The string_decoder module from Node core
62%
Total Score
67
100
83
100
The package has 16 releases since December 2013, but its latest registry release was in August 2019 with no releases in the last 12 months. That long release gap lowers confidence that new issues or compatibility needs will be addressed.
The repository recorded zero commits and zero active maintainers in the last three months. This is the strongest maintenance concern, although the recent push timestamp and organization backing provide some compensating evidence.
There are six open issues and one open pull request, but no new or closed issues or merged pull requests in the last month, indicating limited current issue resolution.
The repository uses a build tool, but no security scanning tools were detected. The missing scanning is a transparency gap rather than evidence that the package is unsafe.
No type declarations are published. This is a minor integration gap for TypeScript consumers, but the package is a small Node.js utility and the signal does not indicate maintenance or abandonment risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
safe-buffer Version ~5.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.