WebSocket buffer utils
78%
Total Score
83
100
94
63
An install lifecycle script can execute build-related code during dependency installation, adding some supply-chain exposure even though this is consistent with a native addon.
All four recent commits came from one contributor, creating concentration risk. The organization-owned repository provides some capacity to hand maintenance off, so this is a moderate concern rather than a severe one.
The project uses a build tool, but no security-scanning tools were detected. That is a transparency and hygiene gap, not evidence of unsafe code by itself.
No repository security policy was found, reducing guidance for reporting and handling vulnerabilities.
The workflow audit completed cleanly, uses read-only permissions, and has no untrusted checkouts or script injections. However, all eight action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
node-gyp-build Version ^4.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.