Package Health

@docsearch/sidepanel-js

Strong release cadence and active organization-backed maintenance provide a solid foundation. Keep in mind the repository does not explicitly identify this package, and its workflow has one unpinned action.

Latest 5.1.2NPMNPM

84%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Are you affected? Scan for Free

Health Score Breakdown

Repo package mentioncaution

The repository name does not match the package name and its README does not mention @docsearch/sidepanel-js. Although this can occur in a monorepo, the package-to-repository link is less transparent.

Security policycaution

The repository has no security policy. This is a transparency and vulnerability-reporting gap, although active organization backing partly offsets the concern.

Workflow auditcaution

The single analyzed workflow had no dangerous triggers, untrusted checkouts, or audit findings, but its one action is unpinned. That leaves a modest reproducibility and action-integrity gap.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-269220 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
@docsearch/sidepanel-js is vulnerable to Cross-Site Scripting (XSS) in versions 4.4.0 - 4.6.3.
4.4.0 - 4.6.3
Medium

Package versions

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
12 hours ago
Created
9 months ago
Unpacked Size
6.4 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform