A modern CSS parser and stringifier with TypeScript support
65%
Total Score
83
100
94
88
The package is mature at over four years old with 22 releases and a latest release within the measured period, but only one release occurred in the last 12 months.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance warning even though other signals show recent release and pull-request activity.
All four workflows were analyzed, with no untrusted checkout or script-injection findings, but all seven action references are unpinned and high-confidence bot-condition findings affect two automation workflows; one also grants top-level write permissions.
| Title | Versions | Severity |
|---|---|---|
CVE-2023-48631 @adobe/css-tools is vulnerable to Improper Input Validation in versions 0.0.0 - 4.3.2. | 0.0.0 - 4.3.2 | Medium |
CVE-2023-26364 @adobe/css-tools is vulnerable to Improper Input Validation in versions 0.0.0 - 4.3.1. | 0.0.0 - 4.3.1 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.