headless rich text editor
91%
Total Score
healthy
Healthy release backed by active maintenance, frequent releases, and a recent source update.
Four publishing accounts use the organization domain, consistent with the organization-backed project. _bdbch (bdbch.com) and svenadlung (ueber.io) are outside-domain publishing accounts, which is a minor account-hygiene concern.
All three workflows were analyzed with no untrusted checkout or script-injection findings, but all 19 action references are unpinned. The publish workflow also has high-confidence template-injection and adhoc-package findings; these are workflow hygiene concerns rather than standalone evidence that the release is unsafe.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-65180 @tiptap/core is vulnerable to Prototype Pollution in versions 2.0.0 - 3.30.3. | 2.0.0 - 3.30.3 | High |
AIKIDO-2026-395472 @tiptap/core is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.7.0 - 3.30.4. | 3.7.0 - 3.30.4 | Medium |
AIKIDO-2026-613639 @tiptap/core is vulnerable to Cross-Site Scripting (XSS) in versions 2.0.0 - 3.30.3. | 2.0.0 - 3.30.3 | High |
AIKIDO-2026-738065 @tiptap/core is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 3.7.0 - 3.30.4. | 3.7.0 - 3.30.4 | Medium |
AIKIDO-2026-484358 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @tiptap/core is vulnerable to Denial of Service (DoS) in versions 2.11.0 - 3.26.1. | 2.11.0 - 3.26.1 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.