The JS plugin for Nx contains executors and generators that provide the best experience for developing JavaScript and TypeScript projects.
36%
Total Score
unhealthy
Risky: @nrwl/js is replaced by @nx/js and has had no releases in the last 12 months.
The package includes a README, but it explicitly says @nrwl/js was renamed to @nx/js and will no longer be published. Repository tests and changelog evidence show the underlying project remains maintained, but they do not restore this package name's future support.
The package has 1,072 releases overall but none in the last 12 months; its latest release was over a year ago, indicating that this package line is no longer being maintained for new consumers.
The linked repository does not match the package name and does not mention it in the README, which weakens package-to-source traceability. The organization-owned Nx monorepo provides some context for the mismatch, but not for the package's stated replacement.
All 13 workflows were analyzed, actions are fully pinned, and no untrusted checkout or script-injection trigger was found. High-confidence template-injection and ad hoc package-install findings remain workflow hygiene concerns, but the audit provides no evidence of a severe release risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@nx/js Version 19.8.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.