Robustly get the byte offset of a Typed Array
78%
Total Score
67
50
94
80
50
Staged publishing is enabled, but no build attestation or trusted publisher identity is present, leaving publication provenance less independently verifiable.
Two of seven workflows use pull_request_target, which requires elevated trust because it can run with repository privileges, but there are no untrusted checkouts or script-injection findings.
Six runtime dependencies create some transitive supply-chain surface for a small utility, but the dependency list is focused on related typed-array and JavaScript compatibility helpers rather than unusually broad functionality.
The package uses prepack and prepublish lifecycle scripts, which add install and publication complexity; no provided signal shows that these scripts are unsafe, so this is a limited concern rather than a severe risk.
The package has existed for about 3 years and released version 1.0.5 on the assessment date, but only one release occurred in the last 12 months and the median interval is about 256 days, indicating modest rather than rapid maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gopd Version ^1.2.0 | — | — |
for-each Version ^0.3.5 | — | — |
call-bind Version ^1.0.9 | — | — |
is-typed-array Version ^1.1.15 | — | — |
available-typed-arrays Version ^1.0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.