mjml-atable
86%
Total Score
100
100
90
80
50
No build attestation, trusted publisher identity, or staged publishing is present. This reduces release transparency and reproducibility, though it is a caution rather than a health verdict by itself.
The repository name does not match mjml-table and its README does not mention the package, which creates some uncertainty about package-to-repository linkage. However, the repository is a large MJML monorepo containing the package's broader project structure, so this is a caution rather than a severe mismatch.
The repository uses Babel and npm build tooling, but no security scanning tools were detected. The established build process is positive, while the missing scanning capability is a transparency and hygiene gap.
No repository security policy was found. This weakens vulnerability-reporting transparency, but active maintenance and other repository controls partially compensate.
All three workflows lack top-level token-permission declarations, and none declares read-only permissions at the top level. This leaves workflow privilege boundaries less explicit and is a genuine CI security-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
mjml-core Version 5.4.1 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.