Resizable component for React.
68%
Total Score
50
100
92
50
50
No build attestation or trusted-publisher provenance is present. This limits publication transparency, but it is not by itself evidence that the release is unsafe.
The package has existed for about 9 years with 97 releases, but it has had no releases in the last 12 months. That suggests slowing maintenance rather than abandonment by itself.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is a meaningful maintenance warning, although the project was pushed recently and is not archived.
No security policy was found in the linked repository. This weakens vulnerability-reporting transparency, though the package otherwise shows established documentation and licensing.
The single workflow was fully analyzed with no injection or high-confidence audit findings, but all 9 action references are unpinned. That is a supply-chain hygiene gap without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.