72%
Total Score
caution
Active releases and organization backing are offset by highly concentrated commits, an unrelated-looking repository reference, and unpinned workflow actions.
The package has organization-linked publishing accounts, but `hadihallak (gmail.com)` and `chancestrickland (chance.dev)` are outside the primary `workos.com` domain, creating some account-continuity caution. Organization backing partly compensates.
The top contributor made 93 of 94 commits, or 98.9%, while the second contributor made only one. Organization ownership provides some handoff capacity, but the observed activity is still unusually concentrated.
The linked repository name does not match the package and its README does not mention `@radix-ui/react-form`, so the package-to-repository relationship is less transparent even though the repository is a large monorepo-style project.
The repository uses Vitest, Vite, TypeScript, and npm scripts, but no security scanning tools were detected; the missing scanning is a moderate hygiene gap rather than evidence of abandonment.
No repository security policy was found, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/react-id Version 1.1.4 | — | — |
@radix-ui/primitive Version 1.1.7 | — | — |
@radix-ui/react-label Version 2.1.16 | — | — |
@radix-ui/react-context Version 1.2.2 | — | — |
@radix-ui/react-primitive Version 2.1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.