Spectrum UI components in React
42%
Total Score
unhealthy
Strong project maintenance is offset by a misleading name resemblance and completely unpinned workflow actions.
The package is flagged as borrowing the identity of the much more downloaded react-is, with borrows_lookalike_identity true, despite zero artifact overlap. That creates a serious risk that consumers may select the wrong package.
No build attestation or trusted-publisher provenance was reported. This limits publication transparency, though the active organizational repository provides some compensating project context.
All 15 analyzed action references are unpinned, which weakens build reproducibility and exposes workflows to moving action revisions. The audit is otherwise complete, has no reported findings, scopes permissions in several workflows, and found no untrusted checkout or script injection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@swc/helpers Version ^0.5.0 | — | — |
@react-types/shared Version ^3.37.0 | — | — |
@internationalized/date Version ^3.12.4 | — | — |
use-sync-external-store Version ^1.6.0 | — | — |
@internationalized/number Version ^3.6.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.