Healthy and suitable to depend on. It has a current stable release, recent repository activity from two contributors, release notes, tests in the repository, and clear project backing; the workflows do not declare top-level permissions, which is a minor transparency concern.
88%
Total Score
90
100
100
90
There were no new or closed issues in the last month and only limited pull-request activity, indicating a relatively quiet project; recent commits and merged pull requests partly compensate.
All three workflows lack top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege settings would improve CI transparency.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10416 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. ueberdosis/tiptap-php is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 1.4.0. | 1.0.0 - 1.4.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
spatie/shiki-php Version ^2.0 | — | — |
scrivo/highlight.php Version ^9.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.