The source repository is intact and includes tests, a clear README, and an MIT license. However, the release is old, commit activity has stopped, and the registry marks the package abandoned in favor of pickles2/px2-scss.
20%
Total Score
50
75
Packagist marks the entire package as abandoned and provides pickles2/px2-scss as a replacement, which is a severe dependency risk despite the repository still being available.
The latest release was in January 2025, with no releases in the last 12 months and a long median interval between releases, indicating limited ongoing publishing activity.
The repository recorded no commits and no active maintainers in the last three months, so there is no recent evidence of maintenance after the latest release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scssphp/scssphp Version ^1.4||^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.