mjml-wrapper
88%
Total Score
100
100
90
80
50
No build attestation, trusted publisher identity, or staged publishing is reported, leaving release-to-source provenance less transparent.
The repository name does not match the package name and its README does not mention the package, which creates a provenance and package-association ambiguity. The monorepo structure makes a name mismatch ordinary, but the absence of a README mention remains a genuine caution.
The repository uses Babel and npm build tooling, but no security scanning tools are reported, leaving a modest security-hygiene gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.
All three workflows lack top-level permissions declarations and none declares read-only permissions, which weakens least-privilege clarity even though no top-level write permissions were detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lodash Version ^4.17.21 | — | — |
mjml-core Version 5.4.1 | — | — |
mjml-section Version 5.4.1 | — | — |
@babel/runtime Version ^7.28.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.