`@next/third-parties` is a collection of components and utilities that can be used to efficiently load third-party libraries into your Next.js application.
82%
Total Score
healthy
Active, well-backed release with strong provenance, but package ownership is indirect and workflow hygiene needs attention.
The linked repository name does not match the package and its README does not mention @next/third-parties; although a monorepo mismatch can be normal, this weakens direct ownership transparency.
Version 16.4.0 is a stable major release and not a prerelease, although 80% of recent releases being prereleases indicates an experimental development stream.
All 29 workflows were analyzed with no untrusted checkouts or script injections, but high-confidence template-injection findings and repeated secrets-inherit findings indicate workflow hygiene concerns; the single unpinned action is a minor additional gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
third-party-capital Version 1.0.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.