Dependency hygiene / browser-only

READ THE
FINE PRINT.

Paste a package.json. Get a fast, explainable review of version ranges, remote sources, lifecycle scripts, and publishing configuration—without uploading your project.

01 / MANIFESTJSON
02 / FINDINGSSTATIC REVIEW

WHAT IT FLAGS

Unbounded and broad ranges, Git or direct URL dependencies, install-time scripts, workspace-only paths, and accidental public-publish configuration.

WHAT IT DOESN'T

This is not a vulnerability database or malware verdict. It cannot inspect package source, transitive trees, lockfile integrity, or a publisher's intent.

NEXT STEP

Pin or constrain dependencies, keep a reviewed lockfile, inspect install scripts, and use your registry audit tools before release.