Use the parts of normalize.css or sanitize.css you need from your browserslist
68%
Total Score
67
100
88
100
50
No build attestation or trusted-publisher provenance is available, leaving publication origin less verifiable. This is a transparency weakness but not evidence that the release is unsafe by itself.
The package has 24 releases over more than 11 years, but none in the last 12 months and the latest release was nearly two years ago. This indicates materially slowed publishing and raises maintenance concerns.
There were no commits and no active maintainers in the past three months, a meaningful sign of slowed maintenance. The repository's push about six months ago prevents this from being treated as clear abandonment.
There are only three open issues and no recent issue or pull-request activity. This is consistent with a quiet, mature project, but provides little evidence of current responsiveness.
The repository uses build tooling, but no security-scanning tools were detected. The missing scanning layer is a modest maintenance and hygiene gap, partly offset by the repository's other controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sanitize.css Version 13.0.0 | — | — |
@csstools/normalize.css Version 12.1.1 | — | — |
postcss-browser-comments Version ^6.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.