paragraph extension for tiptap
86%
Total Score
healthy
Healthy release with strong maintenance and provenance, despite workflow pinning and repository-package matching gaps.
Four of six publishing accounts use the organization domain, consistent with the organization-backed project. _bdbch (bdbch.com) and svenadlung (ueber.io) are outside-domain publishing accounts, which is a minor account-hygiene concern rather than evidence of limited maintenance capacity.
The repository name does not match this package and its README does not mention @tiptap/extension-paragraph. This can be normal for a monorepo, but it leaves the package-to-repository relationship less explicit.
All three workflows were analyzed with no untrusted checkout or script-injection triggers, and one workflow scopes permissions at job level. However, all 19 action references are unpinned, and the high-confidence template-injection finding plus an ad hoc package install in publish.yml warrant workflow review.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.