78%
Total Score
healthy
Frequent releases and active organization backing offset concentrated commits, unpinned workflow actions, and an unclear package-to-repository link.
The primary publish domain is workos.com, consistent with the organization-owned project. The gmail.com account hadihallak and chance.dev account chancestrickland are outside identities, creating account-hygiene caution despite the company-backed setup.
Only 2 contributors were active in the last 3 months, and one made 98.9% of commits. Organization backing partly compensates, but the recent activity remains highly concentrated.
The repository name does not match the package name and its README does not mention this package. A monorepo can explain the name mismatch, but the lack of a README mention makes package ownership less transparent.
The project uses build tooling such as Vitest, Vite, npm scripts, and TypeScript, but no security scanning tools were detected; this is a modest transparency gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/react-id Version 1.1.4 | — | — |
@radix-ui/primitive Version 1.1.7 | — | — |
@radix-ui/react-menu Version 2.1.25 | — | — |
@radix-ui/react-context Version 1.2.2 | — | — |
@radix-ui/react-primitive Version 2.1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.