React is a JavaScript library for building user interfaces.
82%
Total Score
100
100
83
100
All 26 workflows were analyzed successfully and 25 use read-only permissions, but 196 of 203 action references are unpinned. High-confidence template-injection findings affect release-related workflows, while the low-confidence cache findings are hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2013-7035 react is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.4.0 - 0.4.2 and 0.5.0 - 0.5.2. | 0.4.0 - 0.4.20.5.0 - 0.5.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.