@tiptap/vue-3 3.31.3 appears to be a healthy, actively maintained dependency. It has a long release history with frequent recent releases, stable versioning, no registry deprecation, MIT licensing, type declarations, no install-time lifecycle scripts, reproducible npm provenance, and a substantial organization-backed repository with strong recent commit and pull-request activity. The package artifact lacks tests and a changelog, but the linked repository provides both along with extensive source and project documentation. The main transparency concern is that the linked monorepo neither matches the package name nor mentions it in its README, and two workflows lack top-level token permissions; these merit review but do not outweigh the strong maintenance and provenance evidence.
92%
Total Score
100
100
94
90
100
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.