color-string
npmv2.1.4Parser and generator for CSS color strings
License MITpermissive42 versions1 maintainers1 deps
Qix-/color-string59
/ 100
Health
do not use
Do not install. Package is flagged as malicious (advisory MAL-2025-46973).
Health breakdown0 – 100
15/25
maintenance
0/20
popularity
25/25
security
15/15
maturity
4/15
community
Vulnerabilities
0
none known
Bundle & TypeScript
📦
Bundle Size
6.8 KBminified
2.5 KB gzipped
1 direct dependencies
side effects
🌟
TypeScript
10/10typed
bundled
⚠ Malicious package
This package is flagged as malicious by the OpenSSF/OSV community feed. Do not install.
Advisory:
MAL-2025-46973 — Malicious code in color-string (npm)Quality signals
OSS Criticality
0.75critical
Download trend
stable(+3.9%)
Publish security
npm signed
Health History
Dependency Tree
License Audit
Dependencies (1)
API access
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/color-stringFirst published · 2011-06-19T19:01:39.871Z
Last updated · 2025-11-15T16:35:04.631Z