npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

secretfence

v0.1.0

Published

Stop secrets before they ever leave your machine. A fast, local-first, developer-friendly secret scanner and pre-push guard for Git repositories.

Readme

SecretFence

Stop secrets before they ever leave your machine.

SecretFence is a fast, local-first CLI that catches hardcoded API keys, passwords, and credentials before they get pushed to GitHub, GitLab, Bitbucket, or Azure DevOps — built for the developer experience of JavaScript/TypeScript teams, with 41 built-in detectors, real multi-core scanning, and zero cloud dependency.

✓ 650 files scanned

Found
🔴 High 2   🟠 Medium 4   🟡 Low 1
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🔴 High  AWS Secret Access Key
File      src/config/aws.ts:28:12
Risk      Anyone with this key may access your AWS account.
Fix       Move to .env and rotate the key immediately.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

 Push Blocked 

Why SecretFence

  • Fast — scans 10,000 files in ~1.2 seconds on a single core using a worker-thread pool; scales with available CPU cores.
  • Private — everything runs locally. No account, no cloud upload, no telemetry. The only network calls are an optional version check (secretfence update) and an opt-in live-credential-validation flag (--validate), both off unless you ask for them.
  • Low false positives — regex + entropy scoring, plus automatic suppression for test/fixture/doc files and placeholder values, means fewer "cry wolf" findings than a bare-regex scanner.
  • Actionable output — every finding includes exactly what to do about it: which key, where, how confident, and the specific rotation step.
  • Extensible — add detectors via config (customRules), or publish a secretfence-plugin-* package. Adding a detector never requires touching scanner internals.

Quick start

npm install -g secretfence

cd your-repo
secretfence scan          # scan everything
secretfence install       # add a pre-push hook that blocks High/Critical secrets
secretfence doctor        # verify your setup

See docs/installation.md for dev-dependency and CI setup, and docs/configuration.md for .secretfence.json options.

Usage

secretfence scan                          # scan the whole repo
secretfence scan ./src                    # scan a folder
secretfence scan ./src/config.ts          # scan a single file
secretfence scan --staged                 # scan files staged for commit
secretfence scan --diff                   # scan files changed vs HEAD
secretfence scan --commit <sha>           # scan a specific commit
secretfence scan --min-severity high      # only report high/critical
secretfence scan --format sarif --output results.sarif   # for GitHub code scanning
secretfence report --format html          # export a standalone HTML report
secretfence ignore "legacy/**"            # add a pattern to .secretfenceignore
secretfence config                        # show the resolved configuration
secretfence benchmark                     # measure scan throughput

Every command supports --help. The short alias sf works everywhere secretfence does.

| Command | Purpose | |---|---| | scan | Scan for secrets (see modes above) | | install / uninstall | Manage the pre-push Git hook | | doctor | Diagnose your setup | | init | Create a .secretfence.json | | config | Show the resolved configuration | | ignore <pattern> | Add a pattern to .secretfenceignore | | report | Run a scan and export json/markdown/html/sarif | | update | Check for a newer version | | version | Print the current version | | benchmark | Measure scan throughput on synthetic files |

What it catches

41 detectors across cloud (AWS, GCP, Azure, DigitalOcean, Cloudflare), AI providers (OpenAI, Anthropic, Gemini), payments (Stripe, PayPal, Razorpay), VCS platforms (GitHub, GitLab, Bitbucket, Azure DevOps), messaging (Slack, Discord, Twilio, SendGrid), databases (MongoDB, Postgres, MySQL, Redis, Supabase, Firebase), cryptographic material (RSA/ PEM/OpenSSH/PGP private keys), and generic patterns (JWTs, bearer tokens, basic auth, OAuth secrets, .env files). Full list with detector IDs: docs/detectors.md.

CI integration

# .github/workflows/secretfence.yml
- run: npx secretfence scan --min-severity high --format sarif --output results.sarif
- uses: github/codeql-action/upload-sarif@v3
  with:
    sarif_file: results.sarif

Security

Matched secret values are masked before they ever leave the detection layer — every output format (terminal, JSON, Markdown, HTML, SARIF) shows only a masked value like sk-a****************9fd, never the raw credential. See SECURITY.md for the full policy and how to report a vulnerability.

Documentation

License

MIT — see LICENSE.