Package Health

silverstripe/htmleditor-tinymce

It includes tests, a changelog, clear licensing, and no install-time scripts. The beta release and unpinned workflow actions add avoidable risk, while recent releases and organization backing support continued maintenance.

Latest 1.2.0-beta1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

88

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

88

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitycaution

Only two commits were recorded in the last three months, which is modest activity, but the repository was pushed recently and other activity shows ongoing maintenance.

Repo toolingcaution

The repository uses Composer build tooling, but no security scanning tools were detected. This is a transparency and maintenance-hygiene gap rather than evidence of an unsafe release.

Security policycaution

The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency but is not by itself evidence of abandonment.

Version stabilitycaution

This release is a beta while the latest listed version is stable 1.1.3, so consumers should expect more change than with a stable release. The recent prerelease share is notable but does not indicate abandonment.

Workflow auditcaution

All seven analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkout, script injection, high-severity issue, or broad top-level write permissions, and all workflows were analyzed successfully.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Silverstripe
The Silverstripe Community

Direct Dependencies

DependencyLast ReleaseScore
silverstripe/framework
Version ^6
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform