JS Licence Key Gate: GPL & Eval Keys

Flags GPL and evaluation licence keys and missing commercial keys for Handsontable, TinyMCE, CKEditor 5, FullCalendar, AG Grid, MUI X and Syncfusion in closed-source JS/TS code. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Handsontable, TinyMCE, CKEditor 5, FullCalendar, AG Grid, MUI X and Syncfusion licence keys in closed-source JS/TS

AG Grid Enterprise lists at $999 per developer (perpetual, 1 year of updates)

Buy the full version — $29
Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool

· ReadyStack

Worked example

Real numbers from this tool, line by line.

JS Licence Key Gate: GPL & Eval Keys

4 GPL and evaluation keys shipped in one widgets.ts: that is what JS Licence Key Gate found in its own test file, and the file is the kind of dashboard bootstrap a front-end lead at a closed-source SaaS company writes every quarter.

Here is the file in outline. A spreadsheet grid from Handsontable, a resource timeline from FullCalendar Premium, a notes field in TinyMCE, a contract editor in CKEditor 5, an AG Grid Enterprise table, an MUI X Pro data grid and a Mapbox map. Every component renders and every test passes.

The four keys that ship:

licenseKey: 'non-commercial-and-evaluation' // Handsontable schedulerLicenseKey: 'GPL-My-Project-Is-Open-Source' // FullCalendar Premium license_key: 'gpl' // TinyMCE 7+ licenseKey: 'GPL' // CKEditor 5

Each one is a declaration. The Handsontable string says the grid is used for evaluation or non-commercial work; Handsontable has been proprietary since 7.0.0. The FullCalendar string says your whole project is released under the GPL. The TinyMCE string says you use TinyMCE 7 under GPLv2+, the licence TinyMCE moved to with 7.0. The CKEditor string says the same for CKEditor 5, which made config.licenseKey a required property in v44.0.0. None of these is true for a closed-source SaaS.

The three warnings in the same file are quieter. AG Grid Enterprise is imported but setLicenseKey is never called in that file. MUI X Pro is imported without LicenseInfo.setLicenseKey. And mapbox-gl is imported: from 2.0.0 it is proprietary, under the Mapbox Terms of Service and billed per map load, while 1.13 was the last BSD-3 release.

Why the usual tools miss it. npm licence checkers read the license field each package declares. That tells you TinyMCE is GPL, which you already know; it does not tell you which key string your code passes. A chatbot asked whether TinyMCE is free answers about the package, not about line 34 of your file. The finding lives in your own source, so the check has to read your own source.

What the extension does. It runs 15 rules over the open file as you type and puts each finding in the Problems panel with the rule id, the line and the fix. The fix is always concrete: load a purchased key from config, pin the last permissive release (handsontable 6.2.2, tinymce 6.8.x), move to a permissive fork (maplibre-gl), or call the vendor's setLicenseKey or registerLicense at app start. On the clean version of the same file, with every key read from a config module, it reports 0 findings.

When it costs you. A wrong key costs nothing on the day you ship. It costs at the moment somebody reads the code with a licence question in mind: a vendor audit, a customer security questionnaire, or acquisition due diligence, where a data room reviewer searches the repository for exactly these strings. The price of the licence you should have held is public: AG Grid Enterprise lists at $999 per developer, perpetual, with one year of updates.

Free and full. The free tier checks one file at a time, in VS Code or in the web page, which runs the same engine.js and rules.json in the browser without uploading anything. That is enough to clean a file before a pull request. The full version scans every file in the workspace in one pass and exports the licence inventory as CSV and Markdown for procurement or a due diligence folder.

It is a technical check, not legal advice: the vendor's licence text decides. But it tells you which lines to take to that text.

15 seconds — what it actually does

Questions people ask

What does JS Licence Key Gate actually do?

It reads a JavaScript or TypeScript file and flags licence key strings that do not fit a closed-source commercial product: the Handsontable evaluation key, FullCalendar GPL and non-commercial keys, TinyMCE license_key 'gpl', CKEditor 5 licenseKey 'GPL', and AG Grid Enterprise, MUI X Pro or Syncfusion imported without a key. It runs 15 rules and gives the line and the fix.

Who is JS Licence Key Gate for?

Front-end leads and engineering managers at closed-source SaaS companies, agencies that ship client dashboards built on commercial grids and editors, and teams preparing for a vendor licence audit or acquisition due diligence. It suits anyone whose product imports Handsontable, TinyMCE, CKEditor 5, FullCalendar Premium, AG Grid Enterprise, MUI X Pro or Syncfusion.

Why can't a free npm licence checker find these problems?

Free npm licence checkers read the license field that each package declares in its package.json. The breach here sits in your own source code: a key string such as 'non-commercial-and-evaluation' or license_key 'gpl' passed at runtime. The components render normally with those keys, so tests pass. No dependency scanner reads the value your code passes.

What is free and what does the paid version add?

Free: open any JS or TS file in VS Code, or paste it into the web page, and get every GPL, evaluation or missing commercial key with the line and the fix. The paid version, 29 dollars once per person or team seat, scans every file in the workspace in one pass and exports a CSV and Markdown licence inventory for procurement or due diligence.

What does fixing a licence finding cost compared with the alternatives?

The commercial licences themselves are the real cost: AG Grid Enterprise lists at 999 dollars per developer for a perpetual licence with one year of updates. A licence review by counsel during due diligence is billed by the hour. This check runs in the editor as you type and names the line before the code ships.

Why not just ask ChatGPT or another AI chat?

A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. JS Licence Key Gate: GPL & Eval Keys checks the file you open against 15 rules from a rule set dated 2026-09-28, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.