Package Health

stringstream

Encode and decode streams into string streams

Latest 1.0.0NPMNPM

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

81

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

83

Are you affected? Scan for Free

Health Score Breakdown

Release historydanger

The latest registry release was in August 2018, with no releases in the last 12 months. This is a substantial maintenance concern, although the package has a stable 1.0.0 release and a focused scope.

Repo commit activitydanger

There were zero commits and zero active maintainers in the three months measured. Combined with the old registry release, this indicates weak current maintenance capacity.

Maintainerscaution

Only one registry account has publish access, leaving a thin publishing base. The linked repository is owned by the same individual, so there is no broader organization backing shown to compensate.

Project backingcaution

The repository is owned by an individual rather than an organization, and no registry namespace is shown. This provides limited visible institutional backing for long-term maintenance.

Repo toolingcaution

The repository reports no build tooling and no security scanning. For this small, direct JavaScript package that is a hygiene gap rather than a standalone severe dependency risk.

Vulnerabilities

TitleVersionsSeverity
CVE-2018-21270
stringstream is vulnerable to Out-of-bounds Read in versions 0.0.0 - 0.0.6.
0.0.0 - 0.0.6
Medium

Package versions

Maintainers

Direct Dependencies

No direct dependencies.

Weekly Downloads

Info

Last Published
8 years ago
Created
14 years ago
Unpacked Size
0.1 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform