Package Health

react-email

A live preview of your emails right in your browser.

Latest 6.11.1NPMNPM

58%

Total Score

caution

Strong maintenance and provenance are offset by a suspicious name similarity and a high-confidence workflow audit finding.

Are you affected? Scan for Free

Health Score Breakdown

Name lookalikedanger

The package is reported to borrow the identity of react-is, with borrows_lookalike_identity true, despite zero artifact overlap; this is a serious adoption risk because consumers may have intended the established package.

Repo toolingcaution

The repository uses established build and test tooling, including TypeScript and Vitest, but no security-scanning tools were detected; the missing scanning is a minor hygiene gap.

Workflow auditcaution

All 11 workflows were analyzed with no untrusted checkout or script-injection paths, but a high-confidence template-injection finding remains in sync-skills.yml; trusted publishing was also flagged, though informational.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-310596 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
react-email is vulnerable to Cross-Site Scripting (XSS) in versions 6.0.0 - 6.6.6.
6.0.0 - 6.6.6
Medium

Package versions

Direct Dependencies

DependencyLast ReleaseScore
conf
Version ^15.0.2
—
—
glob
Version ^13.0.6
—
—
jiti
Version 2.6.1
—
—
nypm
Version 0.6.6
—
—
marked
Version ^15.0.12
—
—

Weekly Downloads

Info

Last Published
4 days ago
Created
10 years ago
Unpacked Size
3.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform