pkgproof

Read the package before it reads your keys.

Ask before you install. One word back: safe, caution, or block. Every check named, with its own result and what it found.

$0.05 a check, one request, no account

Certificate of analysis

[email protected]

8 checks run, none skipped

Caution
  1. Safe
  2. Caution
  3. Block
  4. Does not exist
Every check that ran, its result, and what it found.
# Check Result Finding
01 Package exists safe Package 'semver' (version '7.3.5') exists in the npm registry.
02 Known vulnerability caution [email protected] is affected by a known vulnerability (GHSA-c2qf-rxjj-qqgw): semver vulnerable to Regular Expression Denial of Service
03 No install scripts safe Package 'semver' declares no preinstall/install/postinstall scripts.
04 Typosquat recognized package safe 'semver' is itself a popular npm package (>= 100000 weekly downloads), not a typosquat.
05 No combosquat match safe Name 'semver' is not a popular package name with a generic affix attached.
06 Scope not evaluated safe Scope confusion was not evaluated for 'semver': it has no separator to split into a scope and a package name. Absence of a finding here is not evidence the name is unlike a scoped package's.
07 Source repository present safe 'semver' declares a source repository (git+https://github.com/npm/node-semver.git). The declaration is unverified: pkgproof does not confirm the repository exists or that it publishes this package.
08 Reputation safe 'semver': first published 5662 days ago, 832321560 weekly downloads, 119 releases, the most recent 55 days ago.
pkgproof Issued 14 August 2026

No data, no verdict.

Any checker looks good when the data arrives. What matters is the other case. When npm or OSV cannot be reached, the request returns 502 and no verdict, instead of dropping that check quietly and handing you an answer that looks clean.

It costs us uptime and we picked it on purpose, because it is the only way safe can mean anything. Here it means every check ran and every check passed. It never means nothing came back.

Unsigned
HTTP/1.1 502 Bad Gateway
{
  "error": {
    "code": "upstream_error",
    "message": "A required data source could not be reached. Try again shortly."
  }
}

No verdict. The request fails, and you know it failed.

Register of prior analyses

Same request, three different verdicts. Captured from real verifications, not written by hand.

Block

crossenv

crossenv is affected by a confirmed-malicious advisory (GHSA-c2m4-w5hm-vqjw): crossenv is malware

Does not exist

react-auth-helper-pro

No package named 'react-auth-helper-pro' exists in the npm registry.

Put it in front of npm install

One endpoint, one POST, one verdict. There is nothing to sign up for and no key to rotate: the payment is the authorisation, and the docs show the whole call end to end.

Read the docs

What it costs

Per package checked
$0.05
Paid with
USDC on Base
Docs and discovery
free
Payable before the check runs
$0.05