Postgres bytea parser
72%
Total Score
50
100
94
80
50
No build attestation, trusted publisher identity, or staged publishing is present, so release origin is less independently verifiable. This is a transparency limitation rather than evidence that the package is unsafe.
One registry maintainer is consistent with a small individually owned package, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
The repository is owned by an individual user rather than an organization, so there is no organizational backing to offset the package's single-maintainer structure.
The package is mature at 4,113 days old and has a release in the last 12 months, but only four releases overall with a median interval of about 3 years and 10 months indicates a sparse maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release and small stable utility partly compensate, but the lack of recent development still raises abandonment risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
obuf Version ~1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.