
Top picks: AuditJS, NodeSecure, npm-zoo — plus 45 more compared.
Application Securitynpm-scan is a free Software Composition Analysis tool. Security professionals most commonly compare it with AuditJS. All 48 alternatives are matched by shared capabilities, tags, and NIST CSF 2.0 coverage.
A closer look at the 8 most relevant alternatives and competitors to npm-scan, including their key features and shared capabilities.
AuditJS is a command-line tool that scans JavaScript projects for known vulnerabilities and outdated packages in npm dependencies using the OSS Index API or Nexus IQ Server.
NodeSecure is a cybersecurity project that provides security monitoring and analysis capabilities specifically designed for Node.js applications.
npm-zoo is a curated database of known malicious NPM packages that helps developers and security researchers identify and avoid potentially harmful dependencies in their projects.
Software supply chain security platform detecting malware in dependencies
Malware-resistant software libraries rebuilt from source for multiple languages
Detects and blocks malicious/vulnerable open source packages in supply chains.
Tool for searching, comparing, and evaluating open source dependencies.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
AuditJS is a command-line tool that scans JavaScript projects for known vulnerabilities and outdated packages in npm dependencies using the OSS Index API or Nexus IQ Server.
NodeSecure is a cybersecurity project that provides security monitoring and analysis capabilities specifically designed for Node.js applications.
npm-zoo is a curated database of known malicious NPM packages that helps developers and security researchers identify and avoid potentially harmful dependencies in their projects.
Software supply chain security platform detecting malware in dependencies
Malware-resistant software libraries rebuilt from source for multiple languages
Detects and blocks malicious/vulnerable open source packages in supply chains.
Tool for searching, comparing, and evaluating open source dependencies.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
An open-source framework that detects and prevents dependency confusion attacks across multiple package management systems and development environments.
Lint lockfiles for improved security and trust policies.
A tool that safely installs packages with npm/yarn by auditing them as part of your install process.
Gamma Ray is a software that helps developers to look for vulnerabilities on their Node.js applications with a pluggable infrastructure for integration with vulnerabilities databases.
A tool to run YARA rules against node_module folders to identify suspicious scripts
Package verification tool for npm with various verification and testing capabilities.
A dependency security scanner that identifies potential supply chain vulnerabilities by checking for available package namespace registrations across Python, JavaScript, PHP, and Maven repositories.
Reverts sha1 integrity back to sha512 in lock files for enhanced security.
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
SCA tool that finds, prioritizes, and fixes open source vulnerabilities
CI/CD security platform for GitHub Actions with runtime threat detection
Runtime app protection with function-level reachability and exploit prevention
AI-powered application security platform for software development
Platform for vulnerability detection in firmware, binaries, and SBOMs
AI-native AppSec platform with SAST, SCA, container & dependency mgmt.
Automated SCA tool for open source dependency management and vulnerability remediation
SCA tool for identifying vulnerabilities in open-source dependencies
SCA platform for managing open source vulnerabilities across SDLC
SCA tool for code scanning, license identification, and SBOM generation
AppSec platform for supply chain security, SBOM analysis & vuln mgmt
Universal artifact repository & software supply chain security platform
JavaScript security scanner for detecting vulnerabilities in third-party scripts
SCA tool for vulnerability detection, malicious code identification & remediation
Malware detection across SDLC, DevOps pipelines, and open-source components
SCA tool detecting vulnerabilities in third-party libraries at runtime & build
Software supply chain security platform with SCA, package firewall & threat intel
SCA tool for detecting vulnerabilities & license risks in open-source deps
Secures SDLC with malware detection, vuln scanning, SBOM gen & secret detection
SCA tool for identifying & remediating open-source vulnerabilities & risks
Detects malicious open-source packages across SDLC using 410K+ package database
Cloud-native SCA and SBOM platform for supply chain security across code to runtime
SCA tool that scans open-source dependencies for vulnerabilities and malware
Scans open-source licenses in dependencies and generates SBOMs for compliance
Full lifecycle software supply chain security platform for code integrity
SCA platform with reachability analysis, AI-powered fixes, and license compliance
Runtime SCA tool that identifies exploitable vulnerabilities in cloud environments
Runtime protection preventing supply-chain attacks & exploits via library-level policies
SBOM management platform for tracking dependencies and vulnerabilities
SCA tool for identifying & resolving vulnerabilities in dependencies
Common questions security professionals ask when evaluating alternatives and competitors to npm-scan.
The most popular alternatives to npm-scan include AuditJS, NodeSecure, npm-zoo, Aikido Software Supply Chain Security, and Chainguard Libraries. These Software Composition Analysis tools offer similar capabilities and are frequently compared by security professionals evaluating their options.