Package Health

ezsystems/ezplatform-richtext

eZ Platform RichText Extension, including the RichText FieldType.

Latest v4.0.0-alpha2PackagistPackagist

18%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

50

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Are you affected? Scan for Free

Health Score Breakdown

Registry deprecationdanger

Packagist marks the entire package as abandoned, with no replacement package specified. Package-level abandonment is a severe dependency-lifecycle risk.

Repo commit activitydanger

The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the archived repository and providing no evidence of ongoing maintenance.

Repository archiveddanger

The linked source repository is archived, indicating that active maintenance has ended even though the repository was backed by an organization.

Dangerous workflowscaution

One of six workflows uses pull_request_target, which warrants caution because it can run with elevated repository context. No untrusted checkouts or script-injection patterns were detected.

Release historycaution

The package has 87 releases and a history dating back to 2018, but it had no releases in the last 12 months, so its previously active cadence does not compensate for the current abandonment signals.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-43372
ezsystems/ezplatform-richtext is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 3.3.0 - 3.3.40.
3.3.0 - 3.3.40
Low

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
twig/twig
Version ^3.0
—
—
symfony/form
Version ^5.0
—
—
symfony/yaml
Version ^5.0
—
—
symfony/asset
Version ^5.1
—
—
symfony/cache
Version ^5.0
—
—

Weekly Downloads

Info

Last Published
4 years ago
Created
7 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform