postcss-svgo 9.0.2 appears to be a healthy, actively maintained release with a long history, frequent recent releases, stable versioning, current repository activity, build provenance, and strong repository hygiene. The linked cssnano organization repository provides substantial backing, tests and changelog coverage even though those are not packaged, and secure workflow configuration. The main concern is that the linked repository neither matches the package name nor mentions it in its README, which leaves some uncertainty about the package-to-repository relationship; however, the repository's monorepo structure and organization ownership partially mitigate that concern.
88%
Total Score
100
100
95
100
100
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
svgo Version ^4.1.0 | — | — |
postcss-value-parser Version ^4.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.