Basic configuration for the CodeMirror code editor
42%
Total Score
67
100
83
67
The repository recorded zero commits and zero active maintainers in the last three months. This reinforces the archive warning and leaves little evidence of ongoing source maintenance.
The linked GitHub repository is archived. An archived source project is a severe maintenance and abandonment warning even though it was pushed recently and the registry continues to publish releases.
No build tool or security-scanning tool was detected in the linked repository, reducing transparency and automated protection for future changes.
The repository has no security policy. This is not proof of unsafe code, but it weakens the project's stated process for handling vulnerabilities.
The audit completed without findings, but no workflows were present to analyze, so this provides little evidence about release automation or workflow hygiene.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-757251 codemirror is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.33.0 - 5.65.21. | 2.33.0 - 5.65.21 | Medium |
CVE-2020-7760 codemirror is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 5.58.2. | 0.0.0 - 5.58.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@codemirror/lint Version ^6.0.0 | — | — |
@codemirror/view Version ^6.0.0 | — | — |
@codemirror/state Version ^6.0.0 | — | — |
@codemirror/search Version ^6.0.0 | — | — |
@codemirror/commands Version ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.