Package Health

react-native-sensitive-info

Recent releases, tests, documentation, and a live repository show genuine maintenance. A single active contributor, completely unpinned workflow actions, and an audited package install add adoption risk; verify the package identity carefully before use.

Latest 6.1.5NPMNPM

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

91

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Are you affected? Scan for Free

Health Score Breakdown

Name lookalikedanger

The package is marked as borrowing the identity of the much more established react-is, with 0.0 artifact overlap and no self-described fork. Consumers may have intended to install react-is instead, making this a serious supply-chain concern.

Project backingcaution

The repository is owned by an individual account rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.

Repo bus factorcaution

One contributor made 100% of the commits in the last 3 months. This concentration creates meaningful continuity risk for a native security-sensitive library.

Repo commit activitycaution

Only 2 commits were recorded over 3 months, all from one active maintainer. Recent publishing activity offsets this somewhat, but the observed code-change pace is thin.

Repo issue activitycaution

There are 14 new pull requests in the last month and 25 open pull requests, showing ongoing participation, although none were merged during that period.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10692 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
react-native-sensitive-info is vulnerable to Insufficient Verification of Data Authenticity in versions 1.0.0 - 5.6.2.
1.0.0 - 5.6.2
Low

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
2 months ago
Created
10 years ago
Unpacked Size
1.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform