A beautiful WYSIWYG text editor based on HTML5 technology. Cross browser, with mobile support, high performance and Retina Ready modern design.
70%
Total Score
caution
Usable with caveats: workflows contain high-confidence template-injection findings and all three action references are unpinned.
The manifest declares a proprietary license while the artifact and repository contain an MIT license file. This mismatch should be clarified before depending on the release.
Composer is used for builds, but no security-scanning tooling was detected. This is a modest process gap rather than evidence of abandonment.
The repository has no published security policy. That reduces vulnerability-reporting transparency, though the active project and release history provide some compensation.
Both workflows have high-confidence template-injection findings, and all 3 of 3 action references are unpinned. Top-level write permissions on both workflows add exposure, although no untrusted checkout or privileged trigger was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.