A general purpose buffer pool.
70%
Total Score
83
100
81
83
The package has had no registry release in roughly 9 years, with the latest release on January 25, 2017. Active repository work partly compensates for package-level release staleness, but the published artifact is still old.
One contributor made about 76% of recent commits, creating concentration risk, though seven other contributors were active during the same period.
The linked repository name does not match the package and its README does not mention @protobufjs/pool, so the package-to-repository relationship is not clearly demonstrated. The mismatch may reflect a monorepo, but the missing README mention remains a transparency concern.
The project uses TypeScript, npm scripts, and Gulp, but no security scanning tools were detected. This is a modest process gap rather than evidence of abandonment.
All 12 analyzed action references are unpinned, and the release workflow has top-level write permissions. The audit also found high-confidence lockfile-bypassing installs; the cache-poisoning finding is low confidence, so it is hygiene rather than a severe conclusion.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.