The package is licensed, typed, and backed by active project maintenance with broad contributor participation. Its repository does not name this package, and all 15 workflow actions are unpinned, leaving transparency and build-reproducibility concerns.
82%
Total Score
100
100
94
83
The repository name does not match the package and its README does not mention @react-aria/datepicker, so the linkage is less transparent even though the package is part of the broader repository.
All 8 workflows were analyzed with no audit findings, no untrusted checkout or script-injection sinks, and read-only or job-level permissions in 8 workflows. However, all 15 action references are unpinned, a reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react-aria Version ^3.48.0 | — | — |
@swc/helpers Version ^0.5.0 | — | — |
react-stately Version ^3.46.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.