The Node Plugin for Nx contains generators to manage Node applications within an Nx workspace.
91%
Total Score
healthy
Active releases and a heavily maintained monorepo support this package, with minor workflow and publishing-account hygiene concerns.
Four of five publishing accounts use the organization domain, consistent with the organization-backed project. jameshenry (henry.sc) is an outside-domain publishing account, a minor account-hygiene concern rather than evidence of limited maintenance capacity.
The repository name does not match @nx/node and its README does not mention the package. The mismatch is explainable by the Nx monorepo, but the lack of a README mention leaves a small package-to-repository transparency gap.
All 13 workflows were analyzed with no failed files, no untrusted checkouts, no script injection, and all 81 action references pinned. High-confidence template-injection findings and low-confidence cache findings are present, but no dangerous trigger was reported; they remain workflow hygiene concerns rather than standalone severe risk.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
@nx/js Version 23.3.0 | — | — |
semver Version ^7.6.3 | — | — |
@nx/jest Version 23.3.0 | — | — |
kill-port Version ^1.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.