
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@usefillo/react
Advanced tools
Headless React components for embedding Fillo forms natively in your product.
Headless React components and hooks for embedding Fillo forms natively inside your product — rendered in your own DOM, with your styles, on your route. No iframe.
npm i @usefillo/react
react and react-dom (18 or 19) are peer dependencies.
import { FilloForm, createClient } from "@usefillo/react";
import "@usefillo/react/styles.css"; // optional default theme — or bring your own
const client = createClient({ baseUrl: "https://fillo.so" });
export function Feedback() {
return <FilloForm client={client} formId="cust-feedback" onSubmitted={(r) => confetti()} />;
}
Every part is replaceable. Pass your own field components, theme the form via the theme prop, or drop down to the hooks and own the entire render:
<FilloForm> / <FilloProvider> — render a form, or wrap your own layoutuseFillo() / useField() — build a fully custom UI against form stateuseFilloController() — headless controller for total controlFormField / BlockRenderer — render individual blocksdefineForm() — author a form in code and sync it to your workspace on first runThis package re-exports the embedding surface from @usefillo/core (createClient, FormSchema, FormTheme, …) so a single import is usually enough.
MIT licensed.
FAQs
Headless React components for embedding Fillo forms natively in your product.
The npm package @usefillo/react receives a total of 419 weekly downloads. As such, @usefillo/react popularity was classified as not popular.
We found that @usefillo/react demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.