Home / npm
npm package checks
DepWall's recorded check for 3,213 popular npm packages — the verdict its engine returns, the signals behind it, and what a quiet result does not prove.
| Packages checked | 3,213 |
|---|---|
| ALLOW | 3,181 |
| ASK | 32 |
| BLOCK | 0 |
How these were produced
Each page records what DepWall's own engine returned when it was run against live
registry metadata for that package — the same evaluate() the CLI calls,
not a separate scoring system built for the website. Every page carries the date and
the exact version it checked.
Scoped packages (@scope/name) are not covered here.
npm publishes no bulk download counts for them, and DepWall treats an unverifiable
download count as grounds to ask rather than to allow — so including them would mean
publishing thousands of pages describing npm's API rather than this gate. The CLI has
no such limit: run it against any scoped package and it resolves normally.
A quiet result is not a safety certificate. It records that the listed checks did not fire on one version at one moment. Packages change; the classes DepWall does not claim to detect — maintainer compromise chief among them — leave every structural signal green. Treat these pages as a starting point and run the gate for a live answer.
Packages that did not come back quiet
32 of the checked packages returned something other than ALLOW. These are the pages worth reading first.
aberlaas-lintASKarib-b25-stream-testASKbcryptoASKdeasyncASKeslint-config-upholdASKextension-fsASKfs-extASKfs-ext-extra-prebuiltASKfs-extended-attributesASKfs-webASKgdal-asyncASKgit-commit-msg-linterASKhasura-cliASKmongodb-memory-serverASKopencv-buildASKparse-serverASKreactstrap-date-pickerASKredis-memory-serverASKrsbuild-plugin-lintASKscryptASKsnykASKssh2ASKstream-chatASKtree-sitter-cliASKtree-sitter-cssASKtree-sitter-jsonASKvue-composableASKvue-demiASKvue-lsASKvue-typesASKxhs-mp-shared-fsASKzego-express-engine-webrtcASK
Browse all 3,213
Every checked package, alphabetically: start at page 1.
To check a package that is not here, run the gate locally — it works on any package, not only the ones on this site.
npm i -g depwall && depwall init