See it for yourself.

Pick two versions of a real npm package. Vigilance compares them and flags any file that can do something the old version could not. It reads the files. It never runs the package.

Type any npm package to compare two of its versions.

demo-utils 1.0.0 → 1.1.0
loading…

Vigilance reads files. It never runs the package. The reconstructed samples ship as fixed copies, because npm removed the real malicious versions. A live diff has a size cap and a rate limit. Very large packages do not run here.