Know your dependencies.Trust what you ship.
Search any npm package for real security advisories, weekly downloads, and OpenSSF Scorecards — or audit your whole lockfile at once.
Real advisories
Vulnerabilities come straight from OSV.dev — the open database aggregating GitHub Security Advisories and CVEs.
Honest scoring
Security scores are derived from known advisories, publish recency, and the repo's OpenSSF Scorecard — never invented.
Lockfile audit
Drop in a package-lock.json and get every dependency checked against the OSV database in one pass.
Popular packages
Curated selection — live registry & OSV data
Popular packages are momentarily unavailable. Search still works, and this section refreshes on its own within a minute.