Package Health

@next/env

Next.js dotenv file loading

Latest 16.4.0NPMNPM

91%

Total Score

healthy

Active, well-backed package with strong release activity; workflow secret inheritance and repository package ambiguity are the main cautions.

Health Score Breakdown

Repo package mentioncaution

The repository name does not match @next/env and its README does not mention the package, creating some ambiguity about package-to-repository mapping. The organization-owned Next.js monorepo context partly explains the mismatch but does not remove it.

Workflow auditcaution

All 29 workflows were analyzed with no untrusted checkouts or script-injection findings, and only one of 134 action references is unpinned. However, high-confidence secrets-inherit findings and several top-level write permissions create a real workflow-hygiene caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
5 days ago
Created
6 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform