Package Health

imapflow

IMAP Client for Node

Latest 2.2.10NPMNPM

88%

Total Score

healthy

Frequent releases and active contributors support health; all 15 workflow actions are unpinned and the license metadata conflicts.

Are you affected? Scan for Free

Health Score Breakdown

Licensecaution

The package declares MIT and includes license files in both the artifact and repository, but the detected artifact license is MIT-0, creating a metadata mismatch that warrants clarification.

Lifecycle scriptscaution

A prepare lifecycle script runs during installation, adding execution during package setup; this is a modest supply-chain hygiene concern without evidence here of harmful behavior.

Repo toolingcaution

The project uses TypeScript and npm build tooling, but no security scanning tools were detected; this is a minor transparency and hygiene gap.

Workflow auditcaution

All 3 workflows were analyzed with no reported findings or untrusted execution paths, but all 15 action references are unpinned and 2 workflows grant top-level write permissions, creating workflow hardening concerns.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-861989 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
imapflow is vulnerable to STARTTLS Response Injection in versions 1.0.0 - 1.3.5.
1.0.0 - 1.3.5
Medium

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
pino
Version 10.3.1
—
—
libqp
Version 2.1.2
—
—
socks
Version 2.8.10
—
—
libmime
Version 5.4.7
—
—
libbase64
Version 1.3.2
—
—

Weekly Downloads

Info

Last Published
10 hours ago
Created
6 years ago
Unpacked Size
1.7 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform