Check your npm dependencies

Scan your package-lock.json for compromised packages, known vulnerabilities, and malware. No signup required.

We'll fetch the package-lock.json from the default branch (main or master).

Currently supports npm (package-lock.json v1, v2, v3). More ecosystems coming soon.