Is fs-web safe to install?
ASK DepWall stops this install and asks a human.
Checked
against version 1.0.1, using the same engine the CLI runs.
This is a record of one check at one moment — run the gate
for the answer that applies to the version you are about to install.
What the registry says
| Version checked | 1.0.1 |
|---|---|
| Age | 11 years old |
| Weekly downloads | 874 |
| Maintainers | 1 |
| Runs install scripts | no |
| npm provenance | not attested |
| Deprecated | no |
| Git/URL dependencies | 1 |
Signals that fired
- warn
remote-dep"[email protected]" declares 1 unverifiable git/URL dependency [path → git://github.com/component/path.git#7b4f23c38833a5232cd5e3d50ccb8cd13dbcd2f4] — the registry never reviewed that source, and a git dep runs its own `prepare` hook at install; a bare commit SHA reaches code that no tag or branch points at — the Mini Shai-Hulud delivery shape (2026-05). Human review required.
A dependency resolves to a git or URL source rather than to the registry.
What was checked
DepWall reads registry metadata and the package's own manifest before any of its code runs. On npm that means the name against a popularity dictionary and a curated hallucination feed, the tarball hash against OSV's malicious-release advisories, lifecycle scripts, publication age and adoption, provenance attestations across this and prior releases, and dependencies that resolve outside the registry.
It does not execute the package, and this page did not download its source. How verdicts are decided · what this cannot catch.
Check it yourself
npm i -g depwall && depwall init
depwall check fs-web
Once depwall init has run, the check happens on
npm install itself — including for the transitive dependencies you never
chose, which is where most
of this actually arrives.