Healthy and suitable to install, with strong ongoing maintenance and mature project backing. The main caveats are missing build attestation and security policy, plus the linked monorepo does not explicitly mention this package in its README.
88%
Total Score
100
100
85
90
50
No build attestation or trusted publisher identity is present, leaving release origin less independently verifiable even though other maintenance signals are strong.
The repository name does not match the package and its README does not mention @a2ui/web_core, creating some uncertainty about package-to-repository linkage; the organization-backed monorepo and matching namespace partly compensate.
The project uses npm scripts and TypeScript, but no security scanning tools were detected; the build setup is established while automated security coverage is a gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Version 0.11.0 is not yet a stable major release, and 28% of recent releases were prereleases, so the API may still change despite the current release itself not being marked prerelease.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-619367 @a2ui/web_core is vulnerable to Cross-Site Scripting (XSS) in versions 0.9.0 - 0.10.1. | 0.9.0 - 0.10.1 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
lit Version ^3.3.3 | — | — |
zod Version ^3.25.76 | — | — |
date-fns Version ^4.4.0 | — | — |
@lit/context Version ^1.1.6 | — | — |
zod-to-json-schema Version ^3.25.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.