Healthy and suitable to depend on. It has a long, active release history, a current non-prerelease version, recent commits from three contributors, and clear organizational backing; workflow security configuration is the main remaining caveat.
90%
Total Score
88
100
94
90
The repository has ongoing activity with three new issues and one new pull request in the last month, though only one issue was closed and no pull requests were merged, leaving some backlog.
Composer build tooling is present, but no repository security scanning tools were detected; the security policy and active maintenance partly compensate, but automated coverage is less visible.
Two workflows lack top-level token permissions declarations, which weakens least-privilege transparency, although none declares top-level write access and another workflow is explicitly read-only.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-933735 craftcms/ckeditor is vulnerable to Broken Access Control in versions 4.0.0 - 5.6.1. | 4.0.0 - 5.6.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
embed/embed Version ^4.4 | — | — |
craftcms/cms Version ^5.10.0 | — | — |
craftcms/html-field Version ^3.6.0 | — | — |
nystudio107/craft-code-editor Version >=1.0.8 <=1.0.13 || ^1.0.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.