A minimal implementation of xstate fsm for UI machines
86%
Total Score
healthy
Active, well-documented package with strong project activity; workflow dependencies are mostly unpinned.
The project uses established TypeScript and build tooling, but no security-scanning tools were detected; this is a modest transparency gap rather than a release-blocking concern.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for consumers of this library.
All three workflows were analyzed with no dangerous sinks or audit findings, but 8 of 9 action references are unpinned and one workflow grants top-level write access, creating workflow-hygiene risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-57079 @zag-js/core is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 0.82.2. | 0.0.0 - 0.82.2 | High |
| Dependency | Last Release | Score |
|---|---|---|
@zag-js/utils Version 1.45.0 | — | — |
@zag-js/dom-query Version 1.45.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.