@wordpress/postcss-themesnpm
- latest 6.55.0
- licence GPL-2.0-or-later
- stars 11,754
- checked today
- registry ↗
- repository ↗
Vulnerabilities, end of life and next steps
Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.
Review remediation options →Maintenance trends
Loading historical repository activity…
Signals · last 1 check
The first observation is recorded. Trend lines appear once at least two checks have data for the same signal.
Commits 90d
100
Open issues
4509
Unanswered
792
Contributors
39
What the project says about itself
- Build provenance — the latest release carries no provenance attestation. Source: the registry.
- Supported runtime — node >=18.12.0. Source: the registry.
- Publishers on the registry — 25. Source: the registry.
- Security policy — published. Source: the repository.
- Open milestones — 22.8 2/2 done; Gutenberg 21.8 (due 2025-10-08) 121/121 done; Gutenberg 21.9 (due 2025-10-22) 282/282 done; Gutenberg 22.9 (due 2026-03-29) 131/131 done; Gutenberg 23.0 (due 2026-04-11) 177/177 done. Source: the repository's milestones.
- OpenSSF Scorecard — 6.7 / 10 on 2026-08-24. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.
Third-party facts checked today; registry facts on every crawl.
State history 1
| When | Change |
|---|---|
| 2026-09-14 | first verdict: active |
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/npm/@wordpress/postcss-themes)
Watch it
Get told when @wordpress/postcss-themes changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.