The repository has no recent commits, and this is its only release from nearly three years ago. Its README warns that it is not the official package and recommends using the official CKEditor installation instead. Organization backing and a clear license file provide some reassurance, but not enough to offset the adoption risk.
32%
Total Score
50
50
50
The package includes a README and changelog, but the README explicitly says it is not the official text-editor package and recommends using the official installation instead. That materially weakens consumer confidence despite the documentation being present.
This is the package’s only release, published nearly three years ago, with no releases in the last year. That strongly suggests abandonment or a one-off publication.
The repository recorded no commits and no active maintainers in the last three months. Together with the one-release history, this indicates no observable ongoing maintenance.
A license file is present and detected as MIT, but the manifest declares the package as proprietary. The mismatch creates licensing ambiguity for consumers.
The linked repository has no security policy. This is a transparency gap, although the package’s much stronger concerns are its age and lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
quantaforge/support Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.