
NPM Scan
A fast security scanner that detects malicious or suspicious
Over the last few years, the JavaScript ecosystem has turned into a supply-chain battlefield. Packages look harmless on the surface but hide obfuscated code, suspicious postinstall scripts, silent network calls, or maintainers who disappeared years ago. Most of us install dependencies without ever checking what we’re pulling into our codebase.
A few weeks ago I asked myself a simple question:
Why isn’t there a fast, dead-simple way to “x-ray” an npm package before trusting it?
I didn’t want a CLI, config files, or yet another security product that takes an afternoon to set up. I wanted a website where I could type a package name and instantly see all the red flags.
So I built NPM Scan → https://npmscan.com
What it does
Scans npm packages in seconds
Detects hidden scripts, obfuscated code, and suspicious patterns
Highlights inactive or unknown maintainers
Shows full file structure, metadata, and dependencies
Assigns a risk score based on real security signals
No install, no setup — just search and check
Why I built it
I’ve seen too many developers assume a package is safe because it has downloads or stars. That’s how supply-chain attacks spread. My goal was to make package security obvious, fast, and accessible, even for developers who don’t have time to dig through source code.
What’s next
I’m planning to add:
API access
GitHub PR bot integration
Automated scanning for your
package.jsonAlerts for newly compromised packages
I’d love feedback from the IndieHackers community.
What features would actually help you in your workflow?
Would you use this before adding a dependency?
If you want to try it: https://npmscan.com
Happy to answer questions about the build, stack, struggles, or the process behind it.
About
I built NPM Scan because the JavaScript ecosystem has a real supply-chain problem. Developers install packages every day without realizing how many of them contain hidden scripts, obfuscated code, or risky maintainers.

Comment