Skip to main content
Chain305

Look up any open‑source package.

See what a package version does before you install it: malware, vulnerabilities, install scripts, publisher changes and licence, with the file and line behind every finding. Free, no account.

npm · PyPI · Maven · crates.io · RubyGems · NuGet · Go · Packagist · Hugging Face

What every report checks

93 signals in five categories, each scored and shown with its evidence.

Supply chain63

Malware, typosquats, install scripts, publisher changes, what the code can do

Vulnerability8

Known CVEs with severity, exploitation (KEV, EPSS) and fixed versions

License8

Declared SPDX licence, changes between versions, copyleft

Maintenance8

Release cadence, maintainer count, downloads, archived repositories

Quality6

Build provenance, checksums, minified or bundled code

Block these packages at install time

The same checks run in front of your package manager, on your machine and in CI.

curl -fsSL https://chain305.com/install.sh | sh