Supply chain toolsLocal review / optional AI
Supply chain / FREE TOOL
Dependency review
Look beyond the version number. Review install scripts, dependency sources, version ranges, and lockfile integrity metadata.
02 Your results
A closer look starts here.
Add your input and run the check. We will show the observations and explain what needs review.
A QUICK WALKTHROUGH
How to use it
- 01Paste a package.json or npm package-lock.json.
- 02Review source, installation, and integrity signals.
- 03Verify flagged dependencies before changing your build.
What this check can tell you
Reviews the metadata you provide. It does not query vulnerability databases, inspect package code, or establish whether a package is malicious. npm lockfiles v2 and v3 are supported.
The initial review processes files in this tab. If you choose the optional AI summary, the displayed findings are sent to Cloudflare AI; your raw file, result tables and decoded token claims are excluded.
npm package-lock.json documentation