Package Health

froala/craft-froala-wysiwyg

Craft 3 CMS plugin for Froala WYSIWYG HTML Rich Text Editor.

Latest 5.2.0PackagistPackagist

66%

Total Score

caution

Usable with caveats: high-confidence workflow injection findings, broad write tokens, and unpinned actions weaken release safety.

Health Score Breakdown

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.

Security policycaution

The repository has no published security policy, making vulnerability reporting and response expectations less clear.

Workflow auditcaution

Both workflows have high-confidence template-injection findings, all three action references are unpinned, and both workflows grant top-level write permissions. No untrusted checkout or dangerous trigger was reported, so this is a significant hygiene concern rather than a standalone severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
craftcms/cms
Version ^3.1
—
—
froala/wysiwyg-editor
Version 5.2.0
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
8 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform