Scan your dependencies
Upload your package.json and the tool checks every dependency against the OSV and GitHub Advisory databases for known CVEs and GHSAs.
Check package health
See which packages are outdated, deprecated, abandoned, or have a single maintainer. Review licenses including copyleft detection at a glance.
Detect supply-chain script risks
Static analysis of npm lifecycle scripts (postinstall, preinstall) and commands for network exfiltration, env access, code execution, and obfuscation patterns.
Generate fix commands
Get a copyable npm install command with suggested fix versions for every vulnerable or outdated package, ready to paste into your terminal.
Export for CI/CD
Download results as SARIF for GitHub Code Scanning, JSON for programmatic processing, or Markdown for pull request comments.
Package Audit runs entirely in your browser tab. No data is uploaded, no server processes your input, and no account is required.

Encode and decode Base64 for text, files, images, audio, and video.
Encoding & Data
Format, validate, minify, and explore JSON with tree, table, and map views.
Encoding & Data
Preview and debug Open Graph and Twitter Card social share metadata.
Web & Network
Inspect WHOIS, DNS, SSL, IP geolocation, and certificate transparency.
Web & Network