@nx/cypress 23.2.1 appears to be a very healthy dependency: it is actively released, not deprecated, backed by an organization-owned repository that was pushed recently, and supported by substantial commit, issue, and contributor activity. The package is MIT-licensed, includes type declarations, has npm provenance attestation, avoids install-time lifecycle scripts, and the repository uses build and security tooling with no analyzed dangerous workflow patterns. The main transparency concern is that the linked Nx monorepo does not match the package name or mention it in its README, although the @nx namespace and organization backing make a monorepo subpackage explanation plausible; workflow permission declarations also have some hygiene gaps. Overall, the evidence supports adoption with low maintenance and abandonment risk.
94%
Total Score
100
100
95
90
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
@nx/js Version 23.2.1 | — | — |
semver Version ^7.6.3 | — | — |
tree-kill Version ^1.2.2 | — | — |
@nx/devkit Version 23.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.