statically render Tiptap JSON
78%
Total Score
healthy
Active maintenance and strong project backing outweigh unpinned workflow actions and weak package-to-repository naming evidence.
Four of six publishing accounts use the organization domain, while _bdbch (bdbch.com) and svenadlung (ueber.io) are outside-domain accounts; this is a modest account-hygiene caution, mitigated by organization backing.
The repository name does not match the package name and its README does not mention @tiptap/static-renderer, so package ownership is less directly evidenced; this is somewhat mitigated by the organization-backed monorepo context.
All three workflows were analyzed with no untrusted checkout or script-injection findings, but all 19 action references are unpinned. The publish workflow also has a high-confidence template-injection finding and installs an ad hoc package; these warrant workflow review, though they do not by themselves make the package unfit.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10656 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @tiptap/static-renderer is vulnerable to Cross-Site Scripting (XSS) in versions 3.0.0-next.1 - 3.22.4. | 3.0.0-next.1 - 3.22.4 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.