Gathering detailed insights and metrics for @tiptap/core
Gathering detailed insights and metrics for @tiptap/core
Gathering detailed insights and metrics for @tiptap/core
Gathering detailed insights and metrics for @tiptap/core
The headless rich text editor framework for web artisans.
npm install @tiptap/core
Typescript
Module System
Node Version
NPM Version
99.1
Supply Chain
78.1
Quality
98.6
Maintenance
100
Vulnerability
99.6
License
TypeScript (99.34%)
JavaScript (0.66%)
Total Downloads
120,016,837
Last Day
72,042
Last Week
1,753,141
Last Month
7,616,269
Last Year
65,271,715
MIT License
31,238 Stars
7,110 Commits
2,548 Forks
163 Watchers
59 Branches
396 Contributors
Updated on Jul 03, 2025
Minified
Minified + Gzipped
Latest Version
2.24.0
Package Id
@tiptap/core@2.24.0
Unpacked Size
2.44 MB
Size
487.03 kB
File Count
503
NPM Version
10.8.2
Node Version
20.19.2
Published on
Jul 02, 2025
Cumulative downloads
Total Downloads
Last Day
-9.2%
72,042
Compared to previous day
Last Week
-9.3%
1,753,141
Compared to previous week
Last Month
2.8%
7,616,269
Compared to previous month
Last Year
108.7%
65,271,715
Compared to previous year
1
1
Tiptap is a headless wrapper around ProseMirror – a toolkit for building rich text WYSIWYG editors, which is already in use at many well-known companies such as New York Times, The Guardian or Atlassian.
Documentation can be found on the Tiptap website.
Tiptap is open sourced software licensed under the MIT license.
No vulnerabilities found.
Reason
30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10
Reason
no dangerous workflow patterns detected
Reason
license file detected
Details
Reason
no binaries found in the repo
Reason
Found 7/16 approved changesets -- score normalized to 4
Reason
no effort to earn an OpenSSF best practices badge detected
Reason
detected GitHub workflow tokens with excessive permissions
Details
Reason
dependency not pinned by hash detected -- score normalized to 0
Details
Reason
security policy file not detected
Details
Reason
project is not fuzzed
Details
Reason
SAST tool is not run on all commits -- score normalized to 0
Details
Reason
16 existing vulnerabilities detected
Details
Score
Last Scanned on 2025-06-23
The Open Source Security Foundation is a cross-industry collaboration to improve the security of open source software (OSS). The Scorecard provides security health metrics for open source projects.
Learn More