@ctrl/tinycolor
npmv4.2.0Fast, small color manipulation and conversion for JavaScript
License MITpermissive49 versions1 maintainers0 deps
scttcper/tinycolor51
/ 100
Health
do not use
Do not install. Package is flagged as malicious (advisory MAL-2025-47141).
Health breakdown0 – 100
10/25
maintenance
0/20
popularity
25/25
security
12/15
maturity
4/15
community
Vulnerabilities
0
none known
Bundle & TypeScript
📦
Bundle Size
17.0 KBminified
6.3 KB gzipped
0 direct dependencies
ESMscoped
🌟
TypeScript
10/10typed
bundled
⚠ Malicious package
This package is flagged as malicious by the OpenSSF/OSV community feed. Do not install.
Advisory:
MAL-2025-47141 — Malicious code in @ctrl/tinycolor (npm)Health History
Dependency Tree
License Audit
API access
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@ctrl/tinycolorFirst published · 2018-04-30T06:54:02.621Z
Last updated · 2025-09-16T03:17:48.101Z