PACKAGELOCKAUDIT · PROFESSIONAL BROWSER TOOL

Lay out the locked tree, sources, and integrity fields before installing dependencies.

Inspect npm v7+ package-lock.json lockfileVersion, package locations, versions, root direct dependencies, resolved hosts, SRI syntax, and link entries locally.

Open the workbench
Processed locally
Local report studioPreview · Markdown · JSON · SHA-256
SHA-256

Uses only the currently visible result summary, never input controls or original files; the fingerprint is also calculated locally.

Local analysis checkpointsUp to 5 · saved only when you choose

    Stores only the visible result summary, time, and an optional short label; imported files and input controls are never stored. Imports must match this tool and stay under 128KB; comparison also stays on this device.

    01

    Package-location and version ledger

    02

    Root-direct and package dependency counts

    03

    Resolved hosts and SRI syntax

    It installs nothing, contacts no registry, and does not prove content hashes, reproducibility, vulnerabilities, malicious code, or licenses.

    Read the source

    NO ACCOUNT · LOCAL PROCESSING · EXPORTABLE

    Professional tools can still be quiet and transparent.

    Read privacy and limitations →