⚡️ The fastest key/value storage for React Native.
83%
Total Score
100
100
100
67
50
No build attestation or trusted-publisher provenance was reported, leaving release origin less verifiable even though the package has strong maintenance evidence.
No security policy was found in the repository, reducing transparency around vulnerability reporting and response expectations.
All 49 analyzed action references are unpinned, and a high-confidence bot-condition finding affects the lockfile workflow; archived actions also appear in release workflows. Low-confidence cache findings are hygiene concerns, but no untrusted checkout or script-injection path was detected.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-21668 react-native-mmkv is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.0 - 2.11.0. | 0.0.0 - 2.11.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.