Compact binary encoding for geographic data
68%
Total Score
67
92
75
The repository recorded zero commits and zero active maintainers in the last three months. A recent release partly offsets this, but the lack of current development activity lowers maintenance confidence.
There were no new or closed issues and no merged pull requests in the last month, with 32 issues still open. This suggests limited recent project movement, though it is not evidence of abandonment by itself.
The project uses npm scripts and Rolldown for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk on its own.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, both of its two action references are unpinned, leaving a modest dependency-integrity hygiene gap.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-400467 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. geobuf is vulnerable to Prototype Pollution in versions 1.0.0 - 3.0.2. | 1.0.0 - 3.0.2 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
pbf Version ^4.0.1 | — | — |
shapefile Version ~0.6.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.