Babel plugin for React Native for Web
82%
Total Score
healthy
Long-running, actively maintained package with strong project evidence but weak workflow pinning and supply-chain transparency.
The release has no build attestation or trusted-publisher configuration, leaving publication provenance less transparent than stronger supply-chain setups.
The project uses npm scripts and Babel, but no security scanning tools were detected. That is a transparency and hygiene gap, though active tests and review activity provide some compensation.
No repository security policy was found. This reduces the documented process for reporting vulnerabilities, but it does not by itself show poor maintenance.
No type declarations are published. This is a minor consumer-ergonomics gap for a JavaScript Babel plugin, not evidence of abandonment or unsafe maintenance.
All 14 analyzed action references are unpinned, and one workflow uses a high-confidence ad hoc package installation; one workflow also has top-level write permissions. No untrusted checkout or script-injection path was found, limiting the impact to workflow hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.