The free CLI finds
A package one edit-distance from chalk (possible typosquat); a transitive dependency with a postinstall script; a package.json range pointing at an http tarball; a lockfile entry missing integrity.
A free CLI (npx github:st0rm-bless3d/depaudit) statically flags typosquats, install scripts, and risky lockfile entries. The paid report triages every flag into block / pin / ignore with concrete replacements and a ready-to-apply lockfile diff.
No contact details, checkout, or payment. Measurement retains a random per-tab ID, IP address, browser user agent, referrer, page, and classification so internal and automated traffic can be excluded.
A package one edit-distance from chalk (possible typosquat); a transitive dependency with a postinstall script; a package.json range pointing at an http tarball; a lockfile entry missing integrity.
Every flag across the full dependency tree ranked block-now / pin / ignore, a concrete replacement package for each block-now item, and a ready-to-apply lockfile diff, re-resolved in a clean container to confirm it still installs and builds.
Representative synthetic excerpt. The free CLI reads only your project files and sends nothing out. The paid report is produced from the dependency graph you provide, with independent QA before delivery.