Tiny and fast Tar utils for any JavaScript runtime!
72%
Total Score
75
100
92
50
The repository recorded no commits and no active maintainers during the last three months. A recent push and release provide some compensation, but the short-term development pause still raises maintenance concern.
The project uses TypeScript and npm-based build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap.
No repository security policy was found. That weakens disclosure transparency, although it does not by itself indicate abandonment.
Both workflows were fully analyzed with no high- or medium-severity findings and no untrusted checkout or script-injection paths. However, four of five action references are unpinned, and both workflows install packages outside a lockfile, creating a workflow hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-69874 nanotar is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 0.2.0. | 0.0.0 - 0.2.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.