mjml-head-preview
88%
Total Score
100
100
89
67
50
No build attestation or trusted-publisher provenance is available, leaving the relationship between source and published artifact less transparent.
The repository name does not match the package name and its README does not mention mjml-head-preview, creating some uncertainty that this repository directly represents the package; the monorepo structure and organization backing partially mitigate that concern.
The repository uses Babel and npm build tooling, but has no detected security-scanning tools; the missing scanning reduces security-process transparency without indicating abandonment.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
All three workflows lack top-level permissions declarations, and none declares read-only permissions; although no top-level write permissions or dangerous workflow patterns were observed, this is a workflow-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
mjml-core Version 5.4.1 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.