Healthy and suitable to install. It has exceptionally active maintenance, broad contributor participation, reproducible publishing, and strong repository hygiene; the main caveats are no security policy or automated security scanning and workflows that do not declare top-level permissions.
91%
Total Score
100
100
90
80
100
The repository uses TypeScript, Babel, and npm build tooling, but reports no security-scanning tools, leaving a genuine security-process gap.
No SECURITY.md or equivalent security policy was found, reducing transparency about vulnerability reporting and response.
All 14 workflows lack top-level token permissions declarations. No workflow requests top-level write access, which limits severity, but explicit least-privilege configuration would be stronger.
Version 4.28.0 is a stable major release and is not a prerelease, although the recent prerelease share is high at 95%, which adds some release-channel complexity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
warn-once Version ^0.1.0 | — | — |
react-freeze Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.