Package Health

@tiptap/static-renderer

statically render Tiptap JSON

Latest 3.31.4NPMNPM

78%

Total Score

healthy

Active maintenance and strong project backing outweigh unpinned workflow actions and weak package-to-repository naming evidence.

Are you affected? Scan for Free

Health Score Breakdown

Maintainerscaution

Four of six publishing accounts use the organization domain, while _bdbch (bdbch.com) and svenadlung (ueber.io) are outside-domain accounts; this is a modest account-hygiene caution, mitigated by organization backing.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention @tiptap/static-renderer, so package ownership is less directly evidenced; this is somewhat mitigated by the organization-backed monorepo context.

Workflow auditcaution

All three workflows were analyzed with no untrusted checkout or script-injection findings, but all 19 action references are unpinned. The publish workflow also has a high-confidence template-injection finding and installs an ad hoc package; these warrant workflow review, though they do not by themselves make the package unfit.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-10656 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@tiptap/static-renderer is vulnerable to Cross-Site Scripting (XSS) in versions 3.0.0-next.1 - 3.22.4.
3.0.0-next.1 - 3.22.4
Medium

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
11 days ago
Created
1 year ago
Unpacked Size
1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform