Image feature for CKEditor 5.
92%
Total Score
healthy
Frequent releases and active organization-backed maintenance outweigh the package's weak direct repository linkage.
No build attestation is present, so consumers cannot independently verify the artifact's build origin. The package does identify CircleCI as a trusted publisher, which partly offsets this transparency gap.
The repository name does not match the package name and its README does not mention this package, so the direct package-to-repository linkage is less transparent. The package is part of a known-looking monorepo structure, which partly compensates.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
es-toolkit Version 1.52.0 | — | — |
@ckeditor/ckeditor5-ui Version 49.0.0 | — | — |
@ckeditor/ckeditor5-core Version 49.0.0 | — | — |
@ckeditor/ckeditor5-undo Version 49.0.0 | — | — |
@ckeditor/ckeditor5-icons Version 49.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.