
Security News
CVE Volume Surges Past 48,000 in 2025 as WordPress Plugin Ecosystem Drives Growth
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.
@metalsmith/postcss
Advanced tools
A Metalsmith plugin that sends your CSS through any PostCSS plugins.
A Metalsmith plugin that sends your CSS through any PostCSS plugins.
NPM:
npm install @metalsmith/postcss
Yarn:
yarn add @metalsmith/postcss
Note: you need to install postcss and postcss plugins separately
Add the postcss package name, optionally with its options, to your .use() directives.
Here is an example using postcss-pseudoelements and postcss-nested to transform your source files:
import postcss from '@metalsmith/postcss';
// defaults with 2 plugins:
metalsmith.use(postcss({ plugins: {
'postcss-pseudoelements': {}
'postcss-nested': {}
}}))
// explicit defaults with 2 plugins:
metalsmith.use(postcss({
pattern: '**/*.css',
plugins: {
'postcss-pseudoelements': {}
'postcss-nested': {}
},
map: false
}));
{string|string[]} (optional) - Pattern of CSS files to match relative to Metalsmith.source(). Defaults to **/*.css{Object|Array<Object|string>} (optional) - An object with PostCSS plugin names as keys and their options as values, or an array of PostCSS plugins as names, eg 'postcss-plugin'or objects in the format { 'postcss-plugin': {...options}}*(optional)* - Passtruefor inline sourcemaps, or{ inline: false }` for external source maps{string} (optional) - Module name of a PostCSS Syntax or a syntax object itself. Can also be a custom syntax or a relative module path.By default, files with .css extension will be parsed. This may be overridden
by providing a custom pattern e.g.
metalsmith.use(postcss({
pattern: '*.postcss',
plugins: { ... }
}));
Sometimes plugins need to be defined in a certain order and JavaScript Objects cannot guarantee the order of keys in an object. You can also specify PostCSS plugins using an array of objects:
metalsmith.use(
postcss({
pattern: '*.postcss',
plugins: ['postcss-pseudoelements', { 'postcss-nested': { some: 'config' } }]
})
)
This plugin supports generating source maps. To do so, pass map: true for inline source maps (written into the CSS file), or map: { inline: false } for external source maps (written as file.css.map):
metalsmith.use(
postcss({
plugins: {},
map: true // same as { inline: false }
})
)
Example config for external source maps
metalsmith.use(
postcss({
plugins: {},
map: {
inline: false
}
})
)
Source maps generation is compatible with @metalsmith/sass and will find correct file paths from .scss source all the way through the last PostCSS transforms:
metalsmith
.use(
sass({
entries: {
'src/index.scss': 'index.css'
}
})
)
.use(
postcss({
map: true
})
)
To use this plugin with the Metalsmith CLI, add @metalsmith/postcss to the plugins key in your metalsmith.json file:
Here is an example using postcss-pseudoelements and postcss-nested to transform your source files.
{
"plugins": [
{
"@metalsmith/postcss": {
"plugins": {
"postcss-pseudoelements": {},
"postcss-nested": {}
},
"map": true
}
}
]
}
Thanks to AXA Switzerland for developing the initial versions of this plugin on which this plugin is based.
To run the tests use:
npm test
To view end-to-end tests in browser, use:
npm run test:e2e
FAQs
A Metalsmith plugin that sends your CSS through any PostCSS plugins.
We found that @metalsmith/postcss demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
CVE disclosures hit a record 48,185 in 2025, driven largely by vulnerabilities in third-party WordPress plugins.

Security News
Socket CEO Feross Aboukhadijeh joins Insecure Agents to discuss CVE remediation and why supply chain attacks require a different security approach.

Security News
Tailwind Labs laid off 75% of its engineering team after revenue dropped 80%, as LLMs redirect traffic away from documentation where developers discover paid products.