78%
Total Score
healthy
Active, well-backed package with strong release hygiene but concentrated maintenance and weak workflow pinning.
Publishing is primarily associated with the workos.com domain and the project is organization-backed. The gmail.com account hadihallak and chance.dev account chancestrickland are account-hygiene cautions, not evidence of limited maintenance capacity.
Two contributors were active, but one made 93 of 94 recent commits, creating a meaningful concentration risk. Organization backing partly compensates because maintenance can be handed off internally.
The repository name differs from the package name and its README does not mention this package. Although a monorepo mismatch is ordinary, the missing README reference leaves some uncertainty about package ownership.
The project uses TypeScript, Vite, Vitest, and npm tooling. No security scanning tools were detected, leaving a modest security-process gap.
No repository security policy was detected, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/primitive Version 1.1.7 | — | — |
@radix-ui/react-toggle Version 1.1.19 | — | — |
@radix-ui/react-context Version 1.2.2 | — | — |
@radix-ui/react-direction Version 1.1.5 | — | — |
@radix-ui/react-primitive Version 2.1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.