
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
tailwind-morph
Advanced tools
Affected versions:
[![Build status][build-image]][build-url] [![Tests coverage][cov-image]][cov-url] [![npm version][npm-image]][npm-url]
tailwind-morph is a modern Tailwind CSS theme preset designed for teams building
consistent, scalable, and brand-ready design systems.
It provides a structured token architecture, systemized design primitives, and flexible extension patterns — perfect for multi-product UI ecosystems, component libraries, and evolving brand platforms.
🎨 Semantic Theme Tokens
Organized palettes, typography scales, spacing, radii, shadows, and sizing tokens for predictable and consistent UI.
🧱 Design-System Foundations
Token-first architecture ideal for scalable design systems and custom component libraries.
🔌 Preset & Plugin Compatible
Seamlessly integrates with Tailwind presets, plugins, and layered configuration setups.
⚙️ Effortless Customization
Extend or override tokens directly from your tailwind.config.js.
🪶 Zero Runtime Dependencies
Pure Tailwind configuration — no runtime JavaScript shipped to the client.
npm install tailwind-morph --save-dev
FAQs
tailwind-morph
The npm package tailwind-morph receives a total of 0 weekly downloads. As such, tailwind-morph popularity was classified as not popular.
We found that tailwind-morph demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.