The package is actively released and its repository is clearly tied to the package, with organization backing. It still lacks any license file, has only a 14-character README, and all recent commits come from one contributor.
68%
Total Score
83
75
75
Neither the package nor the repository declares or contains a detectable license. That leaves the legal terms for using this SCSS dependency unclear.
A README is present but contains only 14 characters, providing almost no usage guidance; the absence of tests and a changelog is normal for a published SCSS artifact.
All 26 recent commits came from one contributor, creating a meaningful continuity risk; organization backing partly offsets this but no second active contributor is shown.
Composer is used as a build tool, but no security-scanning tooling is present. This is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, reducing clarity about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.