Style once, use everywhere. A build system for creating cross-platform styles.
88%
Total Score
healthy
Frequent releases and active contributors support this package; unpinned workflow actions and missing security policy are the main concerns.
A prepare script runs during installation, adding install-time behavior that deserves review even though the signal does not show malicious behavior.
The repository uses established build tools, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
No repository security policy was found, reducing clarity about vulnerability reporting and response expectations.
Both workflows were audited successfully with no reported findings or untrusted checkout and injection sinks, but all seven action references are unpinned and one workflow has top-level write permissions; without an untrusted trigger, this is workflow hygiene rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-580810 style-dictionary is vulnerable to Prototype Pollution in versions 5.5.0 - 5.5.0. | 5.5.0 - 5.5.0 | High |
CVE-2026-54639 style-dictionary is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 4.3.0 - 5.4.4. | 4.3.0 - 5.4.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
chalk Version ^5.3.0 | — | — |
json5 Version ^2.2.2 | — | — |
prettier Version ^3.3.3 | — | — |
commander Version ^12.1.0 | — | — |
colorjs.io Version ^0.5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.