# shvl

> Get and set dot-notated properties within an object

Latest version **3.0.2** (published 2026-09-07) · MIT license · 0 weekly downloads

## Install

```sh
npm install shvl
pnpm add shvl
yarn add shvl
bun add shvl
```

## Health

**Score 70/100 (B)** — status: active.

Positive: has types; esm support; no vulnerabilities; recently updated; high maintenance score; high quality score.

Warnings: low downloads.

## Facts

| | |
|---|---|
| Version | 3.0.2 |
| Published | 2026-09-07 |
| First published | 2017-11-03 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | ESM + CommonJS |
| Dependencies | 0 |
| Unpacked size | 6 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 73 |
| Author | Robin van der Vleuten |
| Maintainers | robinvdvleuten |
| Keywords | path, dot notation, dot |

## Links

- npm: https://www.npmjs.com/package/shvl
- Repository: https://github.com/robinvdvleuten/shvl
- Homepage: https://github.com/robinvdvleuten/shvl#readme
- Issues: https://github.com/robinvdvleuten/shvl/issues
- npm.io page: https://npm.io/package/shvl

## Alternatives

- [base64url](https://npm.io/package/base64url.md) — 6.1M weekly downloads
- [get-installed-path](https://npm.io/package/get-installed-path.md) — 502.9K weekly downloads
- [@uppy/url](https://npm.io/package/@uppy/url.md) — 185.8K weekly downloads
- [@d3fc/d3fc-shape](https://npm.io/package/@d3fc/d3fc-shape.md) — 16.2K weekly downloads
- [localizer](https://npm.io/package/localizer.md) — 226 weekly downloads

## Recent versions

- 3.0.2 (latest) — 2026-09-07
- 3.0.1 — 2026-07-18
- 3.0.0 — 2022-05-02
- 2.0.3 — 2021-04-12
- 2.0.2 — 2021-01-11
- 2.0.1 — 2020-08-04
- 2.0.0 — 2019-04-15
- 1.3.1 — 2018-04-09
- 1.3.0 — 2018-04-09
- 1.2.1 — 2018-03-14
- 1.2.0 — 2017-12-22
- 1.1.1 — 2017-11-04
- 1.1.0 — 2017-11-04
- 1.0.0 — 2017-11-03

## README

# shvl

Get and set dot-notated properties within an object. **~190 bytes min+gzip, zero dependencies.**

<img src="https://media.giphy.com/media/3o85xLDQLoZD1rk07u/giphy-downsized.gif" width="350" />

<hr />

[![NPM version](https://img.shields.io/npm/v/shvl.svg)](https://www.npmjs.com/package/shvl)
[![Build Status](https://github.com/robinvdvleuten/shvl/actions/workflows/test.yml/badge.svg)](https://github.com/robinvdvleuten/shvl/actions/workflows/test.yml)
[![NPM downloads](https://img.shields.io/npm/dm/shvl.svg)](https://www.npmjs.com/package/shvl)
[![MIT license](https://img.shields.io/github/license/robinvdvleuten/shvl.svg)](https://github.com/robinvdvleuten/shvl/blob/main/LICENSE)

<a href="https://webstronauts.com?utm_source=github&utm_medium=readme&utm_campaign=shvl">
	<picture>
		<img src="https://webstronauts.com/images/sponsored-by.svg" alt="Sponsored by The Webstronauts" width="200" height="65">
	</picture>
</a>

## Installation

```
npm install --save shvl
```

## Usage

```js
import * as shvl from 'shvl';

let obj = {
	a: {
		b: {
			c: 1,
			d: undefined,
			e: null,
		},
	},
};

// Use dot notation for keys
shvl.set(obj, 'a.b.c', 2);
shvl.get(obj, 'a.b.c') === 2;

// Or use an array as key
shvl.get(obj, ['a', 'b', 'c']) === 2;

// Returns undefined if the path does not exist and no default is specified
shvl.get(obj, 'a.b.c.f') === undefined;

// Pass a third argument to get a fallback instead of undefined
shvl.get(obj, 'a.b.c.f', 'fallback') === 'fallback';
```

## API

### `get(object, path, default?)`

Reads the value at `path`, a dot-string or an array of keys. Returns `default` when the path does not resolve, or `undefined` when no default is given.

### `set(object, path, value)`

Writes `value` at `path`, creating intermediate objects along the way, and returns the mutated object.

## Safety

`set` never writes through `__proto__` or `constructor`, so a crafted path like `constructor.prototype.polluted` cannot reach `Object.prototype`. The guard compares keys with strict equality rather than a regular expression, so overriding `RegExp.prototype.test` cannot bypass it.

## License

MIT © [Robin van der Vleuten](https://robinvdvleuten.nl)

---
_Source: https://npm.io/package/shvl · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
