This is a mature, actively released, non-deprecated package with 226 releases over roughly 12 years, 22 releases in the last 12 months, a stable version, an unarchived organization-owned repository, and a package-specific repository match. The main concerns are concentrated recent maintenance in one contributor, no repository security policy or security-scanning tooling, and no tests or changelog; however, the artifact is primarily a customized, prebuilt TinyMCE distribution, so the absence of tests and a changelog is less damaging than it would be for an application library. Overall, it appears suitable to depend on, with some maintainer-bus-factor and security-process risk.
82%
Total Score
80
100
83
90
A README is present, but neither the artifact nor repository contains tests or a changelog. For this package's role as a customized prebuilt editor distribution, the missing tests are less concerning than for a logic-heavy library, though the documentation gap remains a modest transparency weakness.
One contributor made all five commits in the last three months, creating a genuine single-maintainer continuity risk. The organization-owned repository provides some possible handoff capacity, but no second recent contributor is shown.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is not inherently unhealthy, but it provides no evidence of an active community feedback or review process.
The repository reports zero stars, forks, and watchers, so there is little observable community adoption evidence. Popularity is supporting evidence rather than a decisive health criterion, especially for a focused component package.
Composer is used as a build tool, which indicates basic build structure, but no security-scanning tool is configured. The missing scanning process is a security-hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
contao-components/installer Version ^1.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.