ai/nanoid
59.6
Adequate · 25 September 2026
288
lines of production code
JavaScript
primary language
4
measurements over time
What this system is
NanoID is a library for generating unique, non-sequential identifiers, offering both secure and non-secure generation modes with support for custom alphabets and sizes. It provides a command-line interface for quick usage and includes an optimized URL-safe alphabet designed to improve compression efficiency. The system is built as a modern ESM package with comprehensive testing, benchmarking, and browser-based visualization tools to verify randomness and performance.
Features
Add CLI entry point with version, help, and generation options
A new executable CLI script (bin/nanoid.js) is introduced, allowing users to generate NanoIDs directly from the command line. The tool supports the --version and --help flags for metadata, and accepts -s/--size and -a/--alphabet arguments to customize the generated ID's length and character set, providing a convenient interface for quick ID generation without writing code.
bin · high confidence
Add non-secure ID generator with TypeScript support
Introduces a new non-secure random ID generator accessible via the 'nanoid/non-secure' entry point, designed for environments where hardware random generators are unavailable. This addition includes both the JavaScript implementation (index.js) and TypeScript definitions (index.d.ts), exposing the nanoid and customAlphabet functions with an optional size argument and generic type support for opaque ID types.
non-secure · high confidence
Behavioural changes
Nano ID v6.0.1 release with documentation fixes and dev environment updates
This release fixes documentation issues and updates the development environment. The core library code (index.browser.js, nanoid.js) remains unchanged from v6.0.0, but the README and its translations (Arabic, Indonesian, Japanese, Korean, Russian, Chinese) have been refreshed. The project has migrated its CI from Travis CI to GitHub Actions (indicated by the removal of .travis.yml and addition of .devcontainer.json) and switched its package manager from Yarn to pnpm (evidenced by the new pnpm-workspace.yaml and updated .npmignore). Additionally, the code formatting tooling has been updated to use oxfmt/oxlint instead of Prettier/ESLint, and the JSR package configuration (jsr.json) is now included.
(repo-wide) · high confidence
Optimized URL-safe alphabet for compression
The url-alphabet module now exports a character set ordered specifically to improve compression efficiency for both gzip and Brotli. By arranging the \A-Za-z0-9\_-\ symbols to leverage common references in gzip back-references (such as 'use', 'andom', 'rict') and Brotli default dictionary words (such as 'bush', 'jack', 'mind', 'very', 'wolf'), the output generated by this alphabet will result in smaller payload sizes when compressed.
url-alphabet · high confidence
Test coverage
Add browser demo page with benchmark and distribution visualization; Added comprehensive test suite and benchmarking infrastructure.
Dependencies
Major version upgrade to v6.0.1 with modernized tooling and ESM support
The project has been upgraded to version 6.0.1, shifting the package type to ESM ("type": "module") and updating the supported Node.js engines to ^22, ^24, or \>=26. The build and linting toolchain has been modernized by replacing ESLint and Jest with oxlint and better-node-test, and the lockfile has migrated from yarn.lock to pnpm-lock.yaml. Development dependencies have been updated to their latest versions, including Vite (^8.3.0), TypeScript (^7.0.2), and size-limit (^14.0.0), while the package size limit has been adjusted to reflect the new 127-byte target for the main nanoid export.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 44 → 60 (+16.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 62 → 66 (+4.1)
- Architecture 69 (new)
- Maturity 53 → 53 (-0.0)
- Readiness 26 → 61 (+35.2)
- Security 85 → 88 (+2.5)
Resolved (12)
- (anonymous) (cognitive 23) (index.js)
- Change coupling: index.browser.js ↔ index.js (index.browser.js)
- Change coupling: index.d.ts ↔ index.d.ts (index.d.ts)
- Change coupling: index.d.ts ↔ index.js (non-secure/index.d.ts)
- Change coupling: index.js ↔ index.d.ts (index.js)
- Dimension evaluation failed
- No automated tests
- No exposed public API
- No tests found
- Scanner failed to run — not a clean result
- Test reliability not included
- The 'Install' section lists JSR and CDN options but does not explain what JSR means or how to get the JAR. (./README.md)
New (62)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (the committed lockfile resolved no direct production dependency)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: index.js (index.js)
- No ADRs found
- No dependency advisory monitoring
- No direct assertions: accepts string (test/index.test.js)
- No direct assertions: accepts string (test/non-secure.test.js)
- No direct assertions: avoids pool pollution, infinite loop (test/index.test.js)
- No direct assertions: avoids pool pollution, infinite loop (test/index.test.js)
- No direct assertions: avoids pool pollution, infinite loop (test/non-secure.test.js)
- No direct assertions: avoids pool pollution, infinite loop (test/non-secure.test.js)
- No direct assertions: changes ID length (test/index.test.js)
- No direct assertions: changes ID length (test/non-secure.test.js)
- No direct assertions: changes size (test/index.test.js)
- No direct assertions: displays help (test/bin.test.js)
- No direct assertions: displays version (test/bin.test.js)
- No direct assertions: does not fall in infinite loop (test/index.test.js)
- No direct assertions: does not hang on negative size (customAlphabet) (test/non-secure.test.js)
- No direct assertions: does not hang on negative size (nanoid) (test/non-secure.test.js)
- …and 42 more
Changes since last survey
- 10 commits — 10 feature/other, 0 fixes
By area
- (root) — 8 commits
- .github/workflows — 1 commit
- test/non-secure.test.js — 1 commit
Notable commits
- change: Backport v3 changes
- change: Document the alphabet bounds instead of guarding them at runtime (#609)
- change: Reduce dependencies by moving to Rolldown instead of Webpack for Size Limit
- change: Stabilize tests
- change: Update Size Limit
- change: Update dependencies
- change: Update dependencies
- change: Update dependencies
- change: Use pnpm 12 on CI
- change: docs: fix custom generator JSDoc examples (#610)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ai/nanoid was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bb68abcd59ebb86a849d634320726add6be54d47 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.