Recent releases, tests, documentation, and a live repository show genuine maintenance. A single active contributor, completely unpinned workflow actions, and an audited package install add adoption risk; verify the package identity carefully before use.
42%
Total Score
50
100
91
88
The package is marked as borrowing the identity of the much more established react-is, with 0.0 artifact overlap and no self-described fork. Consumers may have intended to install react-is instead, making this a serious supply-chain concern.
The repository is owned by an individual account rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
One contributor made 100% of the commits in the last 3 months. This concentration creates meaningful continuity risk for a native security-sensitive library.
Only 2 commits were recorded over 3 months, all from one active maintainer. Recent publishing activity offsets this somewhat, but the observed code-change pace is thin.
There are 14 new pull requests in the last month and 25 open pull requests, showing ongoing participation, although none were merged during that period.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10692 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. react-native-sensitive-info is vulnerable to Insufficient Verification of Data Authenticity in versions 1.0.0 - 5.6.2. | 1.0.0 - 5.6.2 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.