mjml-divider
88%
Total Score
100
100
90
80
50
No build provenance attestation or trusted publisher identity is available, reducing release transparency and making artifact origin harder to independently verify.
The repository name does not match mjml-divider and its README does not mention the package, creating some linkage ambiguity. However, the repository is an organization-owned monorepo whose file tree visibly contains many component packages, which partly compensates for the mismatch.
The repository uses Babel and npm build tooling, but no security scanning tools were detected. The build setup is established, while security-tooling coverage remains a gap.
No repository security policy was found, which weakens vulnerability-reporting transparency and incident-response expectations.
All 3 workflows lack top-level token permissions declarations, and none has read-only permissions reported. Although no top-level write permissions were detected, explicit least-privilege policy is not consistently documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
mjml-core Version 5.4.1 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.