npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

sourcedump

v1.1.0

Published

Recover a website's original source files from its published JS/CSS sourcemaps, like the Sources panel in Chrome DevTools

Readme

sourcedump

Recover a site's original source files from its published sourcemaps. The same thing Chrome DevTools does in the Sources panel, but on disk.

Zero dependencies. Node ≥ 18.3.

Usage

npx sourcedump -u https://example.com
sourcedump -u <url> [-o <dir>]

  -u, --url <url>     page to scan. A .js/.css/.map URL works too and skips the
                      page scan. https:// is assumed if no scheme is given.
  -o, --out <dir>     where to write the recovered files  (default: ./output)
  -c, --concat <file> write every source into this ONE file instead of a tree,
                      each preceded by a /* ==== asset :: path ==== */ banner.
                      Made for grepping the lot for secrets, TODOs, comments.
                      Overrides -o.
  -H, --header <h>    extra request header, "Name: value". Repeat for more. Use
                      it to reach assets behind a login (Cookie, Authorization)
                      or a header-based WAF. Overrides the default User-Agent if
                      you pass one. NOTE: headers go to every fetched URL, so a
                      map hosted on a third-party CDN gets them too.
  -s, --silent        print nothing on success. Fatal errors still go to stderr
                      and the exit code still tells you what happened.
  -h, --help          help text

Pull sources from a staging app that needs a session:

npx sourcedump -u app.example.com -H "Cookie: session=abc" -H "X-Env: staging"

Grep an entire site's sources in one pass:

npx sourcedump -u example.com -c all-sources.js -s && grep -nE 'api[_-]?key|secret|TODO' all-sources.js
$ npx sourcedump -u https://example.com -o ./dump
12 asset(s) found
  ok https://example.com/assets/app.4f1a.js -> 214 files
  ok https://example.com/assets/dev.bundle.js -> 631 files (598 maps)
  ok https://example.com/assets/style.9c2d.css -> 8 files
  -  https://example.com/vendor.js (HTTP 404 https://example.com/vendor.js.map)

3/12 assets, 601 sourcemaps, 853 files -> /home/you/dump

Files land under the output dir at their original paths, so webpack://app/./src/ui/Button.tsx becomes dump/app/src/ui/Button.tsx.

What it does

  1. Fetches the page and pulls <script src> / <link href> for .js, .mjs, .css.
  2. Reads every //# sourceMappingURL in each asset - external file or inline data: URI (base64 and percent-encoded). Webpack eval / eval-source-map dev bundles carry one inline map per module, hundreds in a single file; all of them are unpacked.
  3. If the comment was stripped, tries <asset>.map anyway. Many builds ship the map without the comment.
  4. Writes every sourcesContent entry to disk. Honors sourceRoot and index maps (sections).

Source paths are sanitized: .., absolute paths, UNC paths, and Windows-illegal characters can't write outside the output dir.

API

const { findAssets, decodeDataUri, extractMapRefs, entries, outPath, parseHeaders } = require("sourcedump");

Limits

Assets are found by scanning the HTML, so chunks loaded at runtime by the JS itself are missed. Fetches are sequential and not retried.

License

MIT