Package Health

darylldoyle/safe-svg

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website

Latest 2.5.1PackagistPackagist

78%

Total Score

healthy

Healthy release with active maintenance and a documented security update, despite workflow hygiene concerns.

Are you affected? Scan for Free

Health Score Breakdown

Workflow auditcaution

All 11 workflows were analyzed, with no untrusted checkouts or script-injection findings. However, a high-confidence template-injection finding in cypress.yml, a high-confidence archived-action finding, four workflows with top-level write permissions, and one unpinned action create moderate workflow hygiene risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2022-1091
darylldoyle/safe-svg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.9.10.
0.0.0 - 1.9.10
Medium

Package versions

Maintainers

10up
Daryll Doyle

Direct Dependencies

DependencyLast ReleaseScore
enshrined/svg-sanitize
Version ^1.0.0
—
—

Weekly Downloads

Info

Last Published
14 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform