Check an npm package before installing it
check_packageInspect an npm package before installing: detect malware, vulnerabilities, removals, typosquats, and hijacked releases without downloading or running any code.
Instructions
Look up an npm package before npm install: removed by npm for security, reported malicious or vulnerable in OSV.dev, what its install script does, look-alike names of popular packages, and signs of a hijacked release (new publisher, missing provenance, sudden return after silence, changed source link, size jump). Never downloads or runs the package code. Accepts "name", "@scope/name", "name@version" or a pasted install command.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| package | Yes | For example lodash, @solana/web3.js or ethers@6.13.0. |