The Nx Devkit is used to customize Nx for different technologies and use cases. It contains many utility functions for reading and writing files, updating configuration, working with Abstract Syntax Trees(ASTs), and more. Learn more about [extending Nx by
42%
Total Score
unhealthy
Risky: the package is explicitly renamed and has had no registry release in over a year.
The README explicitly says @nrwl/devkit was renamed to @nx/devkit and will no longer be published, making this release a poor forward-looking dependency despite repository tests and changelog support.
The registry does not mark the package deprecated, which avoids an automatic withdrawal signal, but the package README provides a stronger replacement warning than the registry metadata.
The package has 1,335 releases over nearly six years, but none in the last 12 months; the long recent pause is consistent with the stated transition away from this package.
The repository name does not match the package and its README does not mention @nrwl/devkit, so package ownership is less directly transparent; the organization backing and package README partly compensate.
All 13 workflows were analyzed, all 81 action references are pinned, and no untrusted checkout or script-injection trigger was found; high-confidence template-injection and adhoc-package findings remain workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@nx/devkit Version 19.8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.