Package Health

picocolors

The tiniest and the fastest library for terminal output formatting with ANSI colors

Latest 1.1.1NPMNPM

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

90

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

80

Attestations
Attestations
Measures the presence and validity of package attestations and signatures

50

Are you affected? Scan for Free

Health Score Breakdown

Build provenancecaution

No build provenance attestation or trusted publisher identity is available, reducing transparency about how the registry artifact was produced. This is a supply-chain transparency gap, but not by itself evidence that the package is unsafe.

Maintainerscaution

Only one registry publishing account is listed, creating some concentration risk. The repository is user-owned rather than organization-owned, so the small maintainer base is less easily compensated by visible organizational backing.

Release historycaution

The package has been published since September 2021 with nine releases, but its latest release was in October 2024 and there were no releases in the following 12 months. The long pause is a maintenance concern for a dependency, though the package is mature and intentionally small.

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release pause. For a mature, narrowly scoped utility this may reflect stability, but it still increases abandonment risk if fixes become necessary.

Repo issue activitycaution

There are eight open issues and nine open pull requests, but no issues or pull requests were opened or closed during the last month. The backlog and lack of recent resolution add a modest maintenance concern.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2024-10093 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
picocolors is vulnerable to Uncontrolled Recursion in versions 0.1.0 - 1.0.0.
0.1.0 - 1.0.0
Low

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
1 year ago
Created
5 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform