@vue/server-renderer
91%
Total Score
100
100
89
90
100
The repository name does not match the package name and its README does not mention this package, creating a package-to-repository transparency concern. The organization-owned monorepo context makes a subpackage layout plausible, but the collected signal does not explicitly establish that mapping.
The project uses established build, test, and compilation tooling, supporting a mature build process; no automated security scanning was detected, which is a modest transparency gap but not severe given the other controls.
Four workflows declare read-only permissions, but the release workflow lacks top-level permissions and four workflows request top-level write access; this leaves some workflow privilege configuration less explicit than ideal.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-283182 @vue/server-renderer is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 3.5.41. | 0.0.1 - 3.5.41 | High |
AIKIDO-2026-135497 @vue/server-renderer is vulnerable to Cross-Site Scripting (XSS) in versions 3.0.0 - 3.5.39. | 3.0.0 - 3.5.39 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
@vue/shared Version 3.5.43 | — | — |
@vue/runtime-dom Version 3.5.43 | — | — |
@vue/compiler-ssr Version 3.5.43 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.