npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@ship-safe/cli

v1.2.4

Published

Independent security scanner for AI-generated code — find vulnerabilities before you ship

Downloads

930

Readme

ShipSafe CLI

Independent security scanner for AI-generated code. Catch leaked secrets, missing auth, single-file IDOR patterns, misconfig, and other vulnerabilities in code written by Cursor, Lovable, Bolt, v0, and friends — from your terminal, before you ship.

npm install -g @ship-safe/cli

Quick start

# Scan the current directory (plain-English results)
shipsafe scan

# Scan a specific path
shipsafe scan ./src

# Sign in to unlock AI analysis + your plan's quotas
shipsafe login

What it can't find

The local scan runs pattern rules over your source files, plus a known-vulnerability lookup for the packages in your lockfiles. A few things follow from that:

  • Anything whose evidence is spread across files or requests (an ownership check in another module, a role check that only exists in the UI, business logic). Each rule matches inside one file, so the local scan catches single-file shapes, like a route that loads a row by a URL id with no owner filter, and misses the rest. The cross-file pass is the AI scan, which needs shipsafe login and a paid plan.
  • Test, fixture, and build-output paths. Anything under __tests__, __mocks__, fixtures, test-fixtures, vendor, build, dist, or coverage, plus files matching *.test.*, *.spec.*, or *.min.js, is skipped outright — including a real secret sitting in a test fixture.
  • Anything inside a dot-directory. .github, .circleci, .vscode, and every other directory whose name starts with a dot are skipped outright, so workflow files and editor configs living there go unscanned.
  • Files without a recognized extension — bare .env/.env.local, Dockerfile, .cursorrules, and other agent rule files. The scanner matches files by extension, and these names don't carry one it recognizes, so they're never read.
  • The AI pass only sees a capped slice of the repo. On a paid plan, the deep AI analysis reads a capped number of files, each under a size limit, in directory-walk order — the highest-risk file in a large repo might not make the cut.
  • Files over 1MB and paths matched by the .gitignore in the folder you scan (nested .gitignore files are not read) are skipped for source files only — lockfiles use a looser 5MB cap instead and are read regardless of .gitignore (see the lockfile bullet below). Symlinks are skipped for both source files and lockfiles.
  • Lockfiles are collected separately, with different rules. package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, Gemfile.lock, go.sum, bun.lockb, bun.lock, and npm-shrinkwrap.json are read wherever they sit — including a path .gitignore would otherwise exclude — except inside node_modules, vendor, a dot-directory, or one of the test/build directories listed above, a symlink, or a path excluded via .shipsafe.yml's exclude. Only the first six formats feed the CVE lookup below; Bun's two lockfile formats and npm-shrinkwrap.json aren't parsed for it yet, so a project whose only lockfile is one of those three gets no dependency CVE check — but the lockfile's presence still satisfies the missing-lockfile check (deps/no-lockfile). A lockfile over 5MB is skipped for the CVE lookup (a warning says so on stderr), but its presence still satisfies the missing-lockfile check too.

Commands

| Command | What it does | |---|---| | shipsafe scan [path] | Scan a directory or file for security vulnerabilities | | shipsafe init | Create a .shipsafe.yml config file | | shipsafe login | Log in to your ShipSafe account | | shipsafe logout | Log out | | shipsafe whoami | Show login status and plan info | | shipsafe ignore <rule-id> | Suppress a rule in future scans | | shipsafe unignore <rule-id> | Re-enable a suppressed rule | | shipsafe false-positive <rule-id> | Report a finding as a false positive (helps tune the rule) |

Run shipsafe <command> --help for options.

What it scans

Static analysis (rules + entropy) for the issues AI builders most often ship: hardcoded secrets, missing or broken authentication, IDOR patterns visible within a single file, insecure configuration, exposed sensitive data, and known vulnerabilities in your dependencies. The CLI scans your local code; the deeper AI analysis and the live-deployed-app scan run through your ShipSafe account.

Dependency vulnerability lookup, on every scan. Whether or not you're logged in, the package names and exact versions found in your lockfiles are sent to api.osv.dev — Google's free, no-auth open-source vulnerability database — to check for known CVEs. Lockfiles are parsed locally; only the resolved (package name, version) pairs leave your machine for this lookup, never the lockfile's raw contents. requirements.txt is one of the six formats this feeds (see "What it can't find" above); since it isn't a resolved lockfile, only its pinned package==version lines give this lookup a single version to check — an unpinned or range-specified line (package>=1.0) is skipped. If the lookup can't complete (offline, or api.osv.dev errors), the scan prints a warning on stderr and shows no all-clear; a failed lookup does not by itself make --ci exit non-zero.

CLI access is bundled with the Growth and Shield plans. See pricing and docs at ship-safe.co.

License

Proprietary. Copyright (c) 2026 ShipSafe. All rights reserved. This package is licensed, not sold, and may be used only to interact with the ShipSafe service in accordance with the Terms of Service. See the bundled LICENSE file.