IMAP Client for Node
88%
Total Score
healthy
Frequent releases and active contributors support health; all 15 workflow actions are unpinned and the license metadata conflicts.
The package declares MIT and includes license files in both the artifact and repository, but the detected artifact license is MIT-0, creating a metadata mismatch that warrants clarification.
A prepare lifecycle script runs during installation, adding execution during package setup; this is a modest supply-chain hygiene concern without evidence here of harmful behavior.
The project uses TypeScript and npm build tooling, but no security scanning tools were detected; this is a minor transparency and hygiene gap.
All 3 workflows were analyzed with no reported findings or untrusted execution paths, but all 15 action references are unpinned and 2 workflows grant top-level write permissions, creating workflow hardening concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-861989 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. imapflow is vulnerable to STARTTLS Response Injection in versions 1.0.0 - 1.3.5. | 1.0.0 - 1.3.5 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
pino Version 10.3.1 | — | — |
libqp Version 2.1.2 | — | — |
socks Version 2.8.10 | — | — |
libmime Version 5.4.7 | — | — |
libbase64 Version 1.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.