Package Health

@dotenvx/dotenvx

a secure dotenv–from the creator of `dotenv`

Latest 2.34.2NPMNPM

82%

Total Score

healthy

Frequent releases and an active repository support this release, but nearly all recent commits come from one contributor.

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

Although four contributors were active, one contributor made 487 of 490 recent commits, creating a significant concentration and continuity risk. Organization ownership provides some ability to hand work off, but no second contributor is comparably active.

Workflow auditcaution

All workflows were analyzed and use job-level permissions, with no untrusted checkout or script-injection findings. However, 10 of 46 action references are unpinned and the audit found high-confidence adhoc package installs; the repeated cache-poisoning findings are low-confidence hygiene signals.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10538 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@dotenvx/dotenvx is vulnerable to OS command injection in versions 1.24.0 - 1.61.5.
1.24.0 - 1.61.5
High

Package versions

Direct Dependencies

DependencyLast ReleaseScore
undici
Version ^6.28.1
—
—
yocto-spinner
Version ^1.2.1
—
—
@dotenvx/tooling
Version ^1.0.5
—
—
write-file-atomic
Version ^5.0.1
—
—
@dotenvx/providers
Version ^0.3.5
—
—

Weekly Downloads

Info

Last Published
2 days ago
Created
2 years ago
Unpacked Size
0.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform