Package Health

@zag-js/core

A minimal implementation of xstate fsm for UI machines

Latest 1.45.0NPMNPM

86%

Total Score

healthy

Active, well-documented package with strong project activity; workflow dependencies are mostly unpinned.

Are you affected? Scan for Free

Health Score Breakdown

Repo toolingcaution

The project uses established TypeScript and build tooling, but no security-scanning tools were detected; this is a modest transparency gap rather than a release-blocking concern.

Security policycaution

The repository has no published security policy, leaving vulnerability-reporting expectations unclear for consumers of this library.

Workflow auditcaution

All three workflows were analyzed with no dangerous sinks or audit findings, but 8 of 9 action references are unpinned and one workflow grants top-level write access, creating workflow-hygiene risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-57079
@zag-js/core is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 0.82.2.
0.0.0 - 0.82.2
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@zag-js/utils
Version 1.45.0
—
—
@zag-js/dom-query
Version 1.45.0
—
—

Weekly Downloads

Info

Last Published
5 days ago
Created
4 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform