This is a healthy, actively maintained release with a stable version, regular release cadence, a non-deprecated registry entry, clear licensing, bundled type declarations, a documented package, and a well-backed organization-owned repository. Repository activity is strong, with 241 commits in the last 3 months, recent issue and pull-request throughput, security tooling, and a security policy. The main concerns are that all recent commits came from one contributor, the linked monorepo does not match or explicitly mention this package, and the release has no build provenance attestation; these reduce transparency and resilience but are partly mitigated by the organization backing and active project infrastructure.
82%
Total Score
88
100
94
80
50
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@csstools/utilities Version ^3.0.0 | — | — |
@csstools/css-tokenizer Version ^4.0.0 | — | — |
@csstools/css-parser-algorithms Version ^4.0.0 | — | — |
@csstools/postcss-progressive-custom-properties Version ^5.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.