The package includes documentation, release notes, and a small runtime dependency footprint. Its workflow omits top-level token permissions, so CI hardening is less explicit.
82%
Total Score
100
100
94
83
The analyzed workflow has no top-level permissions declaration, making its GitHub Actions token access less explicit even though no write permissions were detected.
This assessed release is a prerelease while the latest available version is the stable v1.9.26, so adopters should expect beta-level compatibility risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-570364 james-heinrich/getid3 is vulnerable to OS Command Injection in versions 1.9.8 - 1.9.25. | 1.9.8 - 1.9.25 | High |
AIKIDO-2026-10343 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. james-heinrich/getid3 is vulnerable to XML External Entity (XXE) Attack in versions 1.9.22 - 1.9.24. | 1.9.22 - 1.9.24 | Low |
CVE-2014-2053 james-heinrich/getid3 is vulnerable to Improper Restriction of XML External Entity Reference in versions 0.0.0 - 1.9.9. | 0.0.0 - 1.9.9 | High |
CVE-2021-40926 james-heinrich/getid3 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.0 - 1.9.21. | 1.0.0 - 1.9.21 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.