Webpack loader that resolves relative paths in url() statements based on the original source file
62%
Total Score
50
100
88
75
50
No build attestation or trusted-publisher provenance is present, reducing publication transparency. This is a supply-chain hygiene gap, but it is not evidence that the release is unsafe by itself.
Only one registry account has publish access, which creates a limited publishing base. The repository is also owned by that individual, so there is no organization backing shown to compensate for the narrow maintainer base.
The repository is owned by an individual user rather than an organization, so there is no observed organizational backing to offset the narrow maintainer base.
The package has 51 releases over more than 11 years, but its latest release was in December 2022 and there were no releases in the last 12 months. This indicates established maturity but substantial maintenance inactivity.
The repository recorded zero commits and zero active maintainers over the last three months. Combined with the old latest release, this materially raises the risk that fixes will not arrive promptly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
postcss Version ^8.2.14 | — | — |
source-map Version 0.6.1 | — | — |
loader-utils Version ^2.0.0 | — | — |
convert-source-map Version ^1.7.0 | — | — |
adjust-sourcemap-loader Version ^4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.