npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@mingderwang/xsift

v0.1.9

Published

URL network-vulnerability scanner CLI with Google login, scan reports, and scan history.

Readme

xsift

A URL network-vulnerability scanner in your terminal. Sign in with Google, scan any public URL, and review your scan history — no account setup beyond your Google login.

Install

npm install -g @mingderwang/xsift

Requires Node.js 18+.

Quick start

# 1. Sign in with Google (opens your browser, like `turso auth login`)
xsift auth login

# 2. Create a wallet for paid scans (asks for a new password, ~/.xsift/wallet.json)
xsift wallet create

# 3. Scan a URL — pays 0.5 USDC on Base Sepolia (x402) automatically
xsift scan https://example.com

# 4. See your scan history
xsift history

Scans on the hosted backend are behind an x402 paywall (0.5 USDC on Base Sepolia). On your first xsift scan the CLI gets a 402 Payment Required response, signs an EIP-3009 TransferWithAuthorization with your wallet, and resends it via the X-PAYMENT header. If your wallet has no USDC the scan is rejected with insufficient_funds — fund the address shown by xsift wallet address with Base Sepolia USDC and ETH (faucet) to enable real settlement.

Commands

| Command | Description | | --- | --- | | xsift auth login | Sign in with your Google account | | xsift auth logout | Forget the saved session | | xsift auth whoami | Show the signed-in account | | xsift scan <url> | Scan a URL (pays 0.5 USDC via x402) and print a full report | | xsift history | Show your recent scan history | | xsift wallet create | Create a wallet + encrypted keystore | | xsift wallet import | Import a wallet from a mnemonic or private key | | xsift wallet address | Show the wallet address | | xsift wallet balance | Show ETH + USDC balances (--network <id>, default Base Sepolia) | | xsift wallet export | Show the private key / mnemonic (password protected) | | xsift wallet delete | Delete the local keystore |

Options:

  • --limit <n> — limit history rows (default 20)
  • --json — print raw JSON instead of formatted output
  • --network <id> — network for wallet balance (ethereum-sepolia, ethereum-mainnet, base-sepolia, base)

What a scan checks

  • TLS: protocol version, certificate validity, expiry, hostname match, self-signed
  • HTTP security headers: CSP, HSTS (+ preload/subdomains), X-Content-Type-Options, Referrer-Policy, Permissions-Policy, frame protection
  • Cookie flags: Secure, HttpOnly, SameSite, expiry
  • Transport: HTTP version, redirects, response time, server disclosure
  • Open ports: common web, mail, FTP, SSH, and database ports
  • A 0–100 score with a letter grade (A is a perfect hardening score)

Configuration

  • Session is stored at ~/.xsift/config.json (permissions 0600).
  • Wallet keystore (encrypted with scrypt + AES-256-GCM) at ~/.xsift/wallet.json.
  • XSIFT_API_URL overrides the backend API base URL. Default: https://network-vulnerability-scanner-pink.vercel.app
  • X402_RPC_URL overrides the RPC used for balances / payment defaults.
  • XSIFT_WALLET_PASSWORD — optional env override for wallet unlock (CI/testing; otherwise xsift prompts interactively).

License

MIT