CLI for PostCSS
84%
Total Score
90
100
95
80
50
The release has no attestation, trusted publisher identity, or staged-publishing provenance, leaving the artifact-to-source supply-chain link less transparent.
Recent activity is highly concentrated: the top contributor made 17 of 18 commits, or about 94%, with only one other contributor active. Organization backing partially mitigates handoff risk, but the concentration remains a genuine caution.
The repository reports no build tool and no security-scanning tools. This is a maintenance and assurance gap, although the project is a relatively focused CLI repository.
No security policy was found, reducing transparency around vulnerability reporting and response expectations.
The only workflow lacks top-level token permissions, so its permissions are not explicitly constrained at workflow scope; no top-level write permission was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slash Version ^5.0.0 | — | — |
yargs Version ^18.0.0 | — | — |
chokidar Version ^5.0.0 | — | — |
picocolors Version ^1.0.0 | — | — |
read-cache Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.