# CKEditor 4: what the LTS split means before you adopt it

> CKEditor 4 is a configurable WYSIWYG HTML editor that reached end of life in June 2023. The open source line stops at 4.22.1, while the master branch now carries CKEditor 4 LTS under the Extended Support Model, which requires a license key.

**ckeditor/ckeditor4** — The best enterprise-grade WYSIWYG editor. Fully customizable with countless features and plugins.

- Repository: https://github.com/ckeditor/ckeditor4
- Website: https://ckeditor.com/ckeditor-4
- Stars: 5,821 · Forks: 2,445
- Language: Rich Text Format
- License: NOASSERTION
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/ckeditor-ckeditor4

## The end-of-life split is the first thing to understand about CKEditor 4

CKEditor 4 launched in 2012 and reached end of life on June 30, 2023. That date splits the project in two. Everything up to 4.22.1 remains available under open source terms, and the README states plainly that this line no longer comes with security updates. From 4.23.0-lts onward, releases are CKEditor 4 LTS distributions, sold under the Extended Support Model, which the README says guarantees security updates and critical bug fixes until December 2029.

The repository reflects that split rather than hiding it. The master branch holds the LTS source, and the LICENSE.md file changed after June 30, 2023 to reflect the Extended Support Model. The package.json still names the package ckeditor4-dev at version 4.25.2 and declares its license as SEE LICENSE IN LICENSE.md, which is a pointer rather than an SPDX identifier. If your dependency scanner expects a clean licence string, this package will not give it one.

The practical consequence is that "CKEditor 4" is no longer a single adoption decision. You are choosing a branch, and the branch determines whether you get fixes. The README does not document what happens to a running LTS deployment if a key expires, so treat renewal timing as something to confirm with the vendor rather than infer from the repository.

## What CKEditor 4 does that a plain textarea does not

The editor replaces a form field with a contenteditable surface and a toolbar, then writes HTML back into the page. The README lists the feature set: captioned images, videos, tables, media embeds, emoji and mentions, pasting from Microsoft Word, Excel and Google Docs, drag and drop image upload, and clipboard handling. Over 500 plugins are listed in the Add-ons Repository.

That paste handling is the reason many teams are still on version 4. Cleaning up markup from Word or Google Docs is tedious work, and the editor's filtering rules do it in the browser before the content reaches your server. The toolbar is configurable, and the repository ships samples/toolbarconfigurator/ for building toolbar layouts visually rather than by hand.

It is aimed at teams maintaining existing web applications, typically with server-rendered forms and a JavaScript layer added on top. It is not aimed at greenfield projects. If you are starting now, the README points to CKEditor 5 and warns that upgrading is not as simple as replacing the folder named ckeditor. That warning is worth taking at face value: the two editors have different architectures, so migration is a rewrite of the integration, not a version bump.

## How CKEditor 4 loads and initializes in a page

The data flow is short. You place a container element in the page, load ckeditor.js, and call CKEDITOR.replace with the container's id. The editor reads the container's existing HTML as its starting content, builds an iframe-backed editing area, and keeps the original element in sync so a normal form post submits the edited markup.

The repository layout matches this. ckeditor.js sits at the top level next to config.js and contents.css, with core/, plugins/, lang/ and skins/ beside them. A build is a directory of these files, which is why the npm package is consumed by script tag rather than by a module import. The README's npm example points the script tag at ./node_modules/ckeditor4/ckeditor.js.

Because configuration lives in config.js and in per-instance settings passed to replace, the editor is easy to tune without rebuilding. That also means configuration drifts across a codebase when several teams each pass their own options. There is no schema or validation step described in the README, so a typo in an option name fails quietly at runtime.

## Installing CKEditor 4 and getting a first editor on the page

The README gives two installation routes. The npm route installs the package and then loads the bundled script from node_modules. Run the install first:

```bash
npm install --save ckeditor4
```

After that, place a container in your HTML and initialize the editor against its id. The README uses the id editor and the CKEDITOR.replace call shown here:

```html
<div id="editor">
    <p>This is the editor content.</p>
</div>
<script src="./node_modules/ckeditor4/ckeditor.js"></script>
<script>
    CKEDITOR.replace( 'editor' );
</script>
```

Reload the page and the div should be replaced by a toolbar and an editable area containing the paragraph you wrote. The second route skips the install and pulls the same file from the CDN, which is useful for a quick check before committing to a package version:

```html
<script src="https://cdn.ckeditor.com/4.22.1/standard/ckeditor.js"></script>
```

Note which version that URL pins: 4.22.1, the last open source release. If you hold an Extended Support Model contract, the README says to add a licenseKey option to the replace call:

```html
<script>
    CKEDITOR.replace( 'editor', {
        licenseKey: 'your license key'
    } );
</script>
```

The README links a separate key activation guide rather than describing the activation handshake itself, so the exact failure behaviour of a missing or invalid key is not documented here. Test that path in a staging environment before a production deploy.

For framework integrations, the README defers to the official usage guides for the ckeditor4-angular, ckeditor4-react and ckeditor4-vue packages rather than repeating their setup steps. That is the right place to look if you are wiring the editor into a component tree.

## The open source branch carries no security updates

This is the limitation that decides most evaluations. The README states that the open source version no longer comes with any security updates and that using it introduces a security risk to your application. That applies to 4.22.1 and every earlier version, including anything served from the CDN under those version numbers.

There is a second, less obvious constraint. From July 1, 2024, the README says security notifications were activated for CKEditor 4, affecting the open source version 4.22 and all earlier versions served via the vendor's CDN. So the CDN path is not a neutral mirror of an old release; the project has changed how those versions behave. The README links a dedicated article on the change but does not reproduce its contents, so the precise effect on a given deployment is something to read up on directly.

A third constraint is architectural. The editor runs in the browser, so any filtering it performs can be bypassed by a client that posts directly to your endpoint. Server-side sanitisation of submitted HTML is not optional here, and the README does not claim otherwise. If your threat model assumes the editor is the security boundary, this is the wrong tool.

## CKEditor 4 versus CKEditor 5, and the licence question underneath

The obvious alternative is CKEditor 5, and the difference is not cosmetic. CKEditor 5 is a new editor with a different internal model, and the README warns that migration means more than swapping a folder. The migration guide is a separate document. The licence differs too: CKEditor 5 is available under the GPL copyleft licence or a commercial licence, while older CKEditor 4 versions keep their original terms. Open source projects with a GPL-incompatible licence can apply to the Free for Open Source program.

So the trade is roughly this. Staying on CKEditor 4 keeps an integration that already works, including its paste filtering and its plugin set, but leaves you on a branch that either receives no fixes or requires a commercial contract. Moving to CKEditor 5 gives you a maintained editor under GPL or a commercial licence, at the cost of rewriting the integration and reviewing whether GPL fits your distribution model.

There is a third path the README names without recommending: keep running 4.22.1 or below. The licence terms of those versions have not changed, so it is permitted. It is also explicitly described as introducing a security risk. That is a business decision, not a technical one, and it should be made by someone who owns the risk rather than inherited by whoever maintains the form.

On licensing generally: the repository declares SEE LICENSE IN LICENSE.md, and the master branch LICENSE.md reflects the LTS terms. Any organisation with a compliance process should read LICENSE.md at the tag they actually deploy, because the terms differ between the open source tags and the LTS branch. That is a reading task, not legal advice.

## Maintenance cost and the upgrade path you are actually buying

The last push to this repository was on 2026-07-10, so the LTS branch is still receiving work. That says nothing about the open source tags, which are frozen at 4.22.1 and earlier. Two codebases with the same name now have different maintenance realities, and conflating them is the most common mistake in an evaluation.

The upgrade cost depends on which direction you move. Within the 4.x LTS line, the README describes the LTS distributions as shipping security updates and critical bug fixes, which implies drop-in releases rather than breaking changes, though the README does not promise API stability in those words. Moving from 4.x to 5.x is the expensive direction and the README is direct that it is not a folder swap.

Development tooling is a separate cost. The package.json lists grunt, jshint, jscs, less and uglify-js as devDependencies, and the test script is a placeholder that exits with an error. In practice that means the repository's own test runner is driven through bender.js and bender-runner.config.json rather than npm test. If you plan to fork or patch the editor, budget for learning that harness; if you only consume builds, it does not affect you.

One thing to verify before committing: the version string in your build. The README says all future versions from 4.23.0-lts onward carry -lts in the version number and require a key. A CDN URL or lockfile entry that still resolves to a 4.22.x build is a different product with different support terms, and the difference is easy to miss in a diff.

## Conclusion

Adopt CKEditor 4 LTS only if you hold an Extended Support Model contract and can activate a license key in your build; if you need security updates without a contract, this is the wrong branch. Anyone staying on 4.22.1 or below should verify their own exposure first, because the README states that version receives no security updates. Before writing any integration code, confirm the exact version string you are loading and whether your build pipeline can inject the licenseKey value.

## FAQ

### Can I use CKEditor 4 for free?

Yes, but only the open source line up to 4.22.1, and the README states that version no longer receives security updates. Versions from 4.23.0-lts onward are CKEditor 4 LTS distributions under the Extended Support Model and require a license key.

### How much does CKEditor cost?

The README does not list prices. It states that CKEditor 4 LTS is available under commercial terms through the Extended Support Model, and that CKEditor 5 is available under the GPL copyleft licence or a commercial licence.

### What is CKEditor 4 used for?

It is a configurable WYSIWYG HTML editor for web pages, covering rich text with captioned images, videos, tables, media embeds, emoji and mentions, plus pasting from Word, Excel and Google Docs and drag and drop image upload.

### How do I use CKEditor 4 on a page?

Install the ckeditor4 package or load ckeditor.js from the CDN, place a container element with an id, then call CKEDITOR.replace with that id. The README shows the container holding a paragraph as the starting content.

### What is the difference between CKEditor 4 and CKEditor 5?

CKEditor 5 is a completely new editor, and the README warns that upgrading is not as simple as replacing the ckeditor folder. CKEditor 5 is available only under the GPL copyleft licence or a commercial licence, while older CKEditor 4 versions keep their original terms.

## Sources

- [ckeditor/ckeditor4 on GitHub](https://github.com/ckeditor/ckeditor4)
- [Issues](https://github.com/ckeditor/ckeditor4/issues)
- [Project website](https://ckeditor.com/ckeditor-4)
- [README](https://github.com/ckeditor/ckeditor4/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ckeditor-ckeditor4
