Skip to main content
Supply chain tools

Supply chain / FREE TOOL

Dependency review

Look beyond the version number. Review install scripts, dependency sources, version ranges, and lockfile integrity metadata.

Local review / optional AI

01 Your input

Local processing only. Maximum file size: 2 MB.

02 Your results

A closer look starts here.

Add your input and run the check. We will show the observations and explain what needs review.

 

A QUICK WALKTHROUGH

How to use it

  1. 01Paste a package.json or npm package-lock.json.
  2. 02Review source, installation, and integrity signals.
  3. 03Verify flagged dependencies before changing your build.

What this check can tell you

Reviews the metadata you provide. It does not query vulnerability databases, inspect package code, or establish whether a package is malicious. npm lockfiles v2 and v3 are supported.

The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.

npm package-lock.json documentation