The repository is active, backed by an organization, and has recent releases, tests, and three active contributors. GitHub workflows use unpinned actions and contain high-confidence template-injection findings, while no security policy is published.
48%
Total Score
100
86
67
The package is deprecated at the registry level and explicitly replaced by altis/media. This materially raises adoption risk even though the source repository remains active.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent for a package with multiple runtime dependencies.
All seven analyzed action references are unpinned, and two high-confidence template-injection findings affect release workflows; a low-confidence-style hygiene concern is not needed because the reported findings are high confidence. No untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
darylldoyle/safe-svg Version 2.5.0 | — | — |
humanmade/smart-media Version ~0.5.12 | — | — |
humanmade/amf-wordpress Version ^0.3.1 | — | — |
humanmade/tachyon-plugin Version ~0.11.10 | — | — |
humanmade/aws-rekognition Version ~0.1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.