A custom mux video element for the browser that Just Works™
84%
Total Score
healthy
Active releases, organization backing, and repository activity outweigh workflow pinning and security-policy gaps.
Three of four publishing accounts use the mux.com domain, consistent with organization ownership; the gmail.com account dylanjha is a minor account-hygiene caution, not evidence of limited maintenance capacity.
The repository has no security policy, leaving vulnerability-reporting expectations and disclosure handling unclear.
This release is not a prerelease, although 75% of recent versions were prereleases; that reduces confidence in broad version stability but does not make this specific release unfit.
All 17 action references are unpinned, which weakens build reproducibility. The auditor also reported a low-confidence high-severity cache-poisoning pattern in cd.yml; its low confidence makes this a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
media-tracks Version ~0.3.5 | — | — |
castable-video Version ~1.1.16 | — | — |
@mux/playback-core Version 0.36.0 | — | — |
custom-media-element Version ~1.4.6 | — | — |
@mux/mux-data-google-ima Version ^0.3.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.