The eslint-plugin package is an ESLint plugin that contains a collection of recommended ESLint rule configurations which you can extend from in your own ESLint configs, as well as an Nx-specific lint rule called enforce-module-boundaries.
88%
Total Score
healthy
Active Nx maintenance and reproducible publishing outweigh workflow hygiene findings and one external publish account.
Four of five publish-access accounts use the nrwl.io domain, consistent with organization ownership. The outside-domain account jameshenry (henry.sc) is an account-hygiene caution, but it does not indicate limited maintenance capacity.
The repository name differs from the package name, which is normal for an Nx monorepo, but the README does not mention @nx/eslint-plugin; that weakens direct ownership transparency.
All 13 workflows were analyzed with no untrusted checkouts or script-injection findings, and all 81 action references are pinned. However, high-confidence adhoc package installs, one top-level write workflow, and high-confidence template-injection findings remain workflow hygiene concerns; the absence of dangerous trigger sinks limits their impact.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
@nx/js Version 23.3.0 | — | — |
semver Version ^7.6.3 | — | — |
globals Version ^17.0.0 | — | — |
@nx/devkit Version 23.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.