Look up any open‑source package.
See what a package version does before you install it: malware, vulnerabilities, install scripts, publisher changes and licence, with the file and line behind every finding. Free, no account.
npm · PyPI · Maven · crates.io · RubyGems · NuGet · Go · Packagist · Hugging Face
What every report checks
93 signals in five categories, each scored and shown with its evidence.
Malware, typosquats, install scripts, publisher changes, what the code can do
Known CVEs with severity, exploitation (KEV, EPSS) and fixed versions
Declared SPDX licence, changes between versions, copyleft
Release cadence, maintainer count, downloads, archived repositories
Build provenance, checksums, minified or bundled code
Block these packages at install time
The same checks run in front of your package manager, on your machine and in CI.
curl -fsSL https://chain305.com/install.sh | sh