ckeditor plugin. Adds images from local client as base64 string into the source without server side processing.
43%
Total Score
unhealthy
Risky: no commits or releases for over five years signals strong abandonment risk.
Only two releases were published, both in May 2021, with no releases in more than five years. This strongly limits evidence that the package is maintained for current dependencies or platforms.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity.
The artifact includes a license file, but the manifest declares proprietary licensing while the file is detected as MPL-1.1, GPL-2.0, and LGPL-2.1. That mismatch creates uncertainty about the terms consumers may rely on.
The package runs post-install and post-update Composer scripts. These scripts increase installation-time exposure and deserve scrutiny even though this is not itself evidence of malicious behavior.
The package has one registry maintainer, leaving a thin publishing base. The linked repository is user-owned rather than organization-backed, so there is little provided evidence of broader maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ckeditor/ckeditor Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.