Package Health

sandritsch91/yii2-froala-editor

This is a usable, licensed, stable package with a matching source repository, recent release activity, no registry deprecation, no archive marker, and no install-time lifecycle scripts. However, maintenance depth and transparency are limited: the repository has no commits or active maintainers in the last 3 months, has no tests, changelog, security policy, or security scanning, and shows essentially no community adoption. The package is small and its dependency profile is straightforward, so these gaps do not make it unfit, but they create meaningful maintenance and abandonment risk; review the source and consider whether the recent release cadence is sufficient for your dependency needs.

Latest 1.1.4PackagistPackagist

65%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one registry account has publishing access. This is a thin publishing base for continuity, although the linked repository is clearly owned by the same individual, so it is not evidence of a mismatched project.

Package scaffoldingcaution

A README and GitHub Releases are present, but neither the artifact nor repository contains tests or a changelog. For a small Yii2 widget this is a meaningful transparency and regression-risk gap.

Project backingcaution

The repository is owned by an individual rather than an organization, so continuity depends primarily on one person. The matching repository and package identity provide provenance, but not organizational redundancy.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the recent release and push date partially offset this, the absence of sustained commit activity is a concrete maintenance concern.

Repo issue activitycaution

There are no open issues or pull requests and no recent issue or pull-request activity. This avoids an unresolved backlog, but also provides no evidence of an active user or contributor community.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Sandro Venetz

Direct Dependencies

DependencyLast ReleaseScore
yiisoft/yii2
Version ^2.0.42
froala/yii2-froala-editor
Version ^4.2.1

Weekly Downloads

Info

Last Published
15 days ago
Created
3 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform