👑 A tiny yet powerful tool for high-performance color manipulations and conversions
88%
Total Score
70
100
95
83
50
The release has no attestation or staged-publishing provenance, leaving the build-to-artifact path less transparent than it could be.
Only one registry account has publish access. This is a continuity concern, although active repository work shows the project is currently maintained.
The repository is owned by an individual rather than an organization, so the concentrated contributor activity and single registry publisher leave less evident handoff capacity.
One contributor made 14 of 17 recent commits, concentrating maintenance heavily in one person despite three additional contributors remaining active.
The project uses TypeScript, Rollup, and npm scripts, but no security-scanning tools were detected. The build tooling is appropriate, while security automation is a minor hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-662826 colord is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.0.1 - 2.9.3. | 0.0.1 - 2.9.3 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.