# postcss-selector-parser@7.1.4 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:28.000Z
- Files reviewed: 31
- Findings: no findings
- Report: https://security.togoder.click/npm/postcss-selector-parser@7.1.4
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package postcss-selector-parser@7.1.4 on Oct 6, 2026. An AI review of 31 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/index.js` (safe): The code is a standard TypeScript/CommonJS module wrapper that imports a local processor and selectors, assigns them to a parser function, and exports it without any malicious patterns.
- `dist/parser.js` (safe): No malicious patterns detected; this is a standard CSS selector parser with TypeScript helper boilerplate and no network, filesystem, process, credential, or dynamic-execution activity.
- `dist/processor.js` (safe): No malicious patterns detected; the code is a standard selector processor implementation with no network, filesystem, or dynamic execution activity.
- `dist/selectors/attribute.js` (safe): No malicious patterns detected; the file is a benign CSS attribute selector implementation with only standard imports (cssesc, unesc) and deprecation warnings.
- `dist/selectors/className.js` (safe): No malicious patterns detected; the file is a standard TypeScript-compiled PostCSS selector class definition using cssesc for safe escaping.
- `dist/selectors/combinator.js` (safe): No malicious patterns detected
- `dist/selectors/comment.js` (safe): No malicious patterns detected; the code is a standard TypeScript-compiled class definition for a Comment node with only local relative imports.
- `dist/selectors/constructors.js` (safe): No malicious patterns detected
- `dist/selectors/container.js` (safe): No malicious patterns detected; the code is a standard compiled TypeScript utility module (postcss-selector-parser Container class) with no network, filesystem, process, or dynamic execution behavior.
- `dist/selectors/guards.js` (safe): No malicious patterns detected; the code is a standard utility module for type-guarding CSS AST nodes.
- `dist/selectors/id.js` (safe): No malicious patterns detected
- `dist/selectors/index.js` (safe): No malicious patterns detected; this is a standard TypeScript-generated CommonJS barrel file that re-exports local modules without any suspicious behavior.
- `dist/selectors/namespace.js` (safe): No malicious patterns detected
- `dist/selectors/nesting.js` (safe): This is a standard TypeScript-compiled JavaScript file implementing a Nesting selector class with no malicious patterns detected.
- `dist/selectors/node.js` (safe): No malicious patterns detected; the code is a standard AST node implementation with recursion depth protection and no network, filesystem, process, or dynamic execution behavior.
- `dist/selectors/pseudo.js` (safe): No malicious patterns detected; this is a standard TypeScript-compiled JavaScript module implementing a pseudo-selector class with no network, filesystem, process, or dynamic code execution behavior.
- `dist/selectors/root.js` (safe): No malicious patterns detected in the provided JavaScript file; it is standard compiled TypeScript output for a CSS selector Root class.
- `dist/selectors/selector.js` (safe): No malicious patterns detected
- `dist/selectors/string.js` (safe): No malicious patterns detected; the file contains only standard TypeScript class extension boilerplate and a simple class definition.
- `dist/selectors/tag.js` (safe): No malicious patterns detected; the code is a standard TypeScript-compiled class definition with no network, filesystem, process, or dynamic execution behavior.
- `dist/selectors/types.js` (safe): No malicious patterns detected; the file only exports string constants for CSS selector token types.
- `dist/selectors/universal.js` (safe): No malicious patterns detected
- `dist/sortAscending.js` (safe): No malicious patterns detected
- `dist/tokenTypes.js` (safe): No malicious patterns detected; the file only exports character code constants with no executable or network activity.
- `dist/tokenize.js` (safe): This is a standard CSS tokenizer implementation with no malicious patterns, network activity, or suspicious behavior detected.
- `dist/util/ensureObject.js` (safe): No malicious patterns detected; the code is a simple utility for ensuring nested object properties exist.
- `dist/util/getProp.js` (safe): No malicious patterns detected
- `dist/util/index.js` (safe): No malicious patterns detected
- `dist/util/maxNestingDepth.js` (safe): No malicious patterns detected; the code is a simple input validation utility that safely coerces a nesting-depth limit.
- `dist/util/stripComments.js` (safe): No malicious patterns detected; the file only implements a simple comment-stripping utility with no network, filesystem, process, or dynamic execution behavior.
- `dist/util/unesc.js` (safe): No malicious patterns detected; the file contains a pure CSS escape sequence unescaping utility with no network, filesystem, process, or dynamic execution behavior.

## Version ranges

None of the 2 scanned versions of postcss-selector-parser are flagged high or critical. The latest scanned version, 7.1.6, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 7.1.6 (`7.1.6`): not scanned
- 7.1.4 (`7.1.4`): clean
- 6.1.2 – 7.1.0 (`>=6.1.2 <=7.1.0`): not scanned
- 6.0.10 (`6.0.10`): clean

## Scanned versions

- [7.1.4](https://security.togoder.click/npm/postcss-selector-parser@7.1.4): safe, 2026-10-06T14:23:28.000Z
- [6.0.10](https://security.togoder.click/npm/postcss-selector-parser@6.0.10): safe, 2026-10-06T14:12:28.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
