npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@key-warden/protect

v1.0.1

Published

Key-Warden Protect CLI - obfuscate, seal, embed-key, watermark and verify a build for licensed distribution. Obfuscation is mandatory. Local, source never leaves your machine.

Readme

@key-warden/protect

The Key-Warden Protect CLI - a local, build-time tool that hardens a build for licensed distribution. Your source never leaves your machine.

It does four things and has one command that runs them all:

  • obfuscate - mandatory. Runs javascript-obfuscator (shipped as a dependency of this CLI) over your built JS. A build is not protected without it, so it cannot be turned off - only strengthened.
  • seal - encrypt your licensed file(s) with your product's content key (AES-256-GCM). They only run once Key-Warden hands the key to a valid, activated licence.
  • embed-key - write your vendor public key into the build for offline token verification.
  • watermark - stamp the build with a unique id.
  • check - confirm all of the above are present before you publish (this is "verify a protected build", run locally - nothing is uploaded). It fails if any shippable .js was not obfuscated, and exits non-zero so you can gate CI.

build runs them in order obfuscate → seal → embed-key → watermark → check, so your code is obfuscated first and then encrypted.

Quick start

npx @key-warden/protect init          # writes kw-protect.json - edit it
export KW_CONTENT_KEY=<base64 key>    # from vendor console -> Protect your code -> Reveal key
npx @key-warden/protect build         # obfuscate -> seal -> embed-key -> watermark -> check

Ship the produced *.sealed files plus dist/kw-public-key.txt. At runtime, decrypt with @key-warden/sdk:

const kw = require('@key-warden/sdk');
const res = await kw.validate(licence, { apimKey, clientKey, machineId });
const key = kw.unlockFromToken(res.token, machineId);   // machine-bound content key
const code = kw.unseal(sealedBlob, key);                // your decrypted (obfuscated) file

kw-protect.json

{
  "product": "your-product-code",
  "seal": ["dist/licensed"],
  "publicKey": "BASE64_VENDOR_PUBLIC_KEY",
  "obfuscate": { "include": ["dist"] },
  "out": "dist"
}
  • seal - a list of files or folders (folders are sealed recursively).
  • publicKey - your vendor public key (base64, 32 bytes). Not a secret.
  • The content key is never in the config - it comes from KW_CONTENT_KEY.
  • obfuscate.include - the built JS to obfuscate (default ["dist"]). Obfuscation always runs; add obfuscate.options to strengthen it (any javascript-obfuscator option). There is no switch to disable it.

Commands

| Command | What it does | |---|---| | init | scaffold kw-protect.json | | build | obfuscate → seal → embed-key → watermark → check | | obfuscate | obfuscate your built JS (mandatory) | | seal | seal the configured files | | embed-key | write the public key into the build | | watermark | stamp a build id | | check | verify the build is protected (CI-friendly exit code) |

One dependency - javascript-obfuscator (obfuscation is not optional). Everything else uses Node's built-in crypto.

Licence

MIT.