The old version used in this plugin pulls in the vulnerable `ejs`: https://github.com/advisories/GHSA-phwq-j96m-2c2q