buffer operations
60%
Total Score
50
100
88
75
The registry lists one publishing maintainer, and the repository is owned by a user rather than an organization. That leaves limited visible maintainer capacity if the project needs updates.
The repository is owned by an individual account, with no organization backing shown. This provides less visible continuity assurance than an organization-backed project.
The package has 11 releases but none in the last 12 months; its latest release was over six years ago. This strongly suggests maintenance has stopped, although the stable 1.0.1 release may still suit unchanged use cases.
There were zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release. This raises the risk that compatibility or security issues will not be addressed promptly.
The repository reports no build tooling and no security scanning tools. This is a meaningful maintenance and review gap for a library, though the package's tests provide some compensating evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
to-utf8 Version 0.0.1 | — | — |
base64-js Version 1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.