Now live on npm

Inspect before you run.

betternpm inspects npm packages for typosquats, risky install scripts, and known vulnerabilities before they ever run — then hands off to npm.

npm i -g betternpm-cli
curl -fsSL https://betternpm.org/latest | sh
Search & audit packages

No install needed — search and audit any npm package right in your browser. Sign in with GitHub to claim your handle on the leaderboard.

Caught in the wild

We ran the audit engine against real supply-chain incidents still installable from npm. Every verdict below is a public record — click through for the full agent transcript.

And no false alarms: the clean releases we used as controls — ua-parser-js@0.7.28 (low 96) and left-pad@1.3.0 (low 99) — passed.