Flags install scripts, missing or sha1 integrity, http, git and off-registry tarballs in package-lock.json: the third-party component check behind EU CRA Art. 13(5). 8 rules, line numbers. Runs entirely in your browser — nothing is uploaded.
Same engine as the VS Code extension, byte for byte.
This page is the working piece. The full pack has everything below.
npm install scripts, integrity and sources under EU CRA Art. 13(5)
Buy the full version — $29· ReadyStack
Real numbers from this tool, line by line.

6 findings in one package-lock.json: that is what a JavaScript developer shipping a product into the EU gets from the sample lockfile bundled with Lockfile Due Diligence, and each finding is a third-party component question the Cyber Resilience Act will ask from 2027-12-11.
The six entries are ordinary. sharp 0.33.5 has "hasInstallScript": true, so it runs code on every npm install. ms 2.0.0 carries only a sha1 integrity hash. left-pad 1.3.0 is resolved over plain http://. tiny-csv comes from git+ssh and follows #main, so the code you install tomorrow may not be the code you reviewed today. pdf-sign is a tarball from cdn.acme-files.net, a host that is not the npm registry. And the root package asks for left-pad at "latest". The same lockfile with those six entries fixed scores 0.
Why the date matters. Regulation (EU) 2024/2847, Article 13(5), says manufacturers shall exercise due diligence when integrating components sourced from third parties, including free and open-source components. The main obligations apply from 2027-12-11; vulnerability reporting under Article 14 already applies from 2026-09-11. Article 64(2) sets fines of up to 15 million euros or 2.5% of worldwide annual turnover for breaching Article 13. Every message the lint writes ends with the days left until 2027-12-11: 440 on 2026-09-27.
Why npm audit does not cover it. npm audit compares your tree with published advisories. That is useful, but it answers a different question. A package that runs a postinstall script, arrives over http, comes from an unknown host or carries only a sha1 hash passes npm audit when nobody has filed an advisory against it. Those are exactly the entries where a reviewer has to decide: do we know what this component runs, where it came from, and that the bytes are the ones we checked?
The 8 rules: LDD001 install script (hasInstallScript: true). LDD002 resolved but no integrity. LDD003 sha1-only integrity. LDD004 http:// tarball. LDD005 git source (git+, github:, git@). LDD006 https tarball from a host other than registry.npmjs.org, registry.yarnpkg.com or registry.npmmirror.com. LDD007 lockfileVersion 1 or missing, because version 1 files do not record hasInstallScript at all. LDD008 a direct dependency on *, latest, next, x or an empty range.
Three more lockfiles, three different answers. An agency front end with esbuild and a git-hosted ui-kit gives 2 findings: the esbuild install script and the #main git source. A legacy admin panel still on lockfileVersion 1 gives 3: the version itself, request over http, and a sha1-only hash. An IoT dashboard checked on 2028-01-15 gives 3: chart-lib on "*", sensor-sdk from a vendor host, and no integrity on that tarball; its messages say the duty applies since 2027-12-11 instead of counting down.
How to use it. Open any package-lock.json in VS Code and the findings land in the Problems panel with rule id, package@version, line and fix. Or paste the file into the free web version, which runs the same engine in your browser; nothing is uploaded.
What is free. The free scan covers one package-lock.json with all 8 rules and no scan limit. The full version adds the next job: scanning every lockfile in a workspace at once and exporting a dated due-diligence record in Markdown and CSV to keep with your technical documentation.
What it is not. It reads lockfile metadata only. It does not download packages, read the scripts themselves, or decide whether a script is malicious. It shows where a human decision is due, with the line number to start from.
It reads a package-lock.json and flags 8 kinds of entries: packages with install scripts, tarballs with no integrity hash, sha1-only hashes, http tarballs, git sources, tarballs from hosts other than the npm registry, lockfileVersion 1 files, and direct dependencies on *, latest, next, x or an empty range. Each finding shows the line, package@version and the fix.
JavaScript and TypeScript developers, agencies and product teams who ship software into the EU and must exercise due diligence on third-party components under the Cyber Resilience Act, Article 13(5), from 2027-12-11. It also suits anyone reviewing a pull request that changes package-lock.json and wanting to see which new entries run code on install.
npm audit compares your dependency tree with published security advisories. A package that runs a postinstall script, arrives over plain http, comes from an unknown host, or carries only a sha1 hash passes npm audit when no advisory exists for it. This lint reports those lockfile entries, which are the component decisions CRA Article 13(5) asks you to make.
The free version scans one package-lock.json in the editor and shows every finding from all 8 rules, with its line and fix, with no scan limit. The full version, $29 once with one licence key per person or team seat, scans every lockfile in the workspace at once and exports a dated due-diligence record in Markdown and CSV for your technical documentation.
Article 64(2) of the Cyber Resilience Act allows fines of up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher, for breaching the manufacturer obligations in Article 13, which include due diligence on third-party components. Those obligations apply from 2027-12-11. The free scan shows your own lockfile findings before you pay anything.
A general AI chat answers from training data with a cutoff date, cannot read your repository and names no rule version. Lockfile Due Diligence checks the file you open against 8 rules from a rule set dated 2026-09-27, and points at the exact line with the fix. For a filing, an audit or a client you need that dated result on your own files.
One question, answered by the person who built it. Your email only if you want the answer sent.