← Home

@ckeditor/ckeditor5-export-word

Export to Word feature for CKEditor 5.

18
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ckeditor

Keywords

ckeditorckeditor5ckeditor 5ckeditor5-featureckeditor5-pluginWYSIWYGWYSIWYMtextrich-textrichtextckeditoreditoreditinghtmlcontentEditableWordprint Wordsave Wordconvert to Wordexport Wordexport to WordWord converterHTML to Word

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/export-word.js AI (source-diff): CKSource intentionally obfuscates commercial plugin code; package.json declares 'obfuscated: true'. Legal notice in source confirms this is deliberate IP protection. ai
source-diff obfuscated-file:src/exportwordui.js AI (source-diff): CKSource intentionally obfuscates commercial plugin code; package.json declares 'obfuscated: true'. Legal notice in source confirms this is deliberate IP protection. ai
source-diff obfuscated-file:src/exportwordcommand.js AI (source-diff): CKSource intentionally obfuscates commercial plugin code; package.json declares 'obfuscated: true'. Legal notice in source confirms this is deliberate IP protection. ai
semgrep semgrep:obfuscation-hex-functions AI (semgrep): CKSource intentionally obfuscates commercial plugins; package.json declares 'obfuscated: true'. This is stable across all versions of this commercial plugin. ai
semgrep semgrep:obfuscation-while-true AI (semgrep): Same as above — while(!![]) loops are a direct artifact of CKSource's intentional obfuscation of their commercial Export to Word plugin. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-ui AI (phantom-deps): Same-org CKEditor dependency declared for peer/optional use; consistent with the accepted pattern for other CKEditor phantom deps in this package. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-core AI (phantom-deps): Same-org CKEditor dependency declared for peer/optional use; consistent with the accepted pattern for other CKEditor phantom deps in this package. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-track-changes AI (dependencies): Same-org CKEditor 5 dependency pinned to matching version; part of CKEditor's coordinated monorepo release pattern. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): CKEditor commercial plugins use a custom license; this is expected and consistent across all CKEditor premium feature packages. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-merge-fields AI (phantom-deps): Same-org @ckeditor package; phantom dep pattern is expected in CKEditor's monorepo architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-icons AI (phantom-deps): Same-org @ckeditor package; phantom dep pattern is expected in CKEditor's monorepo architecture where deps may be declared for type resolution without direct imports. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-collaboration-core AI (phantom-deps): Same-org @ckeditor package; phantom dep pattern is expected in CKEditor's monorepo architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-comments AI (phantom-deps): Same-org @ckeditor package; phantom dep pattern is expected in CKEditor's monorepo architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-track-changes AI (phantom-deps): Same-org @ckeditor package; phantom dep pattern is expected in CKEditor's monorepo architecture. ai

Versions (showing 18 of 18)

Version Deps Published
48.3.1 9 / 0
48.3.0 9 / 0
48.2.0 9 / 0
48.1.1 9 / 0
48.1.0 9 / 0
48.0.1 9 / 0
48.0.0 9 / 0
47.7.3 10 / 0
47.7.2 10 / 0
47.7.1 10 / 0
47.7.0 10 / 0
47.6.2 10 / 0
47.6.1 10 / 0
47.6.0 10 / 0
47.5.0 10 / 0
47.4.0 10 / 0
47.3.0 10 / 0
47.2.0 10 / 0

v48.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.