Cost / License
- Freemium (Subscription)
- Open Source
Application type
Platforms
- Online
- PHP

NPMScan is described as 'Security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used' and is an website in the security & privacy category. There are more than 25 alternatives to NPMScan, not only websites but also apps for a variety of platforms, including SaaS, Mac, Self-Hosted and Windows apps. The best NPMScan alternative is GitHub, which is free. Other great sites and apps similar to NPMScan are Artemis Security Scanner, Mend Renovate, Libraries.io and Aikido Security.

vet is a tool for protecting against open source software supply chain attacks. To adapt to organizational needs, it uses an opinionated policy expressed as Common Expressions Language and extensive package security metadata including:


