Mix any number of colors with the color-mix function in CSS
45%
Total Score
unhealthy
Risky: the package presents itself as PostCSS while being published by a different owner.
The name wraps the established `postcss` package name, and the README identifies itself with PostCSS. Although this may describe a legitimate plugin relationship, the supplied lookalike evidence makes package identity a serious adoption risk.
All 349 recent commits came from one contributor, leaving limited observable continuity if that person becomes unavailable. Organization backing helps with handoff potential, but no second recent contributor is shown.
The repository name does not match the package and its README does not mention the full package name, so package ownership is less transparent. The monorepo structure and organization backing partly explain this, but do not eliminate the gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@csstools/utilities Version ^3.0.0 | — | — |
@csstools/css-tokenizer Version ^4.0.2 | — | — |
@csstools/css-color-parser Version ^4.2.6 | — | — |
@csstools/css-parser-algorithms Version ^4.0.2 | — | — |
@csstools/postcss-progressive-custom-properties Version ^5.1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.