npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@damusix/dep-scanner

v1.0.0

Published

A tool for discovering dependencies recursively across package.json and common lock files, useful for finding vulnerabilities and package versions deeply nested in your projects

Readme

Dependency Scanner

npm version License: MIT

A tool for discovering dependencies recursively across package.json and common lock files, useful for finding vulnerabilities and package versions deeply nested in your projects.

Features

  • Search pnpm-lock.yaml, yarn.lock, package-lock.json, npm-shrinkwrap.json, and package.json files recursively
  • Accept packages via a -p comma-separated argument or via file/stdin (-f file, -f -, --stdin)
  • Validate package names and basic semver versions; invalid lines are warned and ignored
  • Works with piped input (e.g., clipboard via pbpaste) and can be run from any root path with -r
  • Lightweight implementation using dynamic regex matching
  • No external dependencies

Installation

Global Installation

Install globally using npm:

npm install -g @damusix/dep-scanner

Or using pnpm:

pnpm add -g @damusix/dep-scanner

Or using yarn:

yarn global add @damusix/dep-scanner

Run without Installation

You can also run dep-scanner directly without installing it globally using npx:

npx dep-scanner -p express,lodash

Usage

After installation, the dep-scanner command will be available globally.

Scan packages specified directly:

dep-scanner -p [email protected],lodash -r /path/to/repo

Scan packages from a file:

dep-scanner -f packages.txt -r /path/to/repo

Pipe clipboard or other stream into the scanner:

pbpaste | dep-scanner -f - -r /path/to/repo
pbpaste | dep-scanner --stdin -r /path/to/repo

Auto-detect piped stdin (no -p or -f):

pbpaste | dep-scanner -r /path/to/repo

Scan current directory:

dep-scanner -p express,react

Command Options

  • -p: Comma-separated packages (version optional). Example: -p [email protected],@scope/[email protected],pkg2
  • -f: File with newline-separated entries, format: package=version or package@version (version optional)
  • -r: Root path to start searching from (defaults to current working directory)
  • -h: Show help message

Examples

Finding a specific vulnerable package version:

dep-scanner -p [email protected] -r ~/projects/myapp

Checking multiple packages from a file:

Create a file vulnerable-packages.txt:

[email protected]
[email protected]
[email protected]

Then run:

dep-scanner -f vulnerable-packages.txt -r ~/projects

Quick clipboard scan (macOS):

Copy a list of packages to clipboard, then:

pbpaste | dep-scanner --stdin

Notes

  • This tool uses dynamic regex matches and may produce false positives for unusual file formats
  • It's intended for quick repository searches, not authoritative dependency resolution
  • The tool searches through lock files and package.json without parsing them as JSON/YAML

Author

Danilo Alonso [email protected]

License

MIT

Repository

GitHub Gist