Multi-account email management with WhatsApp messaging, smart routing, failover, and analytics for Strapi v5
78%
Total Score
75
50
94
67
100
Seventeen runtime dependencies support a feature-rich email and messaging plugin, but the relatively broad dependency surface adds maintenance and update exposure.
Two contributors were active, but the main contributor made 82.8% of commits. Because the repository is user-owned rather than organization-owned, this concentration leaves meaningful continuity risk.
The project uses npm scripts and esbuild, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a plugin handling email credentials and integrations.
The repository has no security policy. For a plugin handling email accounts, OAuth, and messaging credentials, the lack of a documented vulnerability-reporting path is a real hygiene gap.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, and it scopes permissions at job level. However, both action references are unpinned and the audit found a high-confidence low-severity ad hoc package installation, weakening build reproducibility.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10628 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. strapi-plugin-magic-mail is vulnerable to Authorization Bypass in versions 1.0.0 - 2.9.0. | 1.0.0 - 2.9.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
yup Version ^1.7.1 | — | — |
zod Version ^4.4.3 | — | — |
pino Version ^10.3.1 | — | — |
qrcode Version ^1.5.4 | — | — |
baileys Version ^7.0.0-rc13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.