72%
Total Score
83
100
85
75
The repository is owned by an individual rather than an organization, so the single registry maintainer does not benefit from visible organization backing.
The package has 52 releases since 2019, but none in the last 12 months; this is a meaningful release-maintenance concern, partly offset by recent repository activity.
The repository name does not match the package and its README does not mention @nivo/tooltip, so the package-to-repository link is less transparent than it should be, despite the repository appearing to be a broader project source.
The project uses TypeScript, Babel, Rollup, and npm tooling, but no security-scanning tools were detected; the missing scanning is a modest transparency gap.
No repository security policy was found, leaving vulnerability-reporting and security-maintenance expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@nivo/core Version 0.99.0 | — | — |
@nivo/theming Version 0.99.0 | — | — |
@react-spring/web Version 9.4.5 || ^9.7.2 || ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.