If I understand correctly, the vulnerability / trap / questionable design choice that this package exists to address was fixed in Node itself in 2017? At least, the new Buffer(size) docs say that since version 8.0.0 of Node:
The new Buffer(size) will return zero-filled memory by default.
Yet safe-buffer's README still says that Buffer "is" unsafe "today". This is basically untrue, no?