Its long release history, recent releases, and active organization-backed development support continued maintenance. The workflow audit still finds every action reference unpinned and a high-confidence unpinned container image, so pinning is prudent.
70%
Total Score
100
88
83
The linked repository name does not match sanitize-html and its README does not mention the package, creating a material risk that the source link is not the package's actual project.
No type declarations are published. This is a small integration concern for TypeScript consumers, though it does not indicate abandonment by itself.
Both workflows were analyzed completely and have no untrusted checkout or script-injection findings, but all 17 action references are unpinned and the audit reports a high-confidence unpinned container image. The template-injection findings are lower-confidence hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63670 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.17.5. | 0.0.0 - 2.17.5 | Medium |
CVE-2026-84371 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.9.0 - 2.17.6. | 1.9.0 - 2.17.6 | Medium |
CVE-2026-53606 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.18.0 - 2.17.4. | 1.18.0 - 2.17.4 | Medium |
CVE-2026-44990 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.17.3 - 2.17.3. | 2.17.3 - 2.17.3 | Critical |
CVE-2026-40186 sanitize-html is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 2.17.2 - 2.17.3. | 2.17.2 - 2.17.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
launder Version ^1.7.1 | — | — |
postcss Version ^8.3.11 | — | — |
deepmerge Version ^4.2.2 | — | — |
htmlparser2 Version ^12.0.0 | — | — |
parse-srcset Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.