a secure dotenv–from the creator of `dotenv`
82%
Total Score
healthy
Frequent releases and an active repository support this release, but nearly all recent commits come from one contributor.
Although four contributors were active, one contributor made 487 of 490 recent commits, creating a significant concentration and continuity risk. Organization ownership provides some ability to hand work off, but no second contributor is comparably active.
All workflows were analyzed and use job-level permissions, with no untrusted checkout or script-injection findings. However, 10 of 46 action references are unpinned and the audit found high-confidence adhoc package installs; the repeated cache-poisoning findings are low-confidence hygiene signals.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10538 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @dotenvx/dotenvx is vulnerable to OS command injection in versions 1.24.0 - 1.61.5. | 1.24.0 - 1.61.5 | High |
| Dependency | Last Release | Score |
|---|---|---|
undici Version ^6.28.1 | — | — |
yocto-spinner Version ^1.2.1 | — | — |
@dotenvx/tooling Version ^1.0.5 | — | — |
write-file-atomic Version ^5.0.1 | — | — |
@dotenvx/providers Version ^0.3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.