Get the ArrayBuffer out of a DataView, robustly.
65%
Total Score
83
100
95
67
50
No build attestation or trusted-publisher identity is present. This reduces publication transparency, although it is not by itself evidence that the release is unsafe.
The package uses prepack and prepublish lifecycle scripts. These are not automatically unsafe, but they add release-time execution surface that merits caution when provenance is limited.
Only three releases have been published, with none in the last 12 months; the latest release was nearly two years ago. This raises maintenance caution, though the package may be stable and its repository was pushed more recently.
The repository recorded no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance.
All six analyzed workflows completed the audit with no reported findings and five use read-only permissions, but all six action references are unpinned, leaving a workflow reproducibility gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
es-errors Version ^1.3.0 | — | — |
call-bound Version ^1.0.3 | — | — |
is-data-view Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.