npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

vaultgram

v0.1.0

Published

Your entire Google account, mirrored into your own Telegram — encrypted, scheduled, one /restore away.

Readme

Vaultgram

Your entire Google account, mirrored into your own Telegram — encrypted, scheduled, one /restore away.

Vaultgram is a self-hosted daemon that backs up your Google data (Drive, Photos, Gmail, Contacts, Calendar) into a private Telegram channel you control, with every byte sealed client-side before it leaves your machine.

Why

  • Google Photos originals are no longer downloadable via API (Google policy change, March 2025). The only full-fidelity export path is Google Takeout — so Vaultgram automates Takeout instead of pretending an API can do it.
  • Telegram gives you effectively unlimited storage in a channel you own. Nobody else automates Google as the source, and nobody else restores into Google. That's the product.
  • Existing Telegram-storage tools (TAS, TeleVault, TGCloud) take local files. Vaultgram's source is your Google account; its control plane is the bot in your pocket.

Status

v0.1 — core under construction. Done and tested:

  • [x] Crypto envelope: scrypt-derived master key, AES-256-GCM per-chunk sealing (VGK1 wire format), tamper-evident by construction
  • [x] Chunker: 48 MiB Bot-API-safe chunks, planned/read straight off disk (no full-file loads)
  • [x] SQLite index: file → ordered chunks → Telegram message ids, WAL mode, wholesale chunk-list replacement per snapshot

Next up:

  • [ ] Telegram uploader + pair flow (bot token → private channel)
  • [ ] Drive incremental backup via the changes feed
  • [ ] Restore roundtrip (/restore <path> — decrypt, reassemble, sha256-verify, send back)
  • [ ] Scheduled Takeout watcher for Photos/Gmail
  • [ ] Retention pruning, doctor, Docker one-liner

Security model

  • Your passphrase never leaves the machine; Telegram stores only ciphertext it cannot decrypt (AES-256-GCM, scrypt N=2^15 key derivation).
  • Chunks are verified against their SHA-256 on every restore.
  • The salt stays in the local keystore. Lose the passphrase and the salt together and the vault is gone — that's the point.

Honest limits

Using Telegram channels as bulk storage is not an explicitly intended use of Telegram and sits in a gray area of its Terms of Service; Telegram can delete content. Treat Vaultgram as an offsite copy, never your only backup.

License

Apache-2.0