Type declarations, no install-time scripts, and a small runtime dependency surface make integration straightforward. The repository also has tests, a changelog, build tooling, and security scanning; its missing security policy and one unpinned workflow action are minor hygiene gaps.
92%
Total Score
90
100
100
67
Four of five registry publishers use the algolia.com domain, consistent with organization-backed publishing. The consumer account 8bittitan (gmail.com) is an account-hygiene caution, but it does not indicate limited maintenance capacity.
The repository has no security policy file, leaving vulnerability-reporting and response expectations undocumented; this is a transparency gap, not evidence of unsafe code.
The single workflow was fully analyzed with no audit findings or untrusted execution paths. Its one action use is unpinned, a minor reproducibility and supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-460419 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @docsearch/js is vulnerable to Cross-Site Scripting (XSS) in versions 4.0.0 - 4.6.3. | 4.0.0 - 4.6.3 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.