transform a stream into a quoted string
43%
Total Score
50
50
75
100
50
The package is mature at about 12 years old, but its latest release was about 11 years ago and it has had no releases in the last 12 months, indicating likely abandonment.
No build attestation or trusted publisher identity is present, so the artifact's publication provenance cannot be independently verified; this is a transparency weakness rather than evidence of maliciousness.
Three runtime dependencies create some maintenance surface for this small utility, but the count is not excessive enough to be a severe health concern on its own.
Only one registry account has publish access. This does not prove inactivity, but it leaves little visible publishing redundancy alongside the stale release history.
No type declarations are provided, which is a minor integration gap for consumers using typed JavaScript tooling; the package is a small stream utility with documented CommonJS usage.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
minimist Version ^1.1.3 | — | — |
through2 Version ^2.0.0 | — | — |
buffer-equal Version 0.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.