Ultimate calendar for your React app.
76%
Total Score
75
94
75
100
The repository is owned by a user rather than an organization, so the single-contributor concentration is a meaningful continuity concern rather than something clearly covered by organizational backing.
One contributor made all eight commits in the last three months, concentrating maintenance responsibility and increasing continuity risk for a user-owned project.
TypeScript and npm build tooling are present, but no security scanning tool was detected. The missing scanner is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for users and maintainers.
All workflows were analyzed and had no untrusted checkouts or script-injection findings, but all 14 action references are unpinned and one workflow grants top-level write access. The low-confidence cache finding is hygiene rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
clsx Version ^2.0.0 | — | — |
warning Version ^4.0.0 | — | — |
get-user-locale Version ^3.0.0 | — | — |
@wojtekmaj/date-utils Version ^2.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.