The package includes bundled typings, a license, release notes, and a repository with tests and a changelog. GitHub workflows use all nine actions without pinned references, and the linked repository neither matches the package name nor mentions it in its README.
78%
Total Score
75
50
90
67
The package declares 17 runtime dependencies and 14 development dependencies. This is a substantial dependency surface, but the signal provides no indication of abnormal or unmanaged dependencies.
The repository is owned by the user account fuma-nama rather than an organization, so the single registry maintainer does not benefit from visible organization backing.
The repository name does not match fumadocs-openapi and its README does not mention the package, so the linkage is less transparent and the package's source ownership is harder to verify.
The repository uses TypeScript, Vitest, Turbo, Vite, and npm scripts, showing established build and test tooling. No security scanning tools were detected, which leaves a modest hygiene gap.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-389326 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. fumadocs-openapi is vulnerable to Server-Side Request Forgery (SSRF) in versions 5.10.0 - 11.2.1. | 5.10.0 - 11.2.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
cn Version ^0.3.0 | — | — |
yaml Version ^2.9.1 | — | — |
shiki Version ^4.4.3 | — | — |
remark Version ^15.0.1 | — | — |
chokidar Version ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.