
Security News
Risky Biz Podcast: Making Reachability Analysis Work in Real-World Codebases
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
hast-util-embedded
Advanced tools
hast utility to check if a node is embedded content.
This package is a small utility that checks if a node is embedded content according to HTML.
This utility is super niche, if you’re here you probably know what you’re looking for!
This package is ESM only. In Node.js (version 16+), install with npm:
npm install hast-util-embedded
In Deno with esm.sh
:
import {embedded} from 'https://esm.sh/hast-util-embedded@3'
In browsers with esm.sh
:
<script type="module">
import {embedded} from 'https://esm.sh/hast-util-embedded@3?bundle'
</script>
import {embedded} from 'hast-util-embedded'
// Given a non-embedded value:
embedded({
type: 'element',
tagName: 'a',
properties: {href: '#alpha', title: 'Bravo'},
children: [{type: 'text', value: 'Charlie'}]
}) // => false
// Given a embedded element:
embedded({
type: 'element',
tagName: 'audio',
properties: {src: 'delta.ogg'},
children: []
}) // => true
This package exports the identifier embedded
.
There is no default export.
embedded(value)
Check if node
is an embedded content.
value
(unknown
)
— thing to check (typically Node
)Whether value
is an element considered embedded content (boolean
).
The elements audio
, canvas
, embed
, iframe
, img
, math
,
object
, picture
, svg
, and video
are embedded content.
This package is fully typed with TypeScript. It exports no additional types.
Projects maintained by the unified collective are compatible with maintained versions of Node.js.
When we cut a new major release, we drop support for unmaintained versions of
Node.
This means we try to keep the current release line, hast-util-embedded@^3
,
compatible with Node.js 16.
hast-util-embedded
does not change the syntax tree so there are no openings
for cross-site scripting (XSS) attacks.
hast-util-is-element
— check if a node is a (certain) elementhast-util-has-property
— check if a node has a propertyhast-util-is-body-ok-link
— check if a node is “Body OK” link elementhast-util-is-conditional-comment
— check if a node is a conditional commenthast-util-is-css-link
— check if a node is a CSS link elementhast-util-is-css-style
— check if a node is a CSS style elementhast-util-heading
— check if a node is a heading elementhast-util-interactive
— check if a node is interactivehast-util-is-javascript
— check if a node is a JavaScript script elementhast-util-labelable
— check whether a node is labelablehast-util-phrasing
— check if a node is phrasing contenthast-util-script-supporting
— check if a node is a script-supporting elementhast-util-sectioning
— check if a node is a sectioning elementhast-util-transparent
— check if a node is a transparent elementhast-util-whitespace
— check if a node is inter-element whitespaceSee contributing.md
in syntax-tree/.github
for
ways to get started.
See support.md
for ways to get help.
This project has a code of conduct. By interacting with this repository, organization, or community you agree to abide by its terms.
FAQs
hast utility to check if a node is an embedded element
The npm package hast-util-embedded receives a total of 472,018 weekly downloads. As such, hast-util-embedded popularity was classified as popular.
We found that hast-util-embedded demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Security News
This episode explores the hard problem of reachability analysis, from static analysis limits to handling dynamic languages and massive dependency trees.
Security News
/Research
Malicious Nx npm versions stole secrets and wallet info using AI CLI tools; Socket’s AI scanner detected the supply chain attack and flagged the malware.
Security News
CISA’s 2025 draft SBOM guidance adds new fields like hashes, licenses, and tool metadata to make software inventories more actionable.