npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

verscan

v0.1.0

Published

Zero-dependency CLI to verify package.json, CHANGELOG.md, and git tag all share the same version — catch release mistakes before they ship.

Readme

verscan

Zero-dependency CLI to verify that package.json, CHANGELOG.md, and your latest git tag all agree on the same version number — before you ship.

$ verscan

  ✓ package.json   1.3.0  (reference)
  ✓ CHANGELOG.md   1.3.0
  ✓ git tag        1.3.0

verscan: all sources match → 1.3.0

If they don't match, you hear about it before your users do:

  ✓ package.json   1.3.0  (reference)
  ✓ CHANGELOG.md   1.3.0
  ✓ git tag        1.2.9

  ✗ git tag is 1.2.9 — expected 1.3.0

verscan: version mismatch — git differ from 1.3.0

Install

# run once without installing
npx verscan

# or install globally
npm install -g verscan

No dependencies. Node.js ≥ 18 required.

Usage

verscan [options] [dir]

| Option | Description | |--------|-------------| | --no-git | Skip git tag check (useful before you've tagged) | | --no-changelog | Skip CHANGELOG.md check | | --manifest <file> | Custom manifest path (default: auto-detect package.json or pyproject.toml) | | --changelog <file> | Custom changelog path (default: CHANGELOG.md) | | --json | Output JSON (machine-readable) | | --version | Print verscan version | | --help | Show help |

Exit codes: 0 all match · 1 mismatch · 2 parse/read error

Examples

# Check the current directory (reads package.json + CHANGELOG.md + latest git tag)
verscan

# Check before tagging — only compare package.json vs CHANGELOG.md
verscan --no-git

# Check a sub-package in a monorepo
verscan ./packages/ui

# Check a Python project (auto-detects pyproject.toml)
verscan ./my-python-lib

# Use in CI — fail the build if versions don't align
verscan || exit 1

# Machine-readable
verscan --json | jq '.ok'

How it works

  1. Reads the version from package.json (or pyproject.toml if no package.json is present)
  2. Parses the first ## [x.y.z] heading in CHANGELOG.md (supports Keep a Changelog format, bare ## x.y.z, and ## vx.y.z)
  3. Runs git describe --tags --abbrev=0 to get the latest tag (strips leading v)
  4. Compares all three — exits 0 if they match, 1 if any differ

CI integration

# .github/workflows/release.yml
- name: Verify versions aligned
  run: npx verscan
# Pre-push hook: .git/hooks/pre-push
#!/bin/sh
npx verscan --no-git || exit 1

Python projects

verscan auto-detects pyproject.toml when package.json is absent:

verscan ./my-python-package   # reads [project] version from pyproject.toml

For the Python CLI counterpart, see verscan-py.

License

MIT