A
licenseNot graded
qualityC
maintenanceEnables auditing package.json files for real npm supply-chain attack mechanisms — typosquatted dependency names, malicious preinstall/install/postinstall scripts that pipe downloads into a shell or decode base64 payloads, and unpinned versions — plus live npm registry lookups that flag nonexistent, brand-new, deprecated, or typosquatted packages. It exposes dedicated tools for full manifest audits and single-name typosquat checks.
MIT