CSS selector engine supporting jQuery selectors
61%
Total Score
83
100
94
63
50
No build attestation or trusted-publisher provenance is present, so consumers cannot verify how the published artifact was produced.
A prepare install-time script is present. This is a modest supply-chain and installation-complexity concern, though the repository shows a conventional TypeScript build setup.
The package has a long history and 12 releases, but its latest registry release was in May 2022 with no releases in the last 12 months, which raises maintenance and freshness concerns.
There were no commits and no active maintainers in the measured three-month window, a maintenance warning that is partly offset by recent pull-request merges and repository activity.
No repository security policy was found, leaving vulnerability-reporting guidance undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
boolbase Version ^1.0.0 | — | — |
css-what Version ^6.1.0 | — | — |
domutils Version ^3.0.1 | — | — |
css-select Version ^5.1.0 | — | — |
domhandler Version ^5.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.