postcss-safe-parser 7.1.0 appears to be a healthy, established dependency: it has been maintained since 2015, is not deprecated or archived, has a stable release, MIT licensing, bundled type declarations, npm provenance, a matching organization-backed repository, repository tests and changelog coverage, and no install-time lifecycle scripts. The main reservations are that only one contributor made one commit in the last 3 months, the repository lacks security scanning and a security policy, and the release workflow does not declare top-level token permissions. These are meaningful hygiene and maintenance-capacity cautions, but they do not outweigh the package's long history, current release, repository-backed tests, and provenance.
82%
Total Score
75
100
94
80
100
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.