Package Health

@nx/cypress

@nx/cypress 23.2.1 appears to be a very healthy dependency: it is actively released, not deprecated, backed by an organization-owned repository that was pushed recently, and supported by substantial commit, issue, and contributor activity. The package is MIT-licensed, includes type declarations, has npm provenance attestation, avoids install-time lifecycle scripts, and the repository uses build and security tooling with no analyzed dangerous workflow patterns. The main transparency concern is that the linked Nx monorepo does not match the package name or mention it in its README, although the @nx namespace and organization backing make a monorepo subpackage explanation plausible; workflow permission declarations also have some hygiene gaps. Overall, the evidence supports adoption with low maintenance and abandonment risk.

Latest 23.2.1NPMNPM

94%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

95

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
tslib
Version ^2.3.0
@nx/js
Version 23.2.1
semver
Version ^7.6.3
tree-kill
Version ^1.2.2
@nx/devkit
Version 23.2.1

Weekly Downloads

Info

Last Published
6 days ago
Created
3 years ago
Unpacked Size
0.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform