Package Health

strapi-plugin-magic-mail

Multi-account email management with WhatsApp messaging, smart routing, failover, and analytics for Strapi v5

Latest 3.0.4NPMNPM

78%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

75

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

100

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

Seventeen runtime dependencies support a feature-rich email and messaging plugin, but the relatively broad dependency surface adds maintenance and update exposure.

Repo bus factorcaution

Two contributors were active, but the main contributor made 82.8% of commits. Because the repository is user-owned rather than organization-owned, this concentration leaves meaningful continuity risk.

Repo toolingcaution

The project uses npm scripts and esbuild, but no security-scanning tools were detected. That is a modest transparency and maintenance gap for a plugin handling email credentials and integrations.

Security policycaution

The repository has no security policy. For a plugin handling email accounts, OAuth, and messaging credentials, the lack of a documented vulnerability-reporting path is a real hygiene gap.

Workflow auditcaution

The single workflow was fully analyzed with no untrusted checkout or script-injection findings, and it scopes permissions at job level. However, both action references are unpinned and the audit found a high-confidence low-severity ad hoc package installation, weakening build reproducibility.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10628 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
strapi-plugin-magic-mail is vulnerable to Authorization Bypass in versions 1.0.0 - 2.9.0.
1.0.0 - 2.9.0
High

Package versions

Maintainers

Direct Dependencies

DependencyLast ReleaseScore
yup
Version ^1.7.1
—
—
zod
Version ^4.4.3
—
—
pino
Version ^10.3.1
—
—
qrcode
Version ^1.5.4
—
—
baileys
Version ^7.0.0-rc13
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
10 months ago
Unpacked Size
8.3 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform