Strong release cadence and active organization-backed maintenance provide a solid foundation. Keep in mind the repository does not explicitly identify this package, and its workflow has one unpinned action.
84%
Total Score
100
100
93
67
The repository name does not match the package name and its README does not mention @docsearch/sidepanel-js. Although this can occur in a monorepo, the package-to-repository link is less transparent.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although active organization backing partly offsets the concern.
The single analyzed workflow had no dangerous triggers, untrusted checkouts, or audit findings, but its one action is unpinned. That leaves a modest reproducibility and action-integrity gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-269220 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @docsearch/sidepanel-js is vulnerable to Cross-Site Scripting (XSS) in versions 4.4.0 - 4.6.3. | 4.4.0 - 4.6.3 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.