80%
Total Score
healthy
Active releases and organization backing are offset by unpinned CI actions and weak package-to-repository naming evidence.
The package is organization-backed with two workos.com publisher accounts, but hadihallak (gmail.com) and chancestrickland (chance.dev) are outside-domain publishing accounts, creating account-hygiene caution.
The repository name does not match the package name and its README does not mention this package, so the package-to-repository relationship is less transparent even though a monorepo can explain the mismatch.
The repository uses build and test tooling, but no security-scanning tools were detected, leaving a modest security-hygiene gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All 8 analyzed action references are unpinned, so workflow dependencies can change unexpectedly. However, all workflows were analyzed and no untrusted checkouts, script injection, dangerous triggers, or audit findings were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/react-primitive Version 2.1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.