Package Health

humanmade/media

The repository is active, backed by an organization, and has recent releases, tests, and three active contributors. GitHub workflows use unpinned actions and contain high-confidence template-injection findings, while no security policy is published.

Latest 28.0.3PackagistPackagist

48%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

86

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Registry deprecationdanger

The package is deprecated at the registry level and explicitly replaced by altis/media. This materially raises adoption risk even though the source repository remains active.

Security policycaution

The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent for a package with multiple runtime dependencies.

Workflow auditcaution

All seven analyzed action references are unpinned, and two high-confidence template-injection findings affect release workflows; a low-confidence-style hygiene concern is not needed because the reported findings are high confidence. No untrusted checkout or script injection was found.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Human Made

Direct Dependencies

DependencyLast ReleaseScore
darylldoyle/safe-svg
Version 2.5.0
—
—
humanmade/smart-media
Version ~0.5.12
—
—
humanmade/amf-wordpress
Version ^0.3.1
—
—
humanmade/tachyon-plugin
Version ~0.11.10
—
—
humanmade/aws-rekognition
Version ~0.1.10
—
—

Weekly Downloads

Info

Last Published
3 days ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform