A advanced logger for NestJS
68%
Total Score
caution
Usable with caveats: rapid releases and organization backing offset a one-contributor repository, unclear package linkage, and weak workflow pinning.
No build attestation or trusted-publisher provenance is recorded, leaving the connection between source and published artifact less transparent.
All 17 recent commits came from one contributor, giving the project a thin active contributor base. Organization backing partly compensates, but not enough to remove the maintenance risk.
The repository name does not match the package and its README does not mention the package, so the package-to-source relationship is not clearly demonstrated despite the monorepo containing a similarly named documentation path.
No security policy is present in the repository. This is a transparency and vulnerability-reporting gap, though it is not evidence of unsafe code by itself.
Both workflows were analyzed with no dangerous sinks or audit findings, but 4 of 5 action references are unpinned and one workflow grants top-level write access. These are workflow hygiene concerns rather than a severe risk because no untrusted checkout or injection path was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nanoid Version ^6.0.0 | — | — |
express Version ^5.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.