Package Health

react-bootstrap

Bootstrap 5 components built with React

Latest 2.10.10NPMNPM

45%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Name lookalikedanger

The signal says the package borrows the identity of react-is, a much more downloaded package, even though artifact overlap is 0.0. Under the identity-borrowing rule, this is a severe adoption risk because consumers may have intended the lookalike package.

Release historycaution

The package is over 12 years old with 229 releases and a median release interval of about 9 days, showing substantial maturity. However, only one release occurred in the last 12 months, so current momentum is weaker than its historical record.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a meaningful sign of recently slowed maintenance despite the repository being pushed recently.

Security policycaution

No repository security policy was found, reducing transparency for vulnerability reporting. This is a hygiene gap rather than evidence that the package is unsafe.

Workflow auditcaution

The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts or injection findings. All 5 action references are unpinned, leaving avoidable build reproducibility and action-update risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
warning
Version ^4.0.3
—
—
invariant
Version ^2.2.4
—
—
classnames
Version ^2.3.2
—
—
prop-types
Version ^15.8.1
—
—
@restart/ui
Version ^1.9.4
—
—

Weekly Downloads

Info

Last Published
1 year ago
Created
12 years ago
Unpacked Size
1.5 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform