npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

complytest

v1.3.1

Published

Open-source GDPR, WCAG 2.2 & security compliance scanner. The ESLint of web compliance.

Readme

complytest

Deterministic GDPR, WCAG 2.2 & security compliance scanner. The ESLint of web compliance.

npm version License: MIT Node.js

ComplyTest scans any website and produces deterministic pass/fail verdicts for 69 compliance rules across consent (GDPR/ePrivacy/DSA), accessibility (WCAG 2.2 A/AA/AAA), security & privacy (CSP/HSTS/COOP/TLS/PCI DSS/Privacy Sandbox), and transparency (DSA). Zero runtime JavaScript. CI/CD-native.

npx complytest scan https://your-site.com

Install

npm install -g complytest      # global
npm install -D complytest      # dev dependency
pnpm add -D complytest

On first run, Chromium installs automatically (~2 min). To install it manually:

npx playwright install chromium

Requires Node.js >= 22.

Quick start

npx complytest scan https://example.com
Results for https://example.com
Scanned in 8.3s

  Score: 62% (43/69 rules passed)
  consent          WARN  12/19
  accessibility    PASS  21/21
  security         WARN   6/19
  transparency     PASS   4/4

| Score | Meaning | |---------|-----------------------------------------------------| | 80%+ | Good — minor issues only | | 50–79% | Needs work — likely consent or security gaps | | < 50% | Critical issues — GDPR or WCAG violations likely |

Commands

| Command | Purpose | |---------|---------| | complytest scan <url> | Quick single-URL scan | | complytest run | Full config-driven scan | | complytest run-multi | Multi-site scanning | | complytest scan-batch | Batch URL scanning with concurrency + aggregate summary | | complytest diff | Compare two scan results | | complytest validate | Validate config file | | complytest digest | Weekly compliance digest | | complytest agent | Autonomous agent (once / watch) | | complytest init | Setup wizard: CMP detection, scaffold config |

Output formats

complytest scan https://example.com --format json    # also: html, csv, sarif, pdf, complicer

Fail builds in CI

complytest scan https://example.com --fail-on critical

Custom rules

Drop *.json / *.yaml rule files in a directory and load them with --custom-rules <dir>. Rule IDs must start with custom.. Ten check types are supported: selector_exists, selector_absent, selector_count, header_present, header_equals, header_not_contains, cookie_absent, text_contains, text_absent, meta_present.

What gets checked

  • Consent (19 rules) — consent effectiveness via CDP cookie interception (proves trackers actually stop after reject), DSA dark-pattern detection, consent tiers.
  • Accessibility (21 rules) — axe-core plus all 9 new WCAG 2.2 success criteria.
  • Security (23 rules) — Observatory-style CSP/HSTS/TLS/CORS/SRI/cookies, PCI DSS, Privacy Sandbox.
  • Transparency (6 rules) — DSA policy links.

Why ComplyTest

  • Deterministic — same input, same verdict. No AI/ML at runtime.
  • No injected JavaScript — scans from the outside like a real browser; nothing added to your site.
  • CI/CD-native — exit codes, SARIF, JSON. Not a SaaS dashboard.

Links

  • GitHub: https://github.com/petrkindlmann/compliance
  • Full documentation: see the project README

License

MIT