Drop a lock file and every package name is checked, entirely in your browser, against the newest malicious-package advisories from the GitHub Advisory Database. Nothing is uploaded, stored, or tracked.
Drop your lock file here
or click to browse
package-lock.json · pnpm-lock.yaml · yarn.lock · uv.lock · poetry.lock
This is a fast public-advisory check, not a full audit — it only covers packages in the current database, and brand-new threats are not in it yet.
About 20 minutes, read-only, and you get the short written report.
Start the free check