React package for DocSearch, the best search experience for docs.
88%
Total Score
healthy
Active releases, strong repository activity, and organization backing make this a healthy release despite minor workflow and policy gaps.
No build attestation or staged publishing is reported, leaving publication provenance less independently verifiable despite a trusted publisher identity of circleci.
Nine runtime dependencies, including several substantial UI and AI-related packages, create a meaningful dependency surface, but the profile is consistent with this feature-rich React library.
Four of five publish-access accounts use the organization domain, consistent with the organization-backed project; 8bittitan uses gmail.com, which is a minor account-hygiene concern rather than evidence of limited maintenance capacity.
The repository has no published security policy, reducing transparency for vulnerability reporting and response procedures.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. Its one action reference is unpinned, a minor reproducibility and workflow supply-chain gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-681992 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @docsearch/react is vulnerable to Cross-Site Scripting (XSS) in versions 4.0.0 - 4.6.3. | 4.0.0 - 4.6.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
ai Version ^6.0.256 | — | — |
zod Version ^4.1.8 | — | — |
marked Version ^16.3.0 | — | — |
@ai-sdk/react Version ^3.0.259 | — | — |
algoliasearch Version ^5.28.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.