Calculate specificity of a CSS Selector
70%
Total Score
caution
No commits in the last three months and all 10 workflow actions are unpinned, despite a current release and matching repository.
No build attestation, trusted publisher, or staged publishing is reported, leaving release origin less independently verifiable.
The package includes prepack and prepublish lifecycle scripts. These are not install scripts, but they add build-time execution that deserves some supply-chain caution.
Only one registry account has publishing access. The repository is owned by the same individual, so this is not an ownership mismatch, but it still leaves a narrow publishing and maintenance base.
The registry namespace and repository owner match, but the backing is an individual user rather than an organization, so there is no wider organizational continuity signal.
The package is mature at about 4.6 years old with 26 releases and a recent release, but only one release occurred in the last 12 months, indicating a slower current cadence despite a historically short median interval.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
css-tree Version ^3.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.