npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@meredian-labs/latchx

v0.1.3

Published

A safer npx replacement that audits npm packages before execution.

Readme

latchx

latchx is a safer npx replacement that audits npm packages before execution. It is the first product in the Latch family: local-first tooling for package execution trust.

npx and npm exec are convenient, but they can fetch and run package-controlled code in one step. latchx changes the order: resolve metadata, download the tarball, verify integrity when available, inspect package contents, evaluate policy, and only run after approval.

Quick Start

npm install -g @meredian-labs/latchx

latchx doctor
latchx audit is-number
latchx inspect is-number --json --ci
latchx cowsay --yes -- hello

Common Usage

Audit without running:

latchx audit create-vite
latchx inspect @angular/cli

Run after approval:

latchx run cowsay -- hello
latchx cowsay -- hello

Use deterministic CI or agent mode:

latchx audit create-vite --json --ci --policy ./latch.policy.json

What It Checks

  • package identity and publisher metadata
  • tarball integrity from npm metadata
  • extracted package/package.json
  • bin entries and lifecycle scripts
  • dependency counts
  • suspicious static patterns such as process, filesystem, network, shell, and obfuscation signals
  • previous-version differences when npm publish-time metadata is available
  • local policy from latch.policy.json or --policy <path>

Important Limits

latchx is not a malware detector and does not claim certainty. Findings are risk signals for review. The first release does not provide full sandboxing, a backend reputation service, or complete npm exec compatibility.

See the repository README for full documentation.