nowfound

Alternatives

Products that do what NPMScan does

Automated github dependency security scanner

  1. 1

    Fix vulnerabilities in Node & npm dependencies with a click.

    2016

  2. 2TT

    Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!

    Sep 2025 · github.com

  3. 3

    Know before you clone with instant GitHub security insights

    2025

  4. 4

    Make devs notice your repo

    Nov 2025

  5. 5SN

    This past quarter has been awash with sophisticated npm supply chain attacks like [Shai-Hulud](https://www.cisa.gov/news-events/alerts/2025/09/23/widesprea...() and the [Chalk/debug Compromise](https://www.wiz.io/blog/widespread-npm-supply-chain-attack-b...). This CLI helps protect users from recently compromised packages by only downloading packages that have been public for a while (default is 90 days or older). Install: npm install -g @dendronhq/safe-npm Usage: safe-npm install react@^18 lodash How it works: - Queries…

    Nov 2025 · github.com

  6. 6

    Configure once, prevent the next compromised package install

    May 2026 · depsguard.com

  7. 7
    GitJin116

    GitHub repos, issues, and PRs in one clear dashboard

    Dec 2025 · gitjin.com

  8. 8
    Pacgie6

    Secure, updated & optimized dependencies

    Sep 2025

  9. 9NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  10. 10GB
  11. 11

    Malicious npm package detection & security scanner

    Oct 2025

  12. 12
    GitBar126

    Every pull request, one menubar. GitHub, GitLab & Azure

    Apr 2026 · gitbar.app

  13. 13GA
  14. 14

    Scan and auto-fix GitHub vulnerabilities in seconds

    Apr 2026 · package-helper.up.railway.app

  15. 15DA
  16. 16SI

    In light of the ongoing npm supply chain compromises, I built safe-install: https://www.npmjs.com/package/@gkiely/safe-install It brings a couple of protections I wanted from npm but are not built in. Similar to Bun’s trusted dependencies, it lets you disable install scripts by default and define a list of dependencies that are allowed to run build/install scripts: https://bun.com/docs/guides/install/trusted It also supports blocking exotic sub-dependencies, similar to pnpm’s `blockExoticSubdeps` setting:…

    May 2026 · npmjs.com

  17. 17TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev

  18. 18
    trawld4

    catch vulnerable dependencies before they catch you

    May 2026 · trawld.vercel.app

  19. 19

    A tool to help developers stay safe with npm dependencies.

    Feb 2026 · package-sentinel.vercel.app

  20. 20

    Repo context workbench for humans and AI agents

    Jul 2026 · onboardy.dev

  21. 21SS

    If you’ve ever explored GitHub repos and felt frustrated by how little you can tell about a project’s real tech stack — you’re not alone. That’s exactly why I built StackHound https://www.producthunt.com/posts/stackhound It goes beyond the GitHub API to scan dependency files and uncover the actual tools, frameworks, and languages a repo uses — whether it's built with React, Next.js, Tailwind, Flask, or Spring Boot. Just drop in a GitHub username and repo to analyze it instantly. You can also use our /api/analyze endpoint to plug it into your own tools. Try the…

    2025 · stackhound.vercel.app

  22. 22

    Block bad npm and pip packages. Before they download.

    May 2026 · veln.sh

  23. 23

    Easy local sources of your dependencies for LLM context

    26d ago · repos-as-docs.com

  24. 24GC

Ranked by how close each launch is in meaning, then by votes. Refine with a description →