react-native-zip-archive 9.5.1 appears to be a healthy, actively maintained dependency. It has a long release history, frequent recent releases, a stable non-prerelease version, no registry deprecation, an active non-archived organization-backed repository, recent commits and pull-request activity, comprehensive documentation and tests, an MIT license, type declarations, build provenance, and no install-time lifecycle scripts or declared runtime dependencies. The main concerns are that repository security scanning is not reported and most workflows lack explicit top-level token permissions, with the publish workflow declaring write access; these are workflow-hygiene risks but are not accompanied by detected dangerous workflow patterns. The recent commits are concentrated in one contributor, though two additional contributors remain active and organizational backing reduces the bus-factor concern.
88%
Total Score
100
100
95
90
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-703453 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. react-native-zip-archive is vulnerable to Path Traversal in versions 6.0.9 - 9.0.1. | 6.0.9 - 9.0.1 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.