94OUT OF 100
TrustedHigh trustStatic read

npm/nanoid

Nano ID is a widely used, industry-standard utility for generating unique string IDs. The static analysis of the published npm artifact shows no malicious behavior, no install-time network activity, and no obfuscation. The package is highly reputable, maintained by a well-known engineering consultancy, and has a massive, verifiable user base. No malicious behavior observed in our static read; full runtime behavior was not executed in a sandbox on this pass.

Repository size
118 bytes
Packages
0
Stars
—
Created
2017-08-06
Reputation signals
npm avatar
nanoid
npm package
Code & behavior signals
No risky items found

No signatures, install hooks, obfuscation, or embedded secrets were found in the code.

Per-package scoring
Final verdict

No malicious behavior in our static read, and reputation is strong. Runtime was not executed in a sandbox on this pass, so this is a static-read clearance, not a guarantee.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Fetched npm artifact nanoid@6.0.1
›Verified tarball integrity via sha512
Static scan
›No flagged regions detected
›No install hooks found in package.json
›No obfuscation or credential access patterns
Reputation
›Package established since 2017
›High download volume confirms community trust
Read
›README intent matches library functionality
›No undisclosed behavior found
Score
›Score computed by formula: 94/100 (deterministic, code-driven)
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+4 [reputation] good_sentiment: Positive community sentiment (100/100).
Auto-published at clauderabbit.in/npm/nanoid · re-checked when the package changes