A cross-platform, performant image component for React Native and Expo with Web support
91%
Total Score
100
100
95
90
50
No build attestation or trusted publisher provenance is available, which leaves publication origin less verifiable even though the package otherwise shows strong maintenance evidence.
The repository name does not match expo-image and its README does not mention the package, creating a transparency concern about the package-to-repository link. The mismatch is plausibly consistent with a monorepo, but the provided signal does not confirm the package path.
24 of 30 analyzed workflows lack top-level permissions declarations, and six declare top-level write access; this weakens least-privilege transparency despite the repository's other security controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sf-symbols-typescript Version ^2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.