npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

opencode-js-bounty

v1.0.2

Published

Opencode plugin for automated JS bundle bug bounty analysis and UI tracking

Readme

🕷️ OpenCode JS Bounty Hunter Plugin

NPM Version License: MIT OpenCode Plugin Twitter Follow

Plugin UI Screenshot

An official OpenCode plugin that automatically downloads js files, analyzes them for hidden API endpoints and local storage secrets, and spins up a beautiful local Bug Bounty Tracker UI to manage your hunt!

Installation

  1. Add the plugin to your OpenCode project by editing opencode.json:
{
  "$schema": "https://opencode.ai/config.json",
  "plugin": ["opencode-js-bounty"]
}
  1. Run npm install opencode-js-bounty (or whatever your package manager uses to install it locally).

Note: The installation process will automatically register the /js-bounty command into your OpenCode CLI via a post-install hook.

Usage

Simply trigger the analysis inside OpenCode by passing a local file path or a remote URL:

/js-bounty https://example.com/assets/file.js

What happens next?

  1. OpenCode seamlessly intercepts the command and downloads the file.
  2. The plugin executes a high-speed extraction script, aggressively pulling out all `/api/`, `/v1/`, and `/jwt/` paths, along with cached `llab-` secrets.
  3. The data is saved to `tracker-state.json`.
  4. A stealthy local UI server boots up at http://localhost:49152.
  5. OpenCode replies with a single link to click. No terminal clutter!

Features

  • Zero Configuration: Just pass a URL and get a full dashboard.
  • Plannotator-Style UI: A dark-mode, split-pane React application built-in.
  • Persistent State: Notes, statuses, and checkboxes are instantly saved to disk locally.
  • Auto-Categorization: Automatically separates hidden localStorage keys from standard REST APIs.

Author & Support

Created with ❤️ by Ahmed Yasser

If this tool helped you secure a sweet bounty, consider starring the repo or reaching out on Twitter/X (@spxios)!