Now live on npm
Inspect before you run.
betternpm inspects npm packages for typosquats, risky install scripts, and known vulnerabilities before they ever run — then hands off to npm.
npm i -g betternpm-clicurl -fsSL https://betternpm.org/latest | shSearch & audit packages
No install needed — search and audit any npm package right in your browser. Sign in with GitHub to claim your handle on the leaderboard.
Caught in the wild
We ran the audit engine against real supply-chain incidents still installable from npm. Every verdict below is a public record — click through for the full agent transcript.
- node-ipc@11.1.02022 protestware — the agent recursively audited its payload dependencyblocked 18
- faker@6.6.62022 maintainer sabotage releaseblocked 15
- event-source-polyfill@1.0.26protestware hidden in a patch releaseblocked 10
- es5-ext@0.10.61postinstall protestware — caught by the install-script policy floorblocked 25
- minimist@1.2.0prototype-pollution CVE — flagged by the vulnerability floorhigh 55
- peacenotwar@9.1.5the node-ipc payload itselfhigh 38
And no false alarms: the clean releases we used as controls — ua-parser-js@0.7.28 (low 96) and left-pad@1.3.0 (low 99) — passed.