Skip to the card

Card 947 of 9702026-10-07 issue

Observed arrival · 2026-10-07

Who’s There? Maps who can publish into your app

whosthere.dev Visit website
Editorial interest 77/100 Selection signal · not a rating of the site

A browser-based scanner reads an npm lockfile and lists the people who can publish code into a project’s dependencies.

Landing page captured for the 2026-10-07 issue.
For
Teams using npm dependencies
Worth noticing
It flags risks including purchasable maintainer email domains, releases that skip CI, and code that runs on install.

Field notes

The page says scans run in the browser and names specific signals rather than offering only a general dependency warning. These include maintainers with email domains anyone can buy, releases that skip CI, and code executed during installation. Optional Google sign-in is described as enabling saved projects, monitoring for changes, and alerts; the homepage does not show a sample report.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
◎NicheUnusually specific use

One card from the complete issue

Candlelit Hypertext

365,501 arrived 1,000 judged 970 catalogued Enter the complete issue
whosthere.dev

Landing page observed 2026-10-07. The live site may have changed.