visx curve
68%
Total Score
caution
Usable with caveats: only one repository commit in three months, all from one contributor.
One contributor made all commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
Only 1 commit was recorded in the last three months, indicating very limited recent repository activity despite the recent package release history.
The repository name does not match @visx/curve and its README does not mention the package, so the package-to-repository link is less directly verifiable; the monorepo context makes a name mismatch ordinary but does not remove the documentation gap.
The repository uses TypeScript, Vitest, Babel, and npm scripts, and has a build tool; no security scanning tool was detected, which is a minor transparency gap.
Both workflows were analyzed with no reported audit findings, no untrusted checkout or script injection, and no top-level write permissions. However, all 6 action references are unpinned, leaving a workflow reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@visx/vendor Version 4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.