An unified permissions API for React Native on iOS, Android and Windows
86%
Total Score
67
100
95
80
The repository is owned by an individual rather than an organization, so there is no organizational succession signal. However, recent activity from two contributors and the package's sustained release record provide meaningful compensating evidence.
One contributor made 8 of 9 recent commits, so contribution activity is concentrated. A second contributor remains active, which partly offsets but does not eliminate the continuity risk for an individually owned project.
The repository uses TypeScript, npm scripts, and Babel for builds, but no security scanning tools were detected. The established build tooling is positive, while the missing scanning is a modest transparency gap.
No SECURITY.md or equivalent security policy was found. This weakens vulnerability-reporting transparency, although the active repository and long release history compensate for some of the concern.
The single analyzed workflow has no top-level token permissions declaration. No write permissions were detected, but explicitly limiting workflow permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.