Package Health

froala/wysiwyg-editor

The package includes release notes, a README, and a clear license, with no install-time script. An organization backs it, but recent work is concentrated in one contributor and workflow references are entirely unpinned.

Latest v5.4.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Repo bus factorcaution

All 4 recent commits came from one contributor. Organization backing provides some handoff capacity, but the observed maintenance base remains concentrated.

Repo commit activitycaution

Only 4 commits were recorded in the last 3 months, showing some recent work but a relatively light maintenance cadence for a large editor project.

Repo issue activitycaution

The repository has 389 open issues, while no issues or pull requests were closed or merged in the measured month; this suggests backlog and limited visible responsiveness.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected, leaving the project without visible automated security coverage.

Security policycaution

The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.

Vulnerabilities

TitleVersionsSeverity
CVE-2023-41592
froala/wysiwyg-editor is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 4.0.1 - 4.1.3.
4.0.1 - 4.1.3
Medium
CVE-2020-26523
froala/wysiwyg-editor is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.2.2.
0.0.0 - 3.2.2
Medium
CVE-2021-28114
froala/wysiwyg-editor is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.2.7.
0.0.0 - 3.2.7
Medium

Package versions

Maintainers

Froala Labs

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 month ago
Created
9 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform