Clear licensing and a complete README make integration straightforward. Organization backing and a matching repository add useful transparency, while the lack of a security policy leaves a smaller assurance gap.
67%
Total Score
67
93
75
The package has 27 releases and historically released about every 6 days, but it has made no registry release in the last 12 months and its latest release is about 18 months old. That suggests a meaningful slowdown, though the established history reduces abandonment concern.
The repository recorded no commits and no active maintainers in the last 3 months. The repository was pushed more recently than that, which softens the concern but does not show ongoing development.
Issue and pull-request activity is currently light: 1 new issue and 2 new pull requests in the last month, with none closed or merged. This is a maintenance concern, although it is not evidence of an abandoned repository by itself.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear. This is a transparency gap, but it is less significant for a CSS-only package than for software handling sensitive data.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.