mjml-navbar
88%
Total Score
100
100
90
80
50
No build attestation or trusted-publisher provenance is available, leaving release origin and reproducibility less transparent. This is a genuine supply-chain hygiene gap, but not evidence of an unhealthy project by itself.
The repository name does not match mjml-navbar and its README does not mention the package, which creates some uncertainty that the repository is the package's actual source. However, the repository tree clearly contains multiple MJML component packages, so the mismatch is plausibly explained by monorepo organization.
The repository uses Babel and npm scripts for builds, but no security-scanning tools were detected. The missing security automation is a moderate hygiene gap, partially offset by the mature build setup.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures. This is a caution rather than a severe risk because other maintenance signals are strong.
All three workflows lack top-level permissions declarations, and none explicitly declares read-only permissions. Although no workflow has top-level write permissions and one has job-level permissions, explicit least-privilege configuration would be preferable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
mjml-core Version 5.4.1 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.