npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@cecuro/open-security

v0.1.2

Published

Point it at a repository, get real security findings with file:line, evidence, and a severity you can defend — using any model you want, on your own machine.

Readme

OpenSec — open security review for any model

OpenSec runs security-review agents against a repository, validates what they find, and keeps the results in a local SQLite ledger. Use your preferred model and provider. Today, the CLI, agents, database, and review UI all run on your machine.

OpenSec started as an internal benchmark of the OpenAI Codex Security approach using lean prompts and other models. It follows the same core flow: understand the system, search for realistic attack paths, validate findings, and help teams review them.

The small changes come from running Cecuro and learning which tools agents use well. OpenSec builds on the pi agent harness and packages the approach as a lean, open-source tool that is model-neutral and easy to inspect.

OpenSec is in early development. Review its findings before acting on them, and do not treat a clean report as proof that a system is secure.

How it works

Core idea: good coverage can come from an ensemble of similar runs.

Repository
  → inventory and editable threat model
  → independent probe agents
  → deduplication
  → validation and attack-path tracing
  → severity assessment
  → SQLite ledger, review UI, and exports

Each probe gets the same full scan scope and searches it independently. One run will miss things that another finds, so more passes can improve recall. Agreement between agents does not make a finding true. OpenSec merges duplicate candidates, then gives each remaining candidate to a separate validator.

Validation traces input from an entry point to its impact, checks the controls along that path, and tries to reproduce the issue when possible. Severity comes from recorded facts such as reachability, required access, impact, and validation method. The report keeps gaps and incomplete coverage visible.

The threat model persists per repository. You can edit it to match how the system is deployed; later scans reuse it unless you ask OpenSec to rebuild it.

What OpenSec keeps

The SQLite ledger is the shared record for the CLI and review UI. Its main objects are:

  • Repositories and scans: revision, scope, model, configuration, phase, cost, and timestamps.
  • Files and reads: the exact scan scope and byte-level coverage for each probe pass.
  • Findings: evidence, source locations, duplicate links, validation, reachability, and severity.
  • Activity: comments, review decisions, assessments, and scan events.

This makes interrupted scans resumable and keeps team decisions next to the evidence. It also lets you compare past runs and see which parts of a system received real review.

Install

OpenSec needs Node.js 22.19+, Docker Engine 28+, and macOS or Linux. Use WSL2 on Windows.

npm install --global @cecuro/open-security
opensec --version

OpenSec uses provider keys already in your environment or the credentials stored by pi.

opensec env
opensec models
opensec scan /path/to/repository --model provider/model
opensec review

Run opensec scan . --estimate to estimate a scan without calling a model. Run opensec --help for scan limits, cost controls, diff scans, exports, and CI options.

To scan an explicit file set, put one repository-relative path on each line. Blank lines and lines starting with # are ignored.

opensec scan . --scope-file scope.txt --model provider/model

Use it with your team

The local review UI turns scan output into shared work. A team can:

  • Review runs and filter findings by run, repository, severity, or state.
  • Confirm, suppress, follow up, or comment on a finding.
  • Inspect the threat model, evidence, source locations, cost, and coverage.
  • Export JSON, CSV, SARIF, or a read-only HTML snapshot.
  • Resume interrupted scans and set CI severity thresholds.

Run overview

Finding review

Review data stays in ~/.opensec/opensec.db. Exports can contain sensitive code-review data, so inspect them before sharing.

OpenSec is local today. If there is enough interest, we plan to release a hosted version for teams. Let us know.

Develop

git clone https://github.com/Cecuro/open-security.git
cd open-security
npm ci
npm run release:check

See CONTRIBUTING.md before opening a pull request. Report security flaws through SECURITY.md, not a public issue.

License

Apache-2.0. See LICENSE.

Built by Cecuro.