Package health index
Is that package healthy, maintained, and safe?
Free, deterministic health snapshots for 35 popular open-source packages across npm and PyPI — each with a 0–100 score and a full, auditable evidence trail. Data from the public registries and OSV.dev.
npm
24 packages · worst-first0momentv2.30.1Critical0colorsv1.4.0Critical0flatmap-streamv0.0.1-securityCritical3event-streamv4.0.1Critical9node-fetchv3.3.2Critical10fakerv6.6.6Critical10jsonwebtokenv9.0.3Critical10minimistv1.2.8Critical13coav2.0.2Critical17passportv0.7.0Critical18rcv1.2.8Critical20bowerv1.8.14High24requestv2.88.2High25jqueryv4.0.0High34socket.iov4.8.3High35lodashv4.18.1High35classnamesv2.5.1High35is-promisev4.0.0High35left-padv1.3.0High35ua-parser-jsv2.0.10High40axiosv1.20.0Medium40node-ipcv14.0.0Medium50vitev8.2.2Medium55nextv16.3.4Medium
PyPI
11 packages · worst-firstSnapshot generated 2026-09-07 · npm + pypi · scores recomputed on each refresh.
