NPMScan

Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups

Community: Submitted by a user or imported; check the owner before granting accessOnlineNo sign-inGlobalFreeRead-only

What it can do

    What data it sees

    Do you need an account

    No: the server works without sign-in

    Detect malicious or vulnerable npm packages: registry search, OSV.dev and GitHub advisory lookups

    Tools not fetched yet: the server requires sign-in; the list appears after a manual check.