Products
Platform
// dashboard, proxy & brain
XYZ Scanner
// the CLI
VSCode extension
// inline in your editor
Pricing
Resources
Blog
// research notes
Research
// the methodology
Case studies
// attacks we caught
Docs
// CLI & API
Partners
Login
Book a demo →
Package reports
npm package
security reports.
128 packages checked against the XYZ decision brain. Or
check any package live
.
ajv
npm
block
angular
npm
allow
axios
npm
block
babel-loader
npm
allow
bcrypt
npm
allow
bcryptjs
npm
allow
body-parser
npm
alert
bootstrap
npm
alert
chai
npm
alert
chalk
npm
allow
chart.js
npm
allow
cheerio
npm
alert
chokidar
npm
alert
classnames
npm
alert
clsx
npm
allow
coa
npm
block
colors
npm
block
commander
npm
allow
concurrently
npm
allow
cors
npm
allow
cross-env
npm
allow
cypress
npm
block
d3
npm
allow
date-fns
npm
alert
dayjs
npm
alert
debug
npm
allow
dompurify
npm
allow
dotenv
npm
allow
esbuild
npm
allow
eslint
npm
allow
eslint-scope
npm
block
event-stream
npm
block
express
npm
alert
faker
npm
block
fastify
npm
allow
flatmap-stream
npm
block
form-data
npm
allow
formik
npm
allow
fs-extra
npm
allow
glob
npm
allow
got
npm
alert
hapi
npm
allow
helmet
npm
allow
highlight.js
npm
allow
immer
npm
allow
inquirer
npm
allow
ioredis
npm
allow
jest
npm
allow
jest-canvas-mock
npm
block
joi
npm
allow
jquery
npm
allow
js-yaml
npm
allow
jsdom
npm
alert
jsonwebtoken
npm
allow
koa
npm
allow
left-pad
npm
allow
less
npm
allow
lodash
npm
allow
luxon
npm
allow
markdown-it
npm
allow
marked
npm
allow
minimist
npm
allow
mkdirp
npm
allow
mobx
npm
allow
mocha
npm
allow
moment
npm
allow
mongoose
npm
allow
morgan
npm
allow
multer
npm
allow
mysql2
npm
allow
nanoid
npm
allow
nest
npm
allow
next
npm
allow
node-fetch
npm
allow
node-ipc
npm
block
nodemon
npm
allow
nuxt
npm
allow
ora
npm
allow
parcel
npm
allow
passport
npm
allow
pg
npm
allow
pino
npm
allow
playwright
npm
block
postcss
npm
alert
prettier
npm
alert
prisma
npm
alert
puppeteer
npm
allow
qs
npm
allow
query-string
npm
allow
ramda
npm
allow
rc
npm
block
react
npm
allow
react-dom
npm
allow
react-hook-form
npm
alert
react-router-dom
npm
alert
redis
npm
block
redux
npm
alert
rimraf
npm
allow
rollup
npm
block
rxjs
npm
allow
sanitize-html
npm
allow
sass
npm
alert
semver
npm
allow
sequelize
npm
allow
sharp
npm
allow
socket.io
npm
allow
styled-components
npm
allow
superagent
npm
allow
svelte
npm
alert
tailwindcss
npm
alert
three
npm
alert
typescript
npm
alert
ua-parser-js
npm
block
underscore
npm
allow
undici
npm
alert
uuid
npm
alert
validator
npm
allow
vite
npm
alert
vitest
npm
block
vue
npm
allow
webpack
npm
alert
winston
npm
allow
ws
npm
allow
xml2js
npm
allow
yargs
npm
allow
yup
npm
allow
zod
npm
alert
zustand
npm
alert