A tool to migrate a template from MJML 3 to MJML 4
72%
Total Score
100
50
90
67
50
No build attestation or trusted-publisher provenance is present, leaving publication origin less independently verifiable despite the package's active project signals.
Six runtime dependencies are reasonable for this tool, though the dependency surface creates some transitive maintenance exposure.
The repository name does not match mjml-migrate and its README does not mention the package. This can be normal for a monorepo subpackage, but the lack of an explicit mention weakens package-to-repository transparency.
The project uses Babel and npm scripts, but no security-scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yargs Version ^17.7.2 | — | — |
lodash Version ^4.17.21 | — | — |
mjml-core Version 4.18.0 | — | — |
js-beautify Version ^1.6.14 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.