Zero dependency streaming tar parser and writer for JavaScript.
82%
Total Score
75
100
89
88
100
The linked repository is owned by a user rather than an organization, so no organizational maintenance handoff or backing should be assumed.
One contributor produced 100% of the 53 commits during the last three months, creating a genuine single-maintainer continuity risk; the repository is user-owned rather than organization-owned, so there is no project-backing compensation shown.
The repository uses TypeScript and Vitest build tooling, but no security-scanning tools were detected; this is a security-hygiene gap rather than evidence of abandonment.
No security policy was found in the repository, leaving vulnerability-reporting and response expectations undocumented.
The release is not a prerelease, but version 0.8.5 remains before a stable 1.0 major, so API and compatibility maturity are somewhat less established.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-386051 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. modern-tar is vulnerable to Path Traversal in versions 0.0.0 - 0.7.6. | 0.0.0 - 0.7.6 | High |
AIKIDO-2026-10422 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. modern-tar is vulnerable to Integer Overflow in versions 0.7.0 - 0.7.5. | 0.7.0 - 0.7.5 | Medium |
AIKIDO-2026-10275 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. modern-tar is vulnerable to Prototype Pollution in versions 0.4.0 - 0.7.3. | 0.4.0 - 0.7.3 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.