Next.js dotenv file loading
91%
Total Score
healthy
Active, well-backed package with strong release activity; workflow secret inheritance and repository package ambiguity are the main cautions.
The repository name does not match @next/env and its README does not mention the package, creating some ambiguity about package-to-repository mapping. The organization-owned Next.js monorepo context partly explains the mismatch but does not remove it.
All 29 workflows were analyzed with no untrusted checkouts or script-injection findings, and only one of 134 action references is unpinned. However, high-confidence secrets-inherit findings and several top-level write permissions create a real workflow-hygiene caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.