Check your dependencies
Paste a package.json or a requirements.txt. Presend reports names close to popular packages (typosquats), names that do not exist, packages first published less than 30 days ago, and, for npm, recent publisher changes after a long dormancy.
Your file is not uploaded: this page reads it in your browser and sends only the package names to Presend's API. Up to 100 dependencies per check; per-minute rate limits apply.
| Package | Result | Details |
|---|
What this page does not check
- Known vulnerabilities of the versions you use: the GitHub Action checks them with OSV.dev, for the version in your
package-lock.json; or search osv.dev. - Publisher changes on PyPI: PyPI does not expose who published each release, so this check is npm only. On PyPI, the age shown is that of the oldest release still published; deleted releases make a project look younger.
- Malware. These are signals worth a look before installing, not an analysis of the package code.
Every time, automatically
The same checks run in CI with the GitHub Action, and before an AI agent installs a package with the Claude Code and Cursor hook or the MCP server at https://presend.pages.dev/mcp. How often they raise false alarms is measured on the most downloaded packages: measurements.
Want these checks on every pull request for your team? Join the waitlist.