap Explorer matches when react-router-dom rides inside a deployed bundle — here is how the detection works.
We catch react-router-dom from two complementary signals: bundled source paths and the embedded package.json. Modern bundlers (webpack, Vite, esbuild, Rollup, Turbopack) preserve the original node_modules/react-router-dom/ paths inside the JavaScript sourcemap's sources[] array — that's the canonical signal. When the matching package.json is also captured in sourcesContent[], we read the exact version field — patch number included. No regex guessing, no version inference.
- 1
Confirm the site exposes sourcemaps
In DevTools Network, check the response headers of any application script for `SourceMap` or `X-SourceMap`. Failing that, fetch the script's last 4 KB and look for a `//# sourceMappingURL=` comment — that map is where the `react-router-dom` paths live.
- 2
Find the package in the bundle
Open DevTools → Network → reload. Click any application script and look at its sourcemap. Inside, search `sources[]` for entries matching `node_modules/react-router-dom/` — every match confirms the package is bundled. The matching `sourcesContent[i]` for `node_modules/react-router-dom/package.json` gives you the exact installed version.
- 3
Read the version directly from package.json
Run `jq -r '. as $m | $m.sources | to_entries[] | select(.value | endswith("node_modules/react-router-dom/package.json")) | $m.sourcesContent[.key] | fromjson | .version' bundle.js.map`. Sourcemap Explorer automates the same query in the popup.
Major releases of react-router-dom
When each major version first landed. Major bumps are where breaking changes live, so this timeline is the fastest way to date the react-router-dom version a site actually ships against the ecosystem.
Recent security advisories for react-router-dom
The 1 most recent advisories affecting some versions of react-router-dom, aggregated from OSV.dev (GitHub Advisory + CVE data). A listing here doesn't mean the version a given site ships is affected — each advisory applies to a specific version range. Sourcemap Explorer reads the exact bundled version so you can check it against these ranges.
React Router: Open redirect leading to XSS
Recent versions
react-router-dom README
Live mirror of the GitHub README, for reference. Updated whenever the repo's default branch changes.
React Router is a multi-strategy router for React. You can use it maximally as a React framework or minimally as a library with your own architecture.
Packages
react-routercreate-react-router@react-router/dev@react-router/node@react-router/serve@react-router/express@react-router/architect@react-router/cloudflare@react-router/fs-routes
Previous Versions
FAQ
What is react-router-dom used for?
Declarative routing for React web applications
How can I tell if a website is using react-router-dom?
Open the page in Chrome with the Sourcemap Explorer extension installed and read the Stack tab. We catch `react-router-dom` from two complementary signals: `node_modules/react-router-dom/` paths inside the JavaScript sourcemap, and the embedded `package.json` we read for exact-version detection. Without the extension you can do the same lookup manually in DevTools — the steps are listed in the "How Sourcemap Explorer detects" section above.
How do I find out which version of react-router-dom a website is running?
Read it straight from the site's JavaScript sourcemap. When a build ships source maps, the bundled `react-router-dom/package.json` carries the exact `version` string — Sourcemap Explorer extracts it in one click on the Stack tab, and you can do it by hand in DevTools by opening the `.map` file and searching for `node_modules/react-router-dom/package.json`. That is far more reliable than inferring the version from an asset-hash or a `?ver=` query string, which is all surface-level detectors have to go on. The current npm release is 7.18.2, but real deployments frequently run an older pinned version — which is exactly why reading the bundled number matters.
What is the latest version of react-router-dom?
7.18.2, as published on the npm registry. The "Recent versions" table on this page lists the most recent 8 releases with their release dates. Sourcemap Explorer reports the version actually bundled into a site, which can lag the latest release by months on real-world deployments.
Is react-router-dom actively maintained?
Very actively maintained — the last release shipped within the past three months. The last published release was 2026-07-28. Source code: https://github.com/remix-run/react-router.
Does react-router-dom have known security vulnerabilities?
1 recent advisory affecting some versions of react-router-dom is listed in the "Recent security advisories" section above, aggregated from OSV.dev (GitHub Advisory + CVE data). Whether a particular site is exposed depends entirely on the exact version it ships — each advisory applies to a specific version range, not to the package as a whole. That is why the precise bundled version matters: Sourcemap Explorer reads the version a site actually runs, so you can check it against the affected ranges instead of assuming the latest release is what's deployed.
Where can I read more?
Project homepage: https://github.com/remix-run/react-router#readme. Source code: https://github.com/remix-run/react-router. Published on npm: https://www.npmjs.com/package/react-router-dom. Licensed as MIT.
Keep reading on Sourcemap Explorer
Detection deep dives
Alternative tools
Detected by Sourcemap Explorer
When a bundle ships sourcemaps, we read the embedded package.json for react-router-dom and report the precise version (the registry's latest is v7.18.2, published 2026-07-28; the bundled copy is often older). Without sourcemaps, an import / require in the page's scripts is enough to flag it.