Package Health

@radix-ui/react-hover-card

Latest 1.1.24NPMNPM

78%

Total Score

healthy

Frequent releases and active maintenance outweigh unpinned workflow actions and limited repository security documentation.

Health Score Breakdown

Maintainerscaution

The package has four publishing accounts, with two using the organization domain; the gmail.com and chance.dev accounts are account-hygiene cautions, not evidence of limited maintenance capacity.

Repo package mentioncaution

The repository name does not match the package and its README does not mention it, creating some uncertainty about package-to-repository mapping; this is a caution even though the package may be a monorepo subpackage.

Repo toolingcaution

The project uses established build and test tooling, but no security scanning tools were detected, leaving a modest security-process gap.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response.

Workflow auditcaution

All four workflows were analyzed with no audit findings, no untrusted checkouts, and no script injection; however, all 8 action references are unpinned, which weakens build reproducibility.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
@radix-ui/primitive
Version 1.1.7
—
—
@radix-ui/react-popper
Version 1.3.8
—
—
@radix-ui/react-portal
Version 1.1.18
—
—
@radix-ui/react-context
Version 1.2.2
—
—
@radix-ui/react-presence
Version 1.1.11
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
5 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform