Color conversion and manipulation with CSS string support
70%
Total Score
50
100
95
75
50
No build attestation or trusted-publisher provenance is available, limiting publication transparency; this is a caution rather than a standalone dependency blocker.
One registry publishing account creates a thin operational base. The repository is user-owned rather than organization-owned, so there is no provided organizational backing to compensate for that concentration.
The source repository is owned by an individual account, so the available evidence shows limited formal backing rather than organization-level stewardship.
No commits and no active maintainers were recorded in the last three months, a meaningful sign that maintenance may have slowed or stopped.
There were no new or closed issues or pull requests in the last month, leaving open work without evidence of recent triage.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-59143 color is vulnerable to Embedded Malicious Code in versions 5.0.1 - 5.0.1. | 5.0.1 - 5.0.1 | High |
| Dependency | Last Release | Score |
|---|---|---|
color-string Version ^2.1.3 | — | — |
color-convert Version ^3.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.