Package Health

enjoyscms/ckeditor5

The tiny artifact has no README and the linked repository does not match the package name, making ownership and usage harder to verify. Its stable version and organization-backed repository help, but the long inactivity and absent license leave substantial adoption risk.

Latest 4.2.1PackagistPackagist

42%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Licensedanger

No license is declared, and no license file was found in either the package or repository. This is a significant transparency and adoption concern for an open-source dependency.

Release historydanger

The latest release was over 3 years ago, with no releases in the last 12 months; the earlier median interval of about 47 days shows this is a genuine activity collapse rather than a consistently slow cadence.

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the extended release gap and indicating little current maintenance capacity.

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These increase installation-time behavior and deserve review, but the signal alone does not show harmful behavior or make the release unfit.

Package scaffoldingcaution

The published artifact has no README, tests, or changelog, and the repository provides no such evidence either; while tests and changelogs need not ship in an artifact, the missing README weakens consumer guidance for this CMS integration.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
enjoyscms/core
Version ^4.7

Weekly Downloads

Info

Last Published
3 years ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform