Easy as cake e-mail sending from your Node.js applications
88%
Total Score
healthy
Active releases, eight recent contributors, and strong package documentation outweigh workflow pinning and permission gaps.
A prepare install lifecycle script is present, adding some installation-time execution surface, although the repository-backed build context provides useful transparency.
The project uses TypeScript and npm build tooling, but no security-scanning tools were detected; the repository's security policy partly compensates for that tooling gap.
All three workflows were analyzed without untrusted checkouts or script injection, but all 11 action references are unpinned and two workflows grant top-level write permissions. The reported cache-poisoning finding has low confidence, so it is only a hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-804227 New nodemailer is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.0.0 - 10.0.12. | 3.0.0 - 10.0.12 | Medium |
AIKIDO-2026-306294 New nodemailer is vulnerable to Improper Input Validation in versions 3.0.0 - 10.0.12. | 3.0.0 - 10.0.12 | Medium |
AIKIDO-2026-284931 New nodemailer is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 10.0.9. | 0.0.1 - 10.0.9 | Medium |
AIKIDO-2026-810392 New nodemailer is vulnerable to Denial of Service (DoS) in versions 3.0.0 - 10.0.9. | 3.0.0 - 10.0.9 | Medium |
AIKIDO-2026-612508 nodemailer is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.0.0 - 10.0.5. | 3.0.0 - 10.0.5 | High |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.