
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
@zeroheight/adoption-cli
Advanced tools
CLI for measuring component usage to view in your zeroheight account.
For full walk through on how to use this CLI tool, head over to our help centre article.
npm i @zeroheight/adoption-cli
When running a command, you will be prompted to authenticate. This will save the Client ID and Access Token to your local machine.
Alternatively, you can authenticate by running the following command:
zh-adoption auth
When running a command with the --interactive false flag, you will need to provide the Client ID and Access Token as environment variables.
export ZEROHEIGHT_CLIENT_ID="your-client-id"
export ZEROHEIGHT_ACCESS_TOKEN="your-access-token"
In the React repository in which you wish to get usage metrics around how components from your design system packages are being used, run the following command:
zh-adoption analyze
-e / --extensions
Provide a glob pattern to search for files with a specific extension.
zh-adoption analyze -e "**/*.{js,jsx,ts,tsx}"
-i / --ignore
Provide a glob pattern to ignore files, directories or file extensions when searching for components.
zh-adoption analyze -i "**/*.{test,spec}.*"
-r / --repo-name
Provide a name for the current repository. This must be passed when -in / --interactive is set to false.
zh-adoption analyze -r "My Repo"
-in / --interactive
Pass in false to disable the interactive mode e.g. when running in a CI environment.
zh-adoption analyze --interactive false -r "My Repo"
This will analyze your code repository to help you understand what packages are being used and at what version.
In the repository in which you wish to monitor, run the following command:
zh-adoption monitor-repo
-d / --dir
Provide a path to the specific folder to find package.json and lock file. This option can be passed through multiple times. If not included all folders with package.json and lockfile will be uploaded to zeroheight.
zh-adoption monitor-repo -d ./webApp
This will give zeroheight the name and current version of your design system package so you can compare it to the version being used by your other code repositories.
In the repository containing your design system package, run the following command:
zh-adoption track-package
-in / --interactive
Pass in false to disable the interactive mode e.g. when running in a CI environment.
zh-adoption track-package --interactive false
More info on the commands can be seen by running
zh-adoption --help
FAQs
CLI for measuring component usage
The npm package @zeroheight/adoption-cli receives a total of 3,148 weekly downloads. As such, @zeroheight/adoption-cli popularity was classified as popular.
We found that @zeroheight/adoption-cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.