CSS parser
52%
Total Score
75
100
80
100
50
The latest release was published over 12 years ago, with no releases in the last 12 months; this materially raises abandonment and compatibility risk despite 16 historical releases.
No build attestation or trusted-publisher provenance is present, leaving publication origin less verifiable; this is a transparency limitation rather than evidence of unsafe code.
The repository recorded no commits and no active maintainers in the last three months, which weakens the evidence of ongoing maintenance despite the recent repository push timestamp.
The repository uses no build or security-scanning tools; for this small JavaScript package that is a minor hygiene gap, not a decisive health concern.
No type declarations are included, which is a minor integration gap for consumers using typed JavaScript tooling; the package is a small JavaScript parser and remains usable without them.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
css Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.