MJML: the only framework that makes responsive-email easy
88%
Total Score
100
100
95
80
50
The release has no build attestation, trusted publisher identity, or staged publishing, leaving provenance less transparent and warranting caution.
The repository uses Babel and npm build tooling, but no security-scanning tools were detected; the missing scanning is a modest hardening gap.
No repository security policy was found, reducing vulnerability-reporting transparency and leaving a genuine governance gap.
All three workflows lack top-level permissions declarations and none declares read-only permissions, so least-privilege intent is not explicit even though no top-level write permissions were observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
glob Version ^13.0.6 | — | — |
yargs Version ^17.7.2 | — | — |
lodash Version ^4.17.21 | — | — |
chokidar Version ^4.0.3 | — | — |
minimatch Version ^10.2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.