The package is straightforward to integrate and has a clear support trail. Single-owner concentration, no security policy, and unpinned workflow actions warrant routine caution.
88%
Total Score
75
100
100
75
Three contributors were active, but the leading contributor made about 77% of recent commits. The secondary contributor supplied 20%, which partly offsets but does not remove concentration risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent despite the presence of automated security scanning.
The single workflow was fully analyzed with no audit findings or untrusted execution sinks, but all four action references are unpinned, weakening build reproducibility and update control.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-349873 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. HtmlSanitizer is vulnerable to Cross-Site Scripting (XSS) in versions 4.0.210 - 9.2.995. | 4.0.210 - 9.2.995 | Medium |
AIKIDO-2026-667119 HtmlSanitizer is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 9.0.892. | 0.0.1 - 9.0.892 | High |
CVE-2026-25543 HtmlSanitizer is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 9.0.892 and 9.1.878-beta - 9.1.893-beta. | 0.0.0 - 9.0.8929.1.878-beta - 9.1.893-beta | Medium |
CVE-2023-44390 HtmlSanitizer is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 8.0.723 and 8.1.0-beta - 8.1.722-beta. | 0.0.0 - 8.0.7238.1.0-beta - 8.1.722-beta | Medium |
CVE-2020-26293 HtmlSanitizer is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 5.0.372. | 0.0.0 - 5.0.372 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
anglesharp Version [1.7.2, ) | — | — |
anglesharp.css Version [1.0.2, ) | — | — |
system.collections.immutable Version [10.0.11, ) | — | — |
system.valuetuple Version [4.6.2, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.