Eu cra article 13 checklist — check your lockfile free
Flags install scripts, missing or sha1 integrity, http, git and off-registry tarballs in package-lock.json: the third-party component check behind EU CRA Art. 13(5). 8 rules, line numbers. Runs entirely in your browser — nothing is uploaded.
Free here: Scan one package-lock.json: every install script, weak or missing integrity, http, git and off-registry source, with its line and the fix.. In the editor: Scan every lockfile in the workspace at once and export a dated due-diligence record (Markdown and CSV) for your CRA technical documentation. — that part asks for a licence key.
Same engine as the VS Code extension, byte for byte.