The Nx Plugin for Module Federation contains executors and utilities that support building applications using Module Federation.
84%
Total Score
healthy
Active project with verified publishing, but workflow hygiene and weak package-to-repository naming transparency merit caution.
Four of five publishing accounts use the organization domain, consistent with organization backing. The outside-domain account jameshenry (henry.sc) is an account-hygiene caution, not evidence of limited maintenance capacity.
The repository name does not match the package name and its README does not mention @nx/module-federation. A monorepo explains the name mismatch, but the lack of an explicit package mention weakens package-to-repository transparency.
All 13 workflows were analyzed with no untrusted checkouts or script-injection findings, and all 81 action references are pinned. High-confidence template-injection findings and high-confidence ad hoc package installs remain workflow-hygiene concerns, while low-confidence cache findings are not independently decisive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
@nx/js Version 23.3.0 | — | — |
@nx/web Version 23.3.0 | — | — |
express Version ^4.21.2 | — | — |
@nx/devkit Version 23.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.