npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

pi-vuln-scanner

v0.2.1

Published

A pi extension that scans locally installed pi packages for vulnerabilities and supply-chain risk.

Readme

pi-vuln-scanner

A pi extension that scans locally installed pi packages for vulnerabilities and supply-chain risk.

Status

Early MVP. The scanner is advisory only: it warns and reports, but does not block pi package loading.

Install

pi install npm:pi-vuln-scanner

Local development/testing:

pi -e ./src/index.ts

Commands

/pi-scan              run a scan now
/pi-scan --cached     show cached result if still fresh
/pi-scan-report       show latest cached report
/pi-scan-config       show config and cache paths
/pi-scan-config init  write default config file
/pi-scan-clear-cache  clear cached scan result

What is scanned

Only locally installed pi packages are scanned:

  • global packages from ~/.pi/agent/settings.json, ~/.pi/agent/npm/, ~/.pi/agent/git/;
  • project packages from .pi/settings.json, .pi/npm/, .pi/git/ when the project is trusted;
  • local path packages referenced from pi settings.

Data sources

  • npm audit --json --omit=dev when an npm lockfile is available.
  • OSV.dev for npm package name/version lookups, including transitive dependency checks from npm lockfiles.
  • deps.dev package version metadata and advisory keys.
  • npm registry metadata for deprecation, publish age, and package metadata signals.
  • Optional Sonatype OSS Index checks when credentials are configured.
  • Local package metadata checks for lifecycle scripts, native-code indicators, missing pi manifest/resources, and basic package quality signals.

Configuration

Default config path:

~/.pi/agent/pi-vuln-scanner.json

Default config:

{
  "scanOnStartup": true,
  "scanIntervalHours": 24,
  "providers": {
    "npmAudit": true,
    "osv": true,
    "osvTransitive": true,
    "depsDev": true,
    "ossIndex": false,
    "npmRegistry": true,
    "packageMetadata": true
  },
  "thresholds": {
    "startupWarning": "high",
    "showRemoveCommand": "high"
  },
  "privacy": {
    "allowNetwork": true,
    "sendNpmPackageNames": true,
    "sendLocalPackagePaths": false
  },
  "ossIndex": {
    "usernameEnv": "OSS_INDEX_USERNAME",
    "tokenEnv": "OSS_INDEX_TOKEN"
  }
}

Privacy

The extension does not send local source code to third-party services. Network scanners send npm package names and versions only when network access and npm package-name sharing are enabled.

Removal commands

Reports include removal hints when the original pi package source is known, for example:

pi remove npm:@scope/package

Development

npm install
npm run check
npm pack --dry-run