A library of styleable components built using React Aria
88%
Total Score
healthy
Frequent releases and active, diverse Adobe-backed maintenance outweigh unpinned workflows and weak package-to-repository naming evidence.
No build attestation or trusted-publisher configuration was observed, leaving release provenance less transparent despite the repository’s active maintenance.
The repository name does not match react-aria-components and its README does not mention the package, creating some uncertainty about the exact package-to-source linkage. The organization-owned monorepo context partly compensates for this mismatch.
All eight workflows were analyzed with no audit findings or untrusted checkouts, and no workflow grants top-level write access. However, all 15 action references are unpinned, which weakens CI supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react-aria Version 3.53.1 | — | — |
client-only Version ^0.0.1 | — | — |
@swc/helpers Version ^0.5.0 | — | — |
react-stately Version 3.51.0 | — | — |
@react-types/shared Version ^3.37.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.