An open source Mux player web component that Just Works™
88%
Total Score
healthy
Frequent releases and active organization-backed maintenance outweigh minor workflow and security-documentation gaps.
Three of four publishing accounts use the organization domain mux.com, which fits the organization-backed project. One consumer-domain account, dylanjha (gmail.com), is a minor account-hygiene caution rather than evidence of weak maintenance capacity.
The repository has no SECURITY.md policy. This is a transparency gap for vulnerability reporting, though it does not by itself show abandonment or unsafe code.
All three workflows were analyzed with no untrusted checkouts or script injection, and two scope permissions at job level. However, all 17 action references are unpinned, and the auditor reported a low-confidence cache-poisoning finding; these are workflow-hygiene cautions, not severe evidence on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
media-chrome Version ~4.19.3 | — | — |
player.style Version ^0.3.0 | — | — |
@mux/mux-video Version 0.31.5 | — | — |
@mux/playback-core Version 0.36.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.