68%
Total Score
100
100
83
67
The package has had no registry release in about 16 months, which raises maintenance and freshness concerns. Recent repository activity partly offsets the long release gap.
The repository name does not match @nivo/text and its README does not mention the package. The repository is clearly structured as a larger Nivo project, so the mismatch is consistent with a monorepo but still leaves package ownership less explicit.
The repository uses established build tooling, but no security scanning tools were detected, leaving a modest security-hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and handling.
The audit analyzed both workflows completely and found no dangerous sinks or high-severity findings, with job-level permissions used in one workflow. However, all 15 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@nivo/core Version 0.99.0 | — | — |
@nivo/theming Version 0.99.0 | — | — |
@react-spring/web Version 9.4.5 || ^9.7.2 || ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.