Focus visible polyfill utility based on WICG
88%
Total Score
healthy
Active, mature package with strong maintenance signals; workflow pinning and security documentation remain weaker.
The repository name does not match the package and its README does not mention this package. Because it is an organization-backed monorepo, the mismatch is explainable, but the missing README mention leaves some package-to-repository transparency uncertainty.
The project uses established TypeScript, Vite, tsup, SWC, npm-script, and esbuild tooling. No security scanning tools were detected, leaving a modest hygiene gap.
No repository security policy was found, reducing transparency for reporting and handling vulnerabilities, although this does not by itself indicate abandonment.
All three workflows were analyzed with no audit findings or untrusted checkouts, but 8 of 9 action references are unpinned and one workflow grants top-level write access, creating a moderate reproducibility and permission-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@zag-js/dom-query Version 1.46.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.