Package Health

froala/wysiwyg-cake2

A beautiful WYSIWYG text editor based on HTML5 technology. Cross browser, with mobile support, high performance and Retina Ready modern design.

Latest 5.2.0PackagistPackagist

70%

Total Score

caution

Usable with caveats: workflows contain high-confidence template-injection findings and all three action references are unpinned.

Health Score Breakdown

Licensecaution

The manifest declares a proprietary license while the artifact and repository contain an MIT license file. This mismatch should be clarified before depending on the release.

Repo toolingcaution

Composer is used for builds, but no security-scanning tooling was detected. This is a modest process gap rather than evidence of abandonment.

Security policycaution

The repository has no published security policy. That reduces vulnerability-reporting transparency, though the active project and release history provide some compensation.

Workflow auditcaution

Both workflows have high-confidence template-injection findings, and all 3 of 3 action references are unpinned. Top-level write permissions on both workflows add exposure, although no untrusted checkout or privileged trigger was reported.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Froala Labs

Direct Dependencies

DependencyLast ReleaseScore
composer/installers
Version *
—
—

Weekly Downloads

Info

Last Published
4 months ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform