Observed arrival · 2026-10-07
Who’s There? Maps who can publish into your app
A browser-based scanner reads an npm lockfile and lists the people who can publish code into a project’s dependencies.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Teams using npm dependencies
- Worth noticing
- It flags risks including purchasable maintainer email domains, releases that skip CI, and code that runs on install.
Field notes
The page says scans run in the browser and names specific signals rather than offering only a general dependency warning. These include maintainers with email domains anyone can buy, releases that skip CI, and code executed during installation. Optional Google sign-in is described as enabling saved projects, monitoring for changes, and alerts; the homepage does not show a sample report.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
◎NicheUnusually specific use
One card from the complete issue