
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@matrajs/core
Advanced tools
A headless rich text editor framework with a first-class extension API. Zero dependencies.
A headless rich text editor framework. Engine, document model, extension API and starter kit — framework-agnostic and MIT.
npm i @matrajs/core
import { createEditor, starterKit } from '@matrajs/core'
const editor = createEditor({ extensions: starterKit, content: '<p>Hello</p>' })
editor.mount(element)
editor.commands.toggleHeading(2)
Commands are inferred. editor.commands is built from the definitions you
pass — no module augmentation, no registry, no generics to thread. Calling a
command no extension defines is a compile error.
The engine stays hidden. The document is plain JSON and no engine type
appears in a public signature. editor.unsafe is the escape hatch and is
excluded from semver.
Positions survive time. ctx.mark() returns a marker that re-resolves a
range through every edit made since it was taken — the reason a three-second-late
AI response lands on the right words instead of corrupting the paragraph.
@matrajs/react — useEditor, useEditorState, EditorContent
@matrajs/ai — streaming edits that survive concurrent typing
Docs: https://matrajs.com
MIT.
FAQs
A headless rich text editor framework with a first-class extension API. Zero dependencies.
The npm package @matrajs/core receives a total of 67 weekly downloads. As such, @matrajs/core popularity was classified as not popular.
We found that @matrajs/core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.