dropdown ui component for react
81%
Total Score
100
100
94
50
50
No build attestation or trusted-publisher record is available, reducing publishing transparency, although this is a publishing-hygiene gap rather than evidence of an unsafe release.
A prepare install-time script is present, which adds build or execution activity during installation and deserves routine review, though it is not severe on its own.
The project has 68 releases over more than 11 years, but no registry releases in the last 12 months. Recent repository activity partly compensates for the slower release cadence.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. Existing security scanning provides partial compensation but does not replace a policy.
All five workflows were analyzed with no audit findings or untrusted checkouts, but three use top-level write permissions and five of ten action references are unpinned. Without an untrusted trigger, these remain moderate hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rc-util Version ^5.44.1 | — | — |
classnames Version ^2.2.6 | — | — |
@babel/runtime Version ^7.18.3 | — | — |
@rc-component/trigger Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.