Summary
Togoder Security scanned the npm package postcss-selector-parser@7.1.4 on Oct 6, 2026. An AI review of 31 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.js | safe | The code is a standard TypeScript/CommonJS module wrapper that imports a local processor and selectors, assigns them to a parser function, and exports it without any malicious patterns. |
| dist/parser.js | safe | No malicious patterns detected; this is a standard CSS selector parser with TypeScript helper boilerplate and no network, filesystem, process, credential, or dynamic-execution activity. |
| dist/processor.js | safe | No malicious patterns detected; the code is a standard selector processor implementation with no network, filesystem, or dynamic execution activity. |
| dist/selectors/attribute.js | safe | No malicious patterns detected; the file is a benign CSS attribute selector implementation with only standard imports (cssesc, unesc) and deprecation warnings. |
| dist/selectors/className.js | safe | No malicious patterns detected; the file is a standard TypeScript-compiled PostCSS selector class definition using cssesc for safe escaping. |
| dist/selectors/combinator.js | safe | No malicious patterns detected |
| dist/selectors/comment.js | safe | No malicious patterns detected; the code is a standard TypeScript-compiled class definition for a Comment node with only local relative imports. |
| dist/selectors/constructors.js | safe | No malicious patterns detected |
| dist/selectors/container.js | safe | No malicious patterns detected; the code is a standard compiled TypeScript utility module (postcss-selector-parser Container class) with no network, filesystem, process, or dynamic execution behavior. |
| dist/selectors/guards.js | safe | No malicious patterns detected; the code is a standard utility module for type-guarding CSS AST nodes. |
| dist/selectors/id.js | safe | No malicious patterns detected |
| dist/selectors/index.js | safe | No malicious patterns detected; this is a standard TypeScript-generated CommonJS barrel file that re-exports local modules without any suspicious behavior. |
| dist/selectors/namespace.js | safe | No malicious patterns detected |
| dist/selectors/nesting.js | safe | This is a standard TypeScript-compiled JavaScript file implementing a Nesting selector class with no malicious patterns detected. |
| dist/selectors/node.js | safe | No malicious patterns detected; the code is a standard AST node implementation with recursion depth protection and no network, filesystem, process, or dynamic execution behavior. |
| dist/selectors/pseudo.js | safe | No malicious patterns detected; this is a standard TypeScript-compiled JavaScript module implementing a pseudo-selector class with no network, filesystem, process, or dynamic code execution behavior. |
| dist/selectors/root.js | safe | No malicious patterns detected in the provided JavaScript file; it is standard compiled TypeScript output for a CSS selector Root class. |
| dist/selectors/selector.js | safe | No malicious patterns detected |
| dist/selectors/string.js | safe | No malicious patterns detected; the file contains only standard TypeScript class extension boilerplate and a simple class definition. |
| dist/selectors/tag.js | safe | No malicious patterns detected; the code is a standard TypeScript-compiled class definition with no network, filesystem, process, or dynamic execution behavior. |
| dist/selectors/types.js | safe | No malicious patterns detected; the file only exports string constants for CSS selector token types. |
| dist/selectors/universal.js | safe | No malicious patterns detected |
| dist/sortAscending.js | safe | No malicious patterns detected |
| dist/tokenTypes.js | safe | No malicious patterns detected; the file only exports character code constants with no executable or network activity. |
| dist/tokenize.js | safe | This is a standard CSS tokenizer implementation with no malicious patterns, network activity, or suspicious behavior detected. |
Show 6 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/util/ensureObject.js | safe | No malicious patterns detected; the code is a simple utility for ensuring nested object properties exist. |
| dist/util/getProp.js | safe | No malicious patterns detected |
| dist/util/index.js | safe | No malicious patterns detected |
| dist/util/maxNestingDepth.js | safe | No malicious patterns detected; the code is a simple input validation utility that safely coerces a nesting-depth limit. |
| dist/util/stripComments.js | safe | No malicious patterns detected; the file only implements a simple comment-stripping utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/util/unesc.js | safe | No malicious patterns detected; the file contains a pure CSS escape sequence unescaping utility with no network, filesystem, process, or dynamic execution behavior. |
Affected version ranges
None of the 2 scanned versions of postcss-selector-parser are flagged high or critical. The latest scanned version, 7.1.6, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 7.1.6 | Not scanned | 1 | 7.1.6 | |
| 7.1.4 | No issues | 1 | 7.1.4 | |
| 6.1.2 โ 7.1.0 | Not scanned | 3 | >=6.1.2 <=7.1.0 | |
| 6.0.10 | No issues | 1 | 6.0.10 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of postcss-selector-parser
Frequently asked questions
Is postcss-selector-parser safe to use?
Our AI source review of postcss-selector-parser@7.1.4 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does postcss-selector-parser contain malware?
No malware was identified in postcss-selector-parser@7.1.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was postcss-selector-parser checked?
Togoder Security downloaded the published npm package and had an AI model read its 31 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan postcss-selector-parser together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in postcss-selector-parser@7.1.4, cost nothing.