Package Health

starcitizenwiki/embedvideo

This release appears healthy and suitable to depend on: it is a stable 4.2.0 release from a package with a long history, recent publication, an unarchived organization-owned repository, active recent commits from three contributors, ongoing pull-request activity, tests, changelog documentation, build tooling, and Dependabot scanning. The main reservations are a relatively small project and contributor base, only two releases in the last 12 months, no repository security policy, and workflows that do not declare top-level token permissions; these are transparency and hardening gaps rather than evidence of abandonment. No prior malware scan result was available, but that is outside this health assessment.

Latest 4.2.0PackagistPackagist

86%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Are you affected? Scan for Free

Health Score Breakdown

Release historycaution

The package has existed for about 5 years and 3 months with 28 releases, and its latest release is current, but only 2 releases occurred in the last 12 months; this suggests a mature but not rapidly releasing project.

Security policycaution

No SECURITY policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.

Token permissionscaution

Both analyzed workflows lack top-level token-permission declarations. No workflow requests top-level write access, but explicit least-privilege permissions would provide stronger CI hardening.

Vulnerabilities

TitleVersionsSeverity
CVE-2026-55692
starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0.
0.0.0 - 4.0.0
High
CVE-2026-55691
starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0.
0.0.0 - 4.0.0
High
CVE-2026-55690
starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0.
0.0.0 - 4.0.0
High
CVE-2025-59839
starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0.
0.0.0 - 4.0.0
High

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version >=1.0.1

Weekly Downloads

Info

Last Published
15 days ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform