Package Health

@zag-js/focus-visible

Focus visible polyfill utility based on WICG

Latest 1.46.0NPMNPM

88%

Total Score

healthy

Active, mature package with strong maintenance signals; workflow pinning and security documentation remain weaker.

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package and its README does not mention this package. Because it is an organization-backed monorepo, the mismatch is explainable, but the missing README mention leaves some package-to-repository transparency uncertainty.

Repo toolingcaution

The project uses established TypeScript, Vite, tsup, SWC, npm-script, and esbuild tooling. No security scanning tools were detected, leaving a modest hygiene gap.

Security policycaution

No repository security policy was found, reducing transparency for reporting and handling vulnerabilities, although this does not by itself indicate abandonment.

Workflow auditcaution

All three workflows were analyzed with no audit findings or untrusted checkouts, but 8 of 9 action references are unpinned and one workflow grants top-level write access, creating a moderate reproducibility and permission-hygiene concern.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
@zag-js/dom-query
Version 1.46.0
—
—

Weekly Downloads

Info

Last Published
1 hour ago
Created
4 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform