npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

impactcheck-cli

v2.3.2

Published

Pre-PR impact detection — structural + semantic + local HTML report

Readme

ImpactCheck CLI

Know what breaks before your PR merges.

ImpactCheck scans your codebase locally, builds a heuristic call graph, and shows which methods, callers, and API endpoints are structurally affected when something changes — before you raise a PR.

Important: ImpactCheck is a heuristic static analyser, not a runtime oracle. It detects structural changes in the scanned codebase only. Consumers in other services or repos are not checked. Confidence percentages are heuristic estimates, not measured probabilities.

npx impactcheck-cli@latest init
npx impactcheck-cli@latest check

Looking for impactguard-cli? Renamed to impactcheck-cli. Use: npm install impactcheck-cli


How it works

Your code changes
      ↓
npx impactcheck-cli@latest check
      ↓
 ⛔ 1 BREAKING — push blocked

  ⛔ Method Removed [95%]
     DriversService.assignNearestDriver
     callers : DriversController.assignDriver
     api     : POST /caption/assign
     detail  : 1 direct caller found in scanned codebase.
               Consumers outside this repo not checked.

Quick start

# Setup — once per project (auto-detects language)
cd your-project
npx impactcheck-cli@latest init

# After every code change
npx impactcheck-cli@latest check

# View full results in browser (optional, local only)
npx impactcheck-cli@latest config --web-report on
npx impactcheck-cli@latest check

Language support — honest scope

| Language | Framework | Scanner | Coverage | |---|---|---|---| | TypeScript / Node | NestJS, Express, Fastify | ts-morph AST | Strongest — full class/method/decorator analysis | | Java | Spring Boot | Regex-based | Basic — detects common patterns, misses generics, lambdas, nested classes | | Python | FastAPI, Flask | Python AST | Moderate — detects function calls, no type resolution or symbol analysis | | Salesforce | Apex, LWC | Regex-based | Beta — Apex class/trigger detection, LWC wire calls |

Language is auto-detected — no --lang flag needed:

npx impactcheck-cli@latest init
# Detected : java project    ← from pom.xml
# Detected : python project  ← from requirements.txt
# Detected : node project    ← from package.json / tsconfig.json
# Detected : salesforce project ← from sfdx-project.json

What it detects

| Change | Severity | Confidence | Notes | |---|---|---|---| | Method removed | Breaking | 95% (heuristic) | Consumers in other repos not checked | | Endpoint removed | Breaking | 95% (heuristic) | All callers will get 404 | | Signature changed | Warning | 85% (heuristic) | Caller may or may not be incompatible | | Return type changed | Warning | 80% (heuristic) | Verify caller compatibility manually | | Method renamed | Warning | 45% (heuristic) | Low confidence — verify manually |

All confidence percentages are heuristic estimates, not measured probabilities.


What it does NOT check

ImpactCheck is a heuristic static call-graph generator — not a runtime analyser:

  • Logic changes inside methods (what code does, not how it is structured)
  • Feature flag behaviour
  • Database migrations
  • Dynamic calls — service[method]()
  • Consumers in other services or repos
  • Cross-service dependencies (roadmap — Phase 3)
  • Runtime polymorphism
  • Schema compatibility in OpenAPI ($ref resolution)

These are shown at the bottom of every report.


Known limitations

  • Baseline is personal — .impactcheck/baseline.json is local and gitignored. Two developers can check the same branch against different baselines. Shared baseline across a team is a Team Plan feature.
  • Java regex coverage — common Spring Boot patterns are detected. Complex patterns (generics, lambdas, nested classes) may be missed or misattributed.
  • TypeScript identity — methods are keyed as ClassName.methodName. Common names across modules can collide. Use verbose mode to verify findings.
  • Consumer rule — only warns when a consumer is found in the scanned codebase. Missing a consumer means no warning, not safety.

Commands

# Setup
npx impactcheck-cli@latest init

# Check after every change
npx impactcheck-cli@latest check

# Check since specific commit
npx impactcheck-cli@latest check --since HEAD~1

# Combined OpenAPI + call graph
npx impactcheck-cli@latest check --base-spec old.yaml --new-spec new.yaml

# Update baseline after intentional changes
npx impactcheck-cli@latest check --update-baseline

# Configuration
npx impactcheck-cli@latest config --web-report on
npx impactcheck-cli@latest config --telemetry off

# Generate call graph manually
npx impactcheck-cli@latest generate

# Install git pre-push hook
npx impactcheck-cli@latest install-hook
---

## Feedback

Try it and tell us:
1. Did it catch something you would not have noticed?
2. Did it miss something it should have caught?
3. Was anything flagged incorrectly?

Issues: **github.com/impactcheckcli/impactguard-cli/issues**
Email: **[email protected]**

---

*ImpactCheck is a heuristic static call-graph generator. It identifies likely structural impacts and explains why they are at risk. It is not a substitute for tests, code review, or runtime monitoring.*