Know your dependencies.Trust what you ship.

Search any npm package for real security advisories, weekly downloads, and OpenSSF Scorecards — or audit your whole lockfile at once.

Real advisories

Vulnerabilities come straight from OSV.dev — the open database aggregating GitHub Security Advisories and CVEs.

Honest scoring

Security scores are derived from known advisories, publish recency, and the repo's OpenSSF Scorecard — never invented.

Lockfile audit

Drop in a package-lock.json and get every dependency checked against the OSV database in one pass.

Popular packages

Curated selection — live registry & OSV data

Popular packages are momentarily unavailable. Search still works, and this section refreshes on its own within a minute.