Release-to-release comparison
See added, removed, and modified files against the previous npm release instead of judging an update by reputation alone.
Open-source release intelligence for npm
Compare npm releases, expose install-script changes, and review package evidence before new code enters your environment.
postinstall lifecycle hook addedReviewRepresentative interface with illustrative data, not a finding about a real package.
Evidence before conclusions
Each analysis connects its assessment to observable release data your team can inspect and discuss.
See added, removed, and modified files against the previous npm release instead of judging an update by reputation alone.
Bring changes to preinstall, install, postinstall, prepare, and other lifecycle scripts into immediate view.
Review OSV advisories beside an automated risk narrative, notable findings, confidence, and recommended actions.
From package name to review record
Start with the package you are considering. The latest published release is resolved from npm.
The first observed release creates a baseline. Later releases are compared with the previous stored version.
Inspect file changes, lifecycle scripts, suspicious paths, advisories, and the automated assessment before proceeding.
A reusable public record
Completed analyses preserve the baseline, release transition, evidence summary, assessment, and model metadata. Revisit a package when it returns to review or share the same evidence with another team.
Browse public analysesWhat the record keeps
Transparent by design
Automated, not human-reviewed. Assessments help prioritize investigation; they are not malware verdicts.
Current scope is npm. The live service does not claim coverage for package ecosystems it cannot analyze today.
Evidence has limits. A low-risk result cannot guarantee that a package is safe or that every behavior was observed.
Review methods and limitationsThe planned private scanner will help AppSec and platform teams review lockfile dependencies before installation. Public analysis is available now.
Before you analyze
It analyzes public npm releases, prioritizing package metadata, entry points, install scripts, changed files, suspicious paths, and known OSV advisory context.
No. The service produces automated evidence and an AI-generated assessment to support review. It does not guarantee safety, detect every malicious package, or replace human judgment.
The first observed version receives a full baseline scan. When a later version is analyzed, its files and manifest behavior are compared with the previously stored release.
Yes. Submitted public npm package analyses are stored in a searchable public history so evidence can be revisited and shared.
Inspect the release, then decide