Skip to main content

Open-source release intelligence for npm

Know what changed before you accept the update.

Compare npm releases, expose install-script changes, and review package evidence before new code enters your environment.

  • npm releases
  • Public evidence history
  • No account required
Pwned Packages / npmAutomated evidence
Illustrative release comparison

[email protected]

Review priorityElevated
Baseline2.0.4
Latest release2.1.0
SCRIPTpostinstall lifecycle hook addedReview
FILES3 added · 2 modified · 0 removedDiff
OSVKnown advisory context checkedClear

Representative interface with illustrative data, not a finding about a real package.

Evidence before conclusions

Move from package trust to package inspection.

Each analysis connects its assessment to observable release data your team can inspect and discuss.

01

Release-to-release comparison

See added, removed, and modified files against the previous npm release instead of judging an update by reputation alone.

02

Install behavior changes

Bring changes to preinstall, install, postinstall, prepare, and other lifecycle scripts into immediate view.

03

Advisory context and assessment

Review OSV advisories beside an automated risk narrative, notable findings, confidence, and recommended actions.

From package name to review record

A focused check in three steps.

  1. 1

    Name an npm package

    Start with the package you are considering. The latest published release is resolved from npm.

  2. 2

    Compare the evidence

    The first observed release creates a baseline. Later releases are compared with the previous stored version.

  3. 3

    Make the review decision

    Inspect file changes, lifecycle scripts, suspicious paths, advisories, and the automated assessment before proceeding.

Open the public analysis workspace

A reusable public record

Investigations should not disappear after one decision.

Completed analyses preserve the baseline, release transition, evidence summary, assessment, and model metadata. Revisit a package when it returns to review or share the same evidence with another team.

Browse public analyses

What the record keeps

Scope
Full baseline or incremental comparison
Evidence
Manifest, file, path, script, and OSV signals
Assessment
Risk level, confidence, findings, and actions
Provenance
Analyzed versions, provider, model, and timestamp

Transparent by design

Useful evidence without a false promise of certainty.

Automated, not human-reviewed. Assessments help prioritize investigation; they are not malware verdicts.

Current scope is npm. The live service does not claim coverage for package ecosystems it cannot analyze today.

Evidence has limits. A low-risk result cannot guarantee that a package is safe or that every behavior was observed.

Review methods and limitations
Private scanner · Upcoming

Bring release evidence into your dependency workflow.

The planned private scanner will help AppSec and platform teams review lockfile dependencies before installation. Public analysis is available now.

Request scanner access

Before you analyze

What to expect from the evidence.

What does Pwned Packages analyze?

It analyzes public npm releases, prioritizing package metadata, entry points, install scripts, changed files, suspicious paths, and known OSV advisory context.

Does an analysis prove that a package is safe?

No. The service produces automated evidence and an AI-generated assessment to support review. It does not guarantee safety, detect every malicious package, or replace human judgment.

How are package versions compared?

The first observed version receives a full baseline scan. When a later version is analyzed, its files and manifest behavior are compared with the previously stored release.

Are analyses public?

Yes. Submitted public npm package analyses are stored in a searchable public history so evidence can be revisited and shared.

Inspect the release, then decide

Start with the npm package already in your review queue.

Analyze an npm package