The package includes release notes, a README, and a clear license, with no install-time script. An organization backs it, but recent work is concentrated in one contributor and workflow references are entirely unpinned.
68%
Total Score
63
94
67
All 4 recent commits came from one contributor. Organization backing provides some handoff capacity, but the observed maintenance base remains concentrated.
Only 4 commits were recorded in the last 3 months, showing some recent work but a relatively light maintenance cadence for a large editor project.
The repository has 389 open issues, while no issues or pull requests were closed or merged in the measured month; this suggests backlog and limited visible responsiveness.
Composer build tooling is present, but no security scanning tools were detected, leaving the project without visible automated security coverage.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-41592 froala/wysiwyg-editor is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.1 - 4.1.3. | 4.0.1 - 4.1.3 | Medium |
CVE-2020-26523 froala/wysiwyg-editor is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.2.2. | 0.0.0 - 3.2.2 | Medium |
CVE-2021-28114 froala/wysiwyg-editor is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.2.7. | 0.0.0 - 3.2.7 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.