Package Health

mjml-navbar

mjml-navbar

Latest 5.4.1NPMNPM

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Health Score Breakdown

Build provenancecaution

No build attestation or trusted-publisher provenance is available, leaving release origin and reproducibility less transparent. This is a genuine supply-chain hygiene gap, but not evidence of an unhealthy project by itself.

Repo package mentioncaution

The repository name does not match mjml-navbar and its README does not mention the package, which creates some uncertainty that the repository is the package's actual source. However, the repository tree clearly contains multiple MJML component packages, so the mismatch is plausibly explained by monorepo organization.

Repo toolingcaution

The repository uses Babel and npm scripts for builds, but no security-scanning tools were detected. The missing security automation is a moderate hygiene gap, partially offset by the mature build setup.

Security policycaution

No repository security policy was found, reducing transparency about vulnerability reporting and response procedures. This is a caution rather than a severe risk because other maintenance signals are strong.

Token permissionscaution

All three workflows lack top-level permissions declarations, and none explicitly declares read-only permissions. Although no workflow has top-level write permissions and one has job-level permissions, explicit least-privilege configuration would be preferable.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
lodash
Version ^4.17.21
—
—
mjml-core
Version 5.4.1
—
—
@babel/runtime
Version ^7.28.4
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
10 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform