5 min read

Remotion: Make Videos With React Code or an AI Agent (GitHub, Scanned)

Build videos as React components, render them to MP4, and let a coding agent write the animation.

Remotion logo
✅
Scan: safe. Nothing malicious. Two things to know: the repository commits 78 prebuilt binaries (Remotion's compositor and FFmpeg libraries for each platform) that a scan cannot match to source, and its JavaScript dependencies are in a bun.lock the scanner does not read. Scanned Oct 3, 2026; the full report is below.

Remotion treats a video as a React app. Each frame is a component rendered at a given time, so animation is ordinary code driven by the frame number, and anything you can build for the web (charts from live data, captions, 3D, maps) can go into an MP4. A studio lets you preview and scrub the timeline, the Player embeds videos in web apps, and renders run on your own machine, in AWS Lambda or a Vercel sandbox for batch jobs that produce thousands of personalised videos.

It has been around since 2020 and has about 62,000 stars, but its recent jump in attention comes from AI agents: Remotion publishes Agent Skills that teach Claude Code, Codex or Cursor its best practices, and prompt-to-video workflows built on it are a steady topic on TikTok and YouTube. It is made by Jonny Burger and a small team. The licence is not standard open source: individuals, non-profits and companies with up to three employees use it free, including commercially, while larger for-profit companies need a paid company licence.

Who it is for

Developers who want data-driven or templated videos, creators who would rather describe an animation to a coding agent than keyframe it, and teams building video features into a product.

Getting started

1. Create a new project from a template (Node.js required)

npx create-video@latest

2. Add Remotion's Agent Skills for Claude Code, Codex or Cursor

npx skills add remotion-dev/skills

3. Start the studio to preview and render

npm run dev

Rendering uses a headless Chrome and FFmpeg that Remotion downloads and manages for you. Check the licence before using it at a company with more than three employees.

Safety scan

We cloned remotion-dev/remotion at commit b74a8b8 on Oct 3, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • One secret hit in 14,628 files and 1.7 million lines: a Google Maps Embed API key in packages/docs/src/components/GoogleMaps.tsx, a browser key that shows Remotion's Zurich office on the docs site. Embed keys are public by design and meant to be restricted by referrer.
  • Three very long lines, all explained: packages/whisper-web/main.js is Emscripten glue with whisper.cpp's WebAssembly inlined as base64 (1.3 million characters), and the two open-in-editor helpers contain a 7,000-character Unicode regular expression for matching file paths. The npm prepare script only points git at the repository's hooks folder.
  • 78 committed binaries: the remotion compositor executable plus FFmpeg's libavcodec, libavformat and libavfilter for Linux (glibc and musl), macOS and Windows, a few Windows runtime DLLs, and composer.phar in a PHP example. They are what makes rendering work without installing FFmpeg, and you are trusting Remotion's own builds of them.
  • Only the Rust and Go lockfiles were checked: 128 packages with 10 advisories of unknown severity, mostly unmaintained crates and old AWS SDK and golang.org/x versions in the Lambda Go client and its example. The JavaScript packages users install are locked in bun.lock, which this scan does not parse.
  • Six workflows. discord.yml uses pull_request_target only to post a notification and does not check out code; 1 of 29 third-party actions is pinned to a commit. Licence and contributing guide present; no security policy, Dependabot or CodeQL.

What the scanner counted

CheckResult
Secrets1 candidate found and read; see the notes above.
Suspicious code3 pattern hits found and read; every one is listed under the raw findings.
Install-time code1 npm lifecycle script. 2 installer scripts
Committed binaries78 executable or compiled objects committed; listed under the raw findings.
CI workflows6 workflows. 1 uses pull_request_target, none check out the pull request head. 28 of 29 third-party actions pinned to a tag rather than a commit.
Network hosts40 distinct hosts referenced from source; most often fonts.gstatic.com, fonts.googleapis.com, www.remotion.dev, remotion.media. 7 URLs to a bare IP address, listed under the raw findings.
Known vulnerabilities10 advisories across 128 pinned packages: 0 critical, 0 high, 0 moderate, 0 low, 10 unrated. packages/compositor/Cargo.lock: 97 packages, 2 advisories; packages/lambda-go-example/go.mod: 12 packages, 8 advisories; packages/lambda-go/go.mod: 26 packages, 5 advisories.
Project hygieneHas licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Secret candidates (1, redacted)
WhereRuleMatch
packages/docs/src/components/GoogleMaps.tsx:22google-api-keyAIzaSy…7R8 (39 chars)
Pattern hits (3)
WhereRuleMatch
packages/create-video/src/open-in-editor.ts:317very-long-line7251 chars
packages/studio-server/src/helpers/open-in-editor.ts:260very-long-line7251 chars
packages/whisper-web/main.js:275very-long-line1286131 chars
URLs to bare IP addresses (7)
WhereRuleMatch
packages/studio-server/src/test/download-remote-asset.test.ts:49ip-literal-urllocation: 'https://93.184.216.35/logo.gif',
packages/studio-server/src/test/download-remote-asset.test.ts:74ip-literal-urlinput: {url: 'https://93.184.216.34/raw-link'},
packages/studio-server/src/test/download-remote-asset.test.ts:93ip-literal-url'https://93.184.216.34/raw-link',
packages/studio-server/src/test/download-remote-asset.test.ts:94ip-literal-url'https://93.184.216.35/logo.gif',
packages/studio-server/src/test/download-remote-asset.test.ts:145ip-literal-urlinput: {url: 'https://93.184.216.34/raw-link'},
packages/studio-server/src/test/insert-element.test.ts:274ip-literal-urlurl: 'https://93.184.216.35/remote.bin',
packages/studio-server/src/test/insert-element.test.ts:388ip-literal-url{path: 'remote.bin', type: 'url', url: 'https://93.184.216.35/remote.bin'},
npm lifecycle scripts (1)
  • package.json prepare: git config core.hooksPath .githooks
Installer scripts (2)
Committed binaries (78)
  • packages/compositor-linux-x64-musl/libavcodec.so: ELF, 22 MB
  • packages/compositor-linux-x64-gnu/libavcodec.so: ELF, 22 MB
  • packages/compositor-darwin-x64/libavcodec.dylib: Mach-O, 20 MB
  • packages/compositor-win32-x64-msvc/avcodec-61.dll: PE (Windows executable), 18 MB
  • packages/compositor-darwin-arm64/libavcodec.dylib: Mach-O, 14 MB
  • packages/compositor-linux-arm64-musl/libavcodec.so: ELF, 13 MB
  • packages/compositor-linux-arm64-gnu/libavcodec.so: ELF, 10 MB
  • packages/compositor-win32-x64-msvc/libvpx-1.dll: PE (Windows executable), 3 MB
  • packages/lambda-php-example/composer.phar: .phar, 3 MB
  • packages/compositor-linux-x64-musl/remotion: ELF, 1 MB
  • packages/compositor-win32-x64-msvc/libstdc++-6.dll: PE (Windows executable), 1 MB
  • packages/compositor-linux-arm64-musl/remotion: ELF, 1 MB
  • packages/compositor-linux-x64-gnu/remotion: ELF, 1 MB
  • packages/compositor-linux-arm64-gnu/remotion: ELF, 1 MB
  • packages/compositor-linux-x64-musl/libavfilter.so: ELF, 1 MB
  • packages/compositor-win32-x64-msvc/remotion.exe: PE (Windows executable), 1 MB
  • packages/compositor-darwin-arm64/remotion: Mach-O, 1 MB
  • packages/compositor-darwin-x64/remotion: Mach-O, 1 MB
  • packages/compositor-linux-x64-gnu/libavfilter.so: ELF, 1 MB
  • packages/compositor-win32-x64-msvc/avfilter-10.dll: PE (Windows executable), 1 MB
  • packages/compositor-linux-arm64-gnu/libavformat.so: ELF, 1 MB
  • packages/compositor-linux-x64-gnu/libavformat.so: ELF, 1 MB
  • packages/compositor-linux-arm64-musl/libavformat.so: ELF, 1 MB
  • packages/compositor-linux-x64-musl/libavformat.so: ELF, 1 MB
  • and 54 more
Worst known vulnerabilities (10 of 10)
AdvisorySeverityPackageSummary
RUSTSEC-2025-0056unknownadler@1.0.2adler crate is unmaintained, use adler2 instead
RUSTSEC-2026-0204unknowncrossbeam-epoch@0.9.14Invalid pointer dereference in `fmt::Pointer` impl for `Atomic` and `Shared` when the underlying pointer is invalid
GHSA-7f33-f4f5-xwgwunknowngithub.com/aws/aws-sdk-go@1.44.257In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go
GHSA-f5pg-7wfw-84q9unknowngithub.com/aws/aws-sdk-go@1.44.257CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go
GO-2026-5932unknowngolang.org/x/crypto@0.52.0The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
CVE-2026-56854unknowngolang.org/x/crypto@0.52.0Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
CVE-2026-78662unknowngolang.org/x/crypto@0.52.0Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
CVE-2026-56855unknowngolang.org/x/crypto@0.52.0Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
CVE-2026-46600unknowngolang.org/x/net@0.55.0Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVE-2026-56852unknowngolang.org/x/text@0.37.0Infinite loop on invalid input in golang.org/x/text
Workflows worth a look

By the numbers

Stars61.6K
Forks4,755
Contributors437
Commits38K
Open issues226
Open pull requests17
Releases691
Latest releasev4.0.532
Licencecustom
Main languageTypeScript
Project age6 years
Last pushOct 3, 2026
Tracked files14,628
Lines of code1.7M
Checkout size791 MB

Lines by language: TypeScript 1.4M, Markdown 165.1K, JSON 95.4K, JavaScript 21.8K, Rust 4,557, CSS 4,392.

Questions

Is Remotion free?

For individuals, non-profits and for-profit companies with up to three employees, yes, including commercial use. Larger for-profit organisations need a company licence from remotion.pro. Reselling a modified Remotion is not allowed under either licence. Cloud rendering on Lambda or Vercel is billed by those providers.

Can AI make videos with Remotion?

Yes. Because a Remotion video is React code, a coding agent can write and edit it from a prompt. Installing the official skills gives agents Remotion's conventions for timing, transitions, captions and assets, and the result is a real project you can keep editing by hand.

Do I need to know React to use Remotion?

To edit the output yourself, some React and TypeScript knowledge helps a lot. With an agent writing the code, you can get started from prompts and templates, but complex edits and debugging go faster if you can read the components.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.