{"package":"manogi/nova-tiptap","ecosystem":"composer","latest_version":"v3.2.6","description":"A Laravel Nova tiptap editor field.","license":"MIT","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"","repository":"https://github.com/bastihilger/nova-tiptap","downloads_weekly":0,"health":{"score":5,"risk":"critical","breakdown":{"maintenance":5,"popularity":0,"security":15,"maturity":15,"community":0},"deprecated":true,"max_score":100},"vulnerabilities":{"count":1,"critical":1,"high":0,"medium":0,"low":0,"details":[{"vuln_id":"CVE-2025-54082","severity":"critical","summary":"nova-tiptap has Unauthenticated Arbitrary File Upload Vulnerability","affected_versions":"<5.7.0|<=3.2.6|=5.0.0|=5.1.0|=5.2.0|=5.2.1|=5.2.2|=5.3.0|=5.4.0|=5.5.0|=5.6.0|=0.0.1|=0.0.2|=0.1.0|=0.1.1|=0.2.0|=0.2.1|=0.2.2|=0.3.0|=0.3.1|=0.3.2|=0.3.3|=0.3.4|=0.3.5|=0.3.6|=0.3.7|=0.3.8|=0.3.9|=0.4.0|=0.5.0|=2.6.0|=v0.5.1|=v0.6.0|=v0.6.1|=v1.0|=v1.0.1|=v1.1.0|=v1.1.1|=v1.1.2|=v1.1.3|=v1.2.0|=v1.2.1|=v1.3.0|=v1.3.1|=v1.3.2|=v1.4.0|=v1.4.1|=v2.0-alpha|=v2.0-beta|=v2.0-beta-2|=v2.0-beta-3|=v2.0-beta-4|=v2.0.0|=v2.0.1|=v2.0.2|=v2.0.3|=v2.1.0|=v2.1.1|=v2.1.2|=v2.1.3|=v2.1.4|=v2.2.0|=v2.2.1|=v2.3.0|=v2.3.1|=v2.4.0|=v2.4.1|=v2.5.0|=v2.5.1|=v2.5.2|=v2.5.3|=v2.5.4|=v2.6.1|=v2.6.2|=v2.6.3|=v2.7.0|=v2.7.1|=v2.7.2|=v2.7.3|=v2.7.4|=v2.7.5|=v2.7.6|=v2.8.0|=v2.8.1|=v2.8.2|=v2.8.3|=v2.9.0|=v3.0.0|=v3.0.1|=v3.0.2|=v3.0.3|=v3.0.4|=v3.0.5|=v3.0.6|=v3.0.7|=v3.1.0|=v3.1.1|=v3.1.2|=v3.1.3|=v3.2.0|=v3.2.1|=v3.2.2|=v3.2.3|=v3.2.4|=v3.2.5|=v3.2.6","fixed_version":"5.7.0","source":"osv","published_at":"2025-07-21T19:09:21Z","in_kev":false,"epss_prob":0.01462,"epss_percentile":0.80933,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"v3.2.6","total_count":95,"recent":["v3.2.6","v3.2.5","v3.2.4","v3.2.3","v3.2.2","v3.2.1","v3.2.0","v3.1.3","v3.1.2","v3.1.1","v3.1.0","v3.0.7","v3.0.6","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.9.0"]},"metadata":{"deprecated":true,"deprecated_message":"https://github.com/marshmallow-packages/nova-tiptap","maintainers_count":0,"first_published":null,"last_published":"2024-06-27T14:40:30+00:00","dependencies_count":2,"dependencies":["php","laravel/nova"]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"do_not_use","issues":["Low health score (5/100)","Package is deprecated","1 critical vulnerabilities"],"use_version":"v3.2.6","version_hint":"Update to >= 5.7.0 to fix known vulnerabilities","summary":"manogi/nova-tiptap has critical vulnerabilities — do not use"},"version_scoped":null,"requested_version":null,"_cache":"hit","_response_ms":0,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":20,"first_release_age_days":null,"last_release_days_ago":670,"avg_days_between_releases":null,"release_velocity":"stale"}}