78%
Total Score
healthy
Strong release cadence and active organization-backed project, offset by an unlinked package name and all workflow actions being unpinned.
The primary publishing domain is workos.com, but hadihallak (gmail.com) and chancestrickland (chance.dev) are outside-domain publishing accounts, creating account-hygiene risk despite organization backing.
The repository has active recent issue and pull-request traffic, though only 3 issues and 3 pull requests were closed in the last month against a larger open backlog.
The repository name does not match the package name and its README does not mention this package, so the linkage is less transparent even though a monorepo can legitimately host subpackages.
The project uses TypeScript, Vite, Vitest, and npm scripts, but no repository security-scanning tools were detected, leaving a modest hygiene gap.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/primitive Version 1.1.7 | — | — |
@radix-ui/react-dialog Version 1.2.0 | — | — |
@radix-ui/react-context Version 1.2.2 | — | — |
@radix-ui/react-primitive Version 2.1.11 | — | — |
@radix-ui/react-compose-refs Version 1.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.