Encode and decode streams into string streams
58%
Total Score
33
81
83
The latest registry release was in August 2018, with no releases in the last 12 months. This is a substantial maintenance concern, although the package has a stable 1.0.0 release and a focused scope.
There were zero commits and zero active maintainers in the three months measured. Combined with the old registry release, this indicates weak current maintenance capacity.
Only one registry account has publish access, leaving a thin publishing base. The linked repository is owned by the same individual, so there is no broader organization backing shown to compensate.
The repository is owned by an individual rather than an organization, and no registry namespace is shown. This provides limited visible institutional backing for long-term maintenance.
The repository reports no build tooling and no security scanning. For this small, direct JavaScript package that is a hygiene gap rather than a standalone severe dependency risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2018-21270 stringstream is vulnerable to Out-of-bounds Read in versions 0.0.0 - 0.0.6. | 0.0.0 - 0.0.6 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.