Scanning package - this fetches live data from the registry and GitHub, so it can take a few seconds…
Scanning package - this fetches live data from the registry and GitHub, so it can take a few seconds…
risk score 35/100 - 35 from supply-chain heuristics · 0 from known vulnerabilities
⚠️ Deep scan did not complete
Deep scan did not complete due to an unexpected error (AsyncMessages.parse() got an unexpected keyword argument 'temperature').
Supply-chain / malicious-intent signals - typosquatting, maintainer takeovers, install scripts, and similar.
Name 'reactt' is within edit distance 1 of popular package 'react' but does not match it exactly.
Package metadata does not link to a GitHub repository.
Published CVE/GHSA advisories for this exact version, via OSV.dev - independent of the findings above. A package can have no supply-chain findings and still carry a known vulnerability.
Recursively checks this package's dependencies (and their dependencies) for known issues - e.g. "this package is fine, but depends on X which has a CVE."