Over the last few years, the JavaScript ecosystem has turned into a supply-chain battlefield. Packages look harmless on the surface but hide obfuscated code, suspicious postinstall scripts, silent network calls, or maintainers who disappeared years ago. Most of us install dependencies without ever checking what we’re pulling into our codebase.
A few weeks ago I asked myself a simple question:
Why isn’t there a fast, dead-simple way to “x-ray” an npm package before trusting it?
I didn’t want a CLI, config files, or yet another security product that takes an afternoon to set up. I wanted a website where I could type a package name and instantly see all the red flags.
So I built NPM Scan → https://npmscan.com
Scans npm packages in seconds
Detects hidden scripts, obfuscated code, and suspicious patterns
Highlights inactive or unknown maintainers
Shows full file structure, metadata, and dependencies
Assigns a risk score based on real security signals
No install, no setup — just search and check
I’ve seen too many developers assume a package is safe because it has downloads or stars. That’s how supply-chain attacks spread. My goal was to make package security obvious, fast, and accessible, even for developers who don’t have time to dig through source code.
I’m planning to add:
API access
GitHub PR bot integration
Automated scanning for your package.json
Alerts for newly compromised packages
I’d love feedback from the IndieHackers community.
What features would actually help you in your workflow?
Would you use this before adding a dependency?
If you want to try it: https://npmscan.com
Happy to answer questions about the build, stack, struggles, or the process behind it.