Spectrum UI components in React
88%
Total Score
healthy
Healthy: frequent releases and active Adobe-backed maintenance outweigh workflow pinning and package-identification gaps.
No build attestation or trusted-publisher identity is present, limiting release provenance transparency. This is a moderate hygiene gap rather than evidence that the release is unsafe.
The linked repository is a broader monorepo and neither matches the package name nor mentions it in the README, so package ownership is less transparent even though the organization backing is clear.
All eight workflows were analyzed with no reported audit findings, no untrusted checkout or script-injection paths, and scoped read-only or job-level permissions. However, all 15 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@swc/helpers Version ^0.5.0 | — | — |
react-stately Version ^3.46.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.