npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

saz-enforce

v2.3.2

Published

Enterprise React/Next.js code enforcement — ESLint, Tailwind, TypeScript configs + security scan, auto-fix, scoring, CI/CD, hooks by Muhammad Salman

Readme

saz-enforce

Enterprise code enforcement for React & Next.js — by Muhammad Salman

npm license

120 rules | auto-fix | scoring (A+ to F) | perf audit | security scan | HTML dashboard | feature tracker | CI/CD | zero runtime deps


New Project

npm install -D saz-enforce
npx saz init

Asks 8 questions (team, framework, language, typography, animations, Kafka, i18n, theme) and generates:

  • Complete project scaffold (React/Vite or Next.js, JS or TS)
  • Redux store, Axios service layer, useForm hook, design tokens
  • ESLint, Tailwind, TypeScript, PostCSS configs (auto-detect versions)
  • Standards docs, CLAUDE.md for AI tools, package.json scripts

Existing Project

npm install -D saz-enforce
npx saz status                     # see what's set up vs missing
npx saz check --report             # find all violations
npx saz fix                        # auto-fix what's fixable
npx saz baseline                   # freeze current violations
npx saz check --baseline --report  # CI only fails on NEW violations

npx saz status output:

  Foundation
    ✓ package.json
    ✓ React          node_modules/react/package.json
    ✓ Next.js        node_modules/next/package.json
    ✗ saz-enforce    → npm install -D saz-enforce

  Core Files
    ✓ Axios instance  src/services/axiosInstance.ts
    ✓ Redux store     src/store/index.ts
    ✗ useForm         → npx saz init

  Optional
    ⬚ Kafka queue    (not installed)
    ⬚ i18n           (not installed)

  Code Quality (47 violations)
    ████████████████  src/components/  32
    ██████            src/store/       8

  Health: █████████████████████████░░░░░  83%
  • ✓ = found (with file path)
  • ✗ = required but missing (must fix)
  • ○ = recommended (should fix)
  • ⬚ = optional (your choice)

Commands

# Scan & Fix
npx saz check              # interactive audit (file by file)
npx saz check --report     # CI mode (exit 1 on violations)
npx saz check --fix-all    # auto-fix all fixable violations
npx saz check --baseline   # only new violations above baseline
npx saz check --changed    # only git-changed files
npx saz fix                # auto-fix + ESLint --fix + Prettier
npx saz watch              # real-time scan on save

# Analyze
npx saz score              # grade A+ to F across 12 categories
npx saz perf               # rendering performance audit (layout, paint, CWV)
npx saz security           # security vulnerability scan
npx saz status             # project health report with file paths
npx saz dashboard          # interactive HTML report (opens browser)
npx saz rules              # list all 120 active rules

# Automate
npx saz hooks              # install pre-commit hooks
npx saz ci --github        # generate GitHub Actions workflow
npx saz baseline           # freeze violations for incremental CI

# Setup
npx saz init               # scaffold project
npx saz arch --fix         # auto-create missing directories
npx saz claude             # generate CLAUDE.md for AI tools
npx saz doctor             # detect version drift
npx saz eject <target>     # make config standalone
npx saz migrate            # interactive migration with backup

Most commands support --json and --dir <path>.


Configs

// ESLint (auto-detects v8 legacy / v9 flat config)
module.exports = require("saz-enforce/configs/eslint");     // JS
module.exports = require("saz-enforce/configs/eslint-ts");  // TS

// Tailwind (auto-detects v3/v4)
module.exports = { presets: [require("saz-enforce/configs/tailwind")] };

// TypeScript + Prettier
{ "extends": "saz-enforce/configs/tsconfig.json" }
module.exports = require("saz-enforce/configs/prettier");

120 Rules

| Category | Count | Examples | |------------------|-------|--------------------------------------------------| | Code Quality | 21 | No var, strict equality, no magic numbers | | Performance | 17 | Layout thrashing, passive scroll, image CLS/LCP | | Security | 16 | No eval, no localStorage tokens | | Accessibility | 13 | alt text, onKeyDown + onClick, 44px touch targets | | Type Safety | 12 | No any, no assertions, prefer ?? | | React Patterns | 12 | No index keys, no inline handlers | | HTML5 Semantics | 12 | <dialog>, <nav>, <header>, <time> | | CSS / Tailwind | 6 | Design tokens only, no raw colors | | Design Lint | 6 | Deprecated tokens, focus-visible | | Data Fetching | 5 | Axios instance, abort signals |

Plus Project Structure and Config Setup in scoring (12 categories total).


Optional Features

Configured during npx saz init:

  • Design Patterns — 14-token typography, HSL colors, landing page templates
  • Animations — 11 CSS keyframes, RevealSection, StaggerGrid, TiltCard
  • Kafka Queue — createQueueThunk, GlobalMessageBar, dev simulator
  • i18n — i18next + RTL, English + Arabic, LanguageSwitcher
  • Theme System — Light/Dark + 5 static themes, ThemeProvider
  • BMAD Agents — 7 AI agents + MCP config for Claude Code/Cursor/Windsurf

Custom Rules

// saz.rules.js — add project-specific rules
module.exports = [
  { id: "no-moment", description: "Use date-fns", severity: "error",
    test: (line) => /\bmoment\s*\(/.test(line) },
];
// saz.config.json — override severity
{ "rules": { "no-console": "off", "no-any": "warning" } }
// Inline suppression
const x = eval(code); // saz-ignore sec-eval-usage

Requirements

  • Node.js >=16.0.0 — zero runtime dependencies
  • ESLint >=8.0.0 | Tailwind >=3.0.0 | TypeScript >=4.9.0 (all optional)
  • Skip postinstall: SAZ_SKIP_POSTINSTALL=1 npm install saz-enforce

Muhammad Salman — GitHub | npm | MIT License