notification ui component for react
82%
Total Score
100
94
50
50
No build attestation or trusted-publisher provenance is available, leaving the published artifact's origin less independently verifiable.
A prepare install-time script is present, adding a small amount of installation complexity even though no more dangerous lifecycle script is reported.
The package is mature, with 80 releases since 2015, but it has had no registry release in the last 12 months. Recent repository activity partly compensates for the paused publishing cadence.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities.
All five workflows were analyzed with no audit findings or untrusted checkouts, but 3 workflows grant top-level write permissions and 5 of 10 action references are unpinned. These are workflow hygiene concerns, not a severe risk on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rc-util Version ^5.20.1 | — | — |
rc-motion Version ^2.9.0 | — | — |
classnames Version 2.x | — | — |
@babel/runtime Version ^7.10.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.