Selector parser with built in methods for working with selector strings.
88%
Total Score
90
100
94
80
50
No build provenance attestation or trusted publisher identity is present, reducing publication traceability and reproducibility assurance.
A prepare lifecycle script runs during installation, adding some supply-chain and reproducibility surface; no provided signal shows that it is malicious or unusually complex, so this is a moderate hygiene concern.
One contributor made 15 of 19 recent commits, an 83.3% share, which creates concentration risk; the organization-backed repository and two additional active contributors partly compensate but do not eliminate it.
The repository uses TypeScript build tooling, but no security-scanning tools were detected, leaving a security-process gap despite the presence of a structured build.
The only workflow lacks a top-level permissions declaration, so its effective token permissions are less explicit than recommended; no workflow-level write permissions were detected.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-104844 New postcss-selector-parser is vulnerable to Uncontrolled Resource Consumption in versions 0.0.0 - 7.1.6. | 0.0.0 - 7.1.6 | Medium |
CVE-2026-9358 postcss-selector-parser is vulnerable to Improper Resource Shutdown or Release in versions 6.1.0 - 6.1.3 and 7.1.0 - 7.1.3. | 6.1.0 - 6.1.37.1.0 - 7.1.3 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
cssesc Version ^3.0.0 | — | — |
util-deprecate Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.