Log PostCSS messages in the console
58%
Total Score
75
83
50
The package has 28 releases over more than 11 years, but none in the last 12 months and no release since January 2024. This materially raises maintenance and abandonment concerns.
The repository recorded no commits and no active maintainers in the last 3 months. Although the repository was pushed recently, the observed commit activity still indicates limited active development.
The repository has no security policy. This is a transparency and reporting gap, though it is less serious than the observed maintenance slowdown.
The workflow audit was complete and found no dangerous sinks or high-severity issues, with read-only job permissions. However, all 9 action references are unpinned, leaving avoidable build-integrity and update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thenby Version ^1.3.4 | — | — |
picocolors Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.