78%
Total Score
healthy
Active releases and organization backing outweigh concentrated commits and entirely unpinned workflow actions.
Four accounts can publish, with two using the organization domain; hadihallak (gmail.com) and chancestrickland (chance.dev) are outside-domain publishing accounts, creating account-hygiene caution, though organization backing partly compensates.
Only two contributors were active in the last 3 months, and one made 98.9% of commits; organization ownership reduces handoff risk, but the observed activity remains highly concentrated.
The repository had 8 new issues, 3 closed issues, 14 new pull requests, and 3 merged pull requests in the last month, showing ongoing participation but a growing unresolved queue.
The repository name does not match the package name and its README does not mention this package, creating some uncertainty about package-to-repository mapping; the monorepo context makes a name mismatch plausible but does not remove the documentation gap.
The project uses Vitest, Vite, TypeScript, and npm scripts for builds and tests, but no security-scanning tooling was detected, leaving a modest process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/react-id Version 1.1.4 | — | — |
@radix-ui/primitive Version 1.1.7 | — | — |
@radix-ui/react-context Version 1.2.2 | — | — |
@radix-ui/react-presence Version 1.1.11 | — | — |
@radix-ui/react-primitive Version 2.1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.