The React plugin for Nx contains executors and generators for managing React applications and libraries within an Nx workspace. It provides: - Integration with libraries such as Jest, Vitest, Playwright, Cypress, and Storybook. - Generators for applica
88%
Total Score
healthy
Active project with strong release and build practices, but workflow audit flags template injection and ad hoc package installs.
Four of five publishing accounts use the organization domain, consistent with the organization-backed project. jameshenry (henry.sc) is an outside-domain publishing account, a minor account-hygiene caution rather than evidence of weak maintenance capacity.
The repository name does not match @nx/react and its README does not mention the package, so the package-to-repository association is less transparent. The organization-backed monorepo context partly mitigates this concern, but does not remove it.
All 13 workflows were analyzed and all 81 action references are pinned, with no untrusted checkouts or script-injection triggers. However, high-confidence template-injection findings and high-confidence ad hoc package installs remain workflow hygiene concerns; the low-confidence cache findings carry little weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
@nx/js Version 23.3.0 | — | — |
semver Version ^7.6.3 | — | — |
@nx/web Version 23.3.0 | — | — |
minimatch Version 10.2.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.