This release appears healthy and suitable to depend on: it is a stable 4.2.0 release from a package with a long history, recent publication, an unarchived organization-owned repository, active recent commits from three contributors, ongoing pull-request activity, tests, changelog documentation, build tooling, and Dependabot scanning. The main reservations are a relatively small project and contributor base, only two releases in the last 12 months, no repository security policy, and workflows that do not declare top-level token permissions; these are transparency and hardening gaps rather than evidence of abandonment. No prior malware scan result was available, but that is outside this health assessment.
86%
Total Score
100
100
94
80
The package has existed for about 5 years and 3 months with 28 releases, and its latest release is current, but only 2 releases occurred in the last 12 months; this suggests a mature but not rapidly releasing project.
No SECURITY policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.
Both analyzed workflows lack top-level token-permission declarations. No workflow requests top-level write access, but explicit least-privilege permissions would provide stronger CI hardening.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-55692 starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0. | 0.0.0 - 4.0.0 | High |
CVE-2026-55691 starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0. | 0.0.0 - 4.0.0 | High |
CVE-2026-55690 starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0. | 0.0.0 - 4.0.0 | High |
CVE-2025-59839 starcitizenwiki/embedvideo is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.0.0. | 0.0.0 - 4.0.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version >=1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.