🕵️AI Hallucination DetectionCatches imports of packages that don't exist on npm — AI slopsquatting prevention.
📦Shadow Code DetectionFlags packages used in code but missing from package.json — dead or smuggled imports.
🔍Vulnerability ScanningQueries the OSV database (batch API) for all packages including transitive deps.
⏳Package Age CheckFlags packages published less than 72 hours ago — heuristic for supply-chain attacks.
🧩Transitive Dependency AnalysisReads package-lock.json to scan deep dependencies — shows origin for each transitive vuln.
🎯Typosquatting DetectionDetects packages with names suspiciously similar to popular npm packages — catches lodah vs lodash.