78%
Total Score
healthy
Frequent releases and active organization-backed maintenance outweigh workflow pinning and package-link transparency gaps.
The package has a clear workos.com publishing domain, but hadihallak (gmail.com) and chancestrickland (chance.dev) are outside-domain publishing accounts, creating account-hygiene risk.
Recent issue and pull-request activity shows the project is being worked on, although only 3 pull requests were merged in the last month against 14 opened.
The repository name does not match the package and its README does not mention this package, so the linkage is less transparent even though the organization ownership is consistent.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All four workflows were analyzed without dangerous sinks or audit findings, but all 8 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@radix-ui/primitive Version 1.1.7 | — | — |
@radix-ui/react-context Version 1.2.2 | — | — |
@radix-ui/react-direction Version 1.1.5 | — | — |
@radix-ui/react-primitive Version 2.1.11 | — | — |
@radix-ui/react-separator Version 1.1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.