npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@mrkt_frwd/remap

v0.1.0

Published

Reconstruct the original sources embedded in a source map. Refuses any entry that climbs out of the output directory rather than relocating it.

Downloads

84

Readme

@mrkt_frwd/remap

Reconstruct the original source tree embedded in a source map.

npx @mrkt_frwd/remap main.js.map --out ./src

What it is for

Production bundles ship with .map files more often than people intend. When one is available — your own build, a bundle you are debugging, an app whose maps were left on the server — it usually carries sourcesContent: the original, unminified files. This turns that back into a directory tree you can read.

The part that matters

A source map is a file you got from somewhere else, and its sources array is used to build filenames. That makes path traversal the entire security surface of a tool like this, and it is not theoretical:

sources: ["../../../../.ssh/authorized_keys"]

Verified before the guard existed — a Vite/Rollup-style map with plain relative sources wrote a file to its grandparent directory. Webpack's webpack:/// prefix normalises away, which is why casual testing missed it.

Every entry is now checked against the output root. Anything that climbs out is refused and reported, not relocated:

  REMAP  main.js.map
  ────────────────────────────────────
  ok   src/components/Header.jsx
  ok   src/utils/math.js
  --   ../../PWNED.txt
         refused — path escapes the output directory

  2 file(s) written to ./src, 1 refused

Stripping the .. and writing it somewhere inside the root would also be safe, and it would be a guess about what the map meant. A map that climbs out of its own output directory is malformed or hostile; saying which is the caller's business, not this tool's.

Absolute paths and Windows drive letters are made relative to the root rather than honoured. A source the map references but does not embed is reported too, so a partial reconstruction never looks like a complete one.

Use it on things you have the right to read

Your own builds, your own bundles, and code you are permitted to inspect. A source map being reachable is not by itself permission to redistribute what is inside it.

API

const { unpackBundle } = require('@mrkt_frwd/remap');
const { written, skipped } = await unpackBundle('main.js.map', './src');

Requirements

Node 18+. One dependency: source-map.

MIT © Joe Asare. Built at Joe Asare Studio.