CSS color - Resolve and convert CSS colors.
83%
Total Score
healthy
Frequent releases and active commits support it, but nearly all recent commits come from one contributor.
The release has no registry build attestation or trusted-publisher provenance. This limits verification of how the artifact was produced, though it is not evidence of maliciousness by itself.
Only one registry account has publish access, matching the single-user repository ownership and increasing publishing continuity risk. Recent repository activity provides some compensation but not a second publishing path.
One contributor made 74 of 77 commits, or about 96%, in the last three months. The other three contributors made only one commit each, leaving meaningful single-maintainer continuity risk.
All workflows were analyzed successfully, one workflow uses read-only permissions, and no injection, unsafe checkout, or audit findings were reported. Both of the two action references are unpinned, which is a modest reproducibility and supply-chain hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-199800 @asamuzakjp/css-color is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 7.0.0. | 0.0.1 - 7.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
lru-cache Version ^11.5.3 | — | — |
@csstools/css-calc Version ^3.4.3 | — | — |
@csstools/css-tokenizer Version ^4.0.2 | — | — |
@csstools/css-color-parser Version ^4.2.6 | — | — |
@csstools/css-parser-algorithms Version ^4.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.