Analyzing dependencies...
Vulnerability Report
Package | Version | Status | Advisories |
---|
One upload tells you if your dependencies are putting your app at risk.
Know if your npm dependencies are safe with ntlli.com — npm intelligence.
Free instant scan, no signup required.
Files are processed locally. Nothing is uploaded.
Stay informed about the latest security incidents and compromised packages
Multiple versions of a widely-used React component library were compromised with malicious code that exfiltrates environment variables.
Attackers published packages with names similar to popular Express middleware, containing cryptocurrency miners.
A popular utility library was found to be vulnerable to prototype pollution attacks affecting object manipulation functions.
Your lockfiles never leave your browser. All processing happens locally on your device.
Get results in seconds. No server uploads, no waiting in queues.
Daily updates from OSV database and curated incident feeds for the latest threats.
Drag and drop your package-lock.json, pnpm-lock.yaml, or yarn.lock file into the browser.
Dependencies are parsed locally in your browser and matched against our vulnerability database.
Get immediate feedback on vulnerable packages with links to security advisories and remediation steps.
Our system processes your lockfiles entirely within your browser using advanced client-side parsing and vulnerability matching algorithms.
Ready to check your dependencies? Go back to the scanner above.