mjml-button 5.4.1 appears to be a healthy, actively maintained monorepo component: it has 154 releases over more than 10 years, 25 releases in the last 12 months, a current non-deprecated stable version, an unarchived organization-owned repository, recent commits from six maintainers, and substantial repository activity. The package is MIT licensed and its small four-file artifact is consistent with a built component; missing packaged tests are compensated by repository tests. The main concerns are absent build provenance attestations, security scanning and security policy, incomplete explicit workflow token permissions, and the repository not naming or mentioning this subpackage directly, although the repository tree clearly contains the mjml-button package and the monorepo structure explains that mismatch.
87%
Total Score
100
100
95
80
50
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
mjml-core Version 5.4.1 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.