This release appears healthy and suitable to depend on. It has a long release history with 335 releases and 68 releases in the last 12 months, is a stable non-prerelease version, is not deprecated, and was published with npm provenance. The linked organization-owned repository is active rather than archived, with substantial recent commits, 38 active maintainers, strong contributor distribution, active issue and pull-request throughput, security scanning, a security policy, and read-only workflow permissions. The package includes a license file, extensive type declarations, a README, changelog, and a substantial artifact; the absence of packaged tests is compensated by repository tests. The only modest concern is that two workflows use pull_request_target, although the analyzed workflows show no untrusted checkout or script injection and all declare read-only permissions.
96%
Total Score
100
100
100
90
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
clsx Version ^2.1.1 | — | — |
@mui/utils Version ^9.4.0 | — | — |
prop-types Version ^15.8.1 | — | — |
@babel/runtime Version ^7.29.7 | — | — |
@mui/x-license Version ^9.13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.