This is a healthy, actively maintained release from an organization-backed project: it has a stable version, a long release history, recent publication, an unarchived repository with substantial recent commit and pull-request activity, documented licensing, bundled types, repository tests, security scanning, and a security policy. The main concerns are that all 241 recent repository commits came from one contributor, the package has no build provenance attestation, and the linked monorepo neither matches the package name nor mentions it in its README, which modestly reduces transparency and raises continuity risk. The small six-file artifact is appropriate for a compiled PostCSS plugin, and the absence of packaged tests is compensated by repository tests.
82%
Total Score
90
100
95
80
50
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@csstools/utilities Version ^3.0.0 | — | — |
@csstools/css-tokenizer Version ^4.0.0 | — | — |
@csstools/postcss-progressive-custom-properties Version ^5.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.