The tiniest and the fastest library for terminal output formatting with ANSI colors
68%
Total Score
63
90
80
50
No build provenance attestation or trusted publisher identity is available, reducing transparency about how the registry artifact was produced. This is a supply-chain transparency gap, but not by itself evidence that the package is unsafe.
Only one registry publishing account is listed, creating some concentration risk. The repository is user-owned rather than organization-owned, so the small maintainer base is less easily compensated by visible organizational backing.
The package has been published since September 2021 with nine releases, but its latest release was in October 2024 and there were no releases in the following 12 months. The long pause is a maintenance concern for a dependency, though the package is mature and intentionally small.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release pause. For a mature, narrowly scoped utility this may reflect stability, but it still increases abandonment risk if fixes become necessary.
There are eight open issues and nine open pull requests, but no issues or pull requests were opened or closed during the last month. The backlog and lack of recent resolution add a modest maintenance concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2024-10093 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. picocolors is vulnerable to Uncontrolled Recursion in versions 0.1.0 - 1.0.0. | 0.1.0 - 1.0.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.