Waitlist open ยท 0%

Paste a package. See the supply-chain risk before you run install.

Web tool. Paste an npm, PyPI, or RubyGems package name. Get a one-page supply-chain audit in three seconds: maintainer history, postinstall script flag, recent ownership changes, install spike check, transitive risk roll-up, plain English verdict.

0of 5 on waitlist

Bring a friend who'd use this. Each signup pulls the launch closer.

See it live

$4.99 lifetime ยท or $19 / month SaaS ยท no charge today

๐ŸŒ Web toolยทdev tools

Built by someone who already shipped 30+ tools

30+
tools shipped
2,300
weekly Google impressions
35d
day-by-day streak
12
ranked in top-10

For a sense of what shipped looks like: relly.permissionlabs.com โ†—

What it does

Audit before you run install.

Click any card to jump to its deep dive below.

Who it's for

Built for these decisions.

If any of these are your question, this is the tool.

Solo dev about to npm install some-obscure-pkg

Is this package safe enough to run install on my machine?

โ†’ Verdict in three seconds. Postinstall scripts and recent maintainer changes flagged. Decide before npm runs the script.

Indie SaaS founder rotating dependencies

Did any package I depend on change owners or grow a postinstall script this month?

โ†’ Paste each top-level dep. Anything with new ownership or new install-time scripts surfaces in the verdict line.

Dev who saw the latest supply-chain headline

Am I exposed to the package the news is about?

โ†’ Paste the package and your common alternatives. Side-by-side verdicts. Pick the one that is not on fire.

Team lead choosing between two libs

Which option has fewer install-time risks today?

โ†’ Paste both. Compare verdicts, transitive risk counts, maintainer history. Pick on data instead of GitHub stars.

The problem

npm audit only catches CVEs. The real attacks ship as a maintainer takeover with a postinstall script and a six-hour window.

npm audit only catches known CVEs. The real attacks ship as a fresh maintainer takeover with a clean version number, a postinstall script, and 6 hours before the registry pulls it. 2024 to 2026 has seen six mass-compromise events on npm and PyPI alone. Solo devs and indie SaaS founders run install dozens of times a week. You either pay enterprise pricing for Snyk and a CI pipeline, or you read every package by hand. Nobody reads every package by hand.

What you'd get

Four pieces, one tool.

Each piece ships in the first build for waitlist members. SaaS upgrades layer on top.

01 ยท feature

Maintainer takeover detector

We track ownership changes per package across npm, PyPI, and RubyGems. New publisher in the last 90 days is the loudest signal in modern supply-chain attacks. We flag it on the verdict line, with the date and the prior owner, so you know whether the change matches a public handover or looks unannounced.

Pre-bill alert
โฐ
Cursor Pro renews in 3 days
$20/mo ยท last used 2 days ago
โš ๏ธ
Midjourney renews in 3 days
$30/mo ยท last used 41 days ago
02 ยท feature

Postinstall script and lifecycle flag

Postinstall, preinstall, install, and prepare scripts run code on your machine the second npm install finishes. We extract them, show the script body, and rate the risk based on what it does. Most clean packages have no install scripts. The flag turns red when one appears.

Trust signal scorecard
47
  • Real founder photo
  • Real testimonials with photos
  • OKSpecific metrics with units
  • Custom typography
  • OKCustom design tokens
  • Social proof above the fold
  • OKFooter with company details
03 ยท feature

Install spike and typosquat distance

Sudden 100x install spike on a low-attention package is a red flag. Same for a name that is one letter off a popular package (react-doom vs react-dom). We compute Levenshtein distance to the top 10K packages and surface the closest match if any are within edit distance two.

AI subscriptions detected
  • Cursor Pro
    $20/mo
  • Claude Pro
    $20/mo
  • GPT Plus
    $20/mo
  • Midjourney Standard
    $30/mo
  • GitHub Copilot
    $10/mo
  • Perplexity Pro
    $20/mo
  • ElevenLabs Creatortrial
    $22/mo
  • Replicate
    $25/mo
Monthly total$167
04 ยท feature

Plain English verdict and transitive roll-up

No 40-row CVE table. One verdict line, one reason line, one risk count. Click to expand the full transitive tree if you want it. The headline answers the only question that matters: should I run install or not.

Saved scenarios
  • Default plan
    Survives 40y
  • 2008 stress
    Year 17
  • Aggressive draw
    Year 11
  • Conservative
    Survives 40y
  • + Save current scenarioSaaS
Why paid

Today's tools don't do this.

One compromised postinstall script ships every secret in env.local to an attacker. Recovery is rotating every API key, auditing git history, and explaining to your users why the auth provider invalidated their sessions. A two-hour outage on a paid product is more revenue lost than this tool will ever cost.

โœ—Catches known CVEs only. Fresh maintainer takeover or new postinstall script with no public CVE shows zero results. The real attacks ship before any CVE exists.
Built-in
โœ—Built around GitHub OAuth, org-wide CI integration, and team workflows. Useful, but the paste-and-decide flow for one developer reading a single package is buried under setup.
$0 tier + paid team plans
โœ—Heavy CI pipeline tool aimed at security teams. Today's tools assume you have an org account and a build pipeline. A solo dev about to run install on one obscure lib has no entry point here.
Enterprise pricing
โœ—Browse a package and see its dependency tree. No verdict, no postinstall script flag, no ownership-change line. Read-only data, not a decision tool.
Browse-only
Before You Install
โœ“Paste-and-decide, not GitHub OAuth ยท Install-time risks, not just CVEs ยท Cross-ecosystem from day one ยท Plain English verdict, not a 200-row table
$4.99
Price anchor
Compared to
DevOps consultant 1hr
Their price
$150~300 / hour
What you get
Same supply-chain instinct as a senior DevOps review, $4.99 once, runs every time you paste a package. Or $19/month team tier with shared watchlists.
โœ“
What you get now

Paste box for npm, PyPI, RubyGems. Verdict line, postinstall script flag, ownership-change line, install spike check, typosquat distance, transitive risk count. Three-second response on cached packages.

โ†—
What's coming

Slack and email watchlist on packages already in your project. GitHub Action for CI. Team workspace with shared verdict history. Team tier ($19/month).

ยท
What's not included

Org-wide policy enforcement, code review of transitive deps, replacement for Snyk in regulated environments, runtime monitoring of installed packages.

Pricing

Which price would get you on the waitlist?

No charge today. The click tells me which tier is real demand. Early access price โ‰  launch price.

Join the waitlist

Want this built?

Drop your email. No charge, no spam. You're saying "yes, I'd actually use this." That's the signal I'm looking for.

Hi, I'm Hyunyoung.

Solo builder ยท Choppy Toast

This page is a quick vibe-coded probe to test demand and gather feature requests. The actual product, when it ships, will be a polished, hand-built tool, not this scaffold.

For a sense of what "polished and shipped" looks like, here's another product I built: relly.permissionlabs.com.

FAQ

Honest answers.

Then I wait. The waitlist stays live, no expiry, no archive. The faster you tell one dev who installed a sketchy package this month, the faster it ships. That is the whole engine.

More

More upcoming tools.

๐Ÿงฉ

Extension Listing Kit

SaaS

Upload each screenshot, promo tile, and description once. We resize and crop every image to the exact spec the Chrome Web Store, Firefox Add-ons, and Edge Add-ons each ask for, hold one copy of your name, summary, and description per store and per language with the character limit checked as you type, and run a pre-submit pass that names every missing or out-of-spec asset before you hit publish.

Waitlist 0%Waitlist open
๐ŸŽฌ

Video Bloat Audit

Web tool

Paste a URL. We find every autoplay and background video on the rendered page, show the real transfer weight and how much each one adds to your largest paint, estimate the monthly bandwidth bill at your actual traffic, and hand you a ranked plan to swap each clip for a poster, a lazy load, a smaller encode, or a scripted animation.

Waitlist 0%Waitlist open
๐Ÿ“‰

Decompound Calc

Web tool

See exactly when your retirement money runs out.

Waitlist 0%Waitlist open
๐Ÿ’ธ

AI Stack Cost

SaaS dashboard

One dashboard for every AI subscription you forgot about.

Waitlist 0%Waitlist open
๐Ÿ”

Vibe Check

Web tool

Find every AI-generated tell on your landing page.

Waitlist 0%Waitlist open
๐Ÿฆ

Account Stack 2026

Web tool

Tell us your income. We tell you exactly where to put each dollar across 401k, Roth IRA, HSA, and backdoor.

Waitlist 0%Waitlist open
๐Ÿ›ก๏ธ

Ad Precheck

Web tool

Paste your ad copy, image, and landing URL. Get a per-platform rejection score for Meta, Google Ads, and AdSense before you submit.

Waitlist 0%Waitlist open
๐Ÿ”ฌ

Silent AI Audit

Mac app

Find every AI model silently installed on your Mac. See the size, last access, and how to remove each one.

Waitlist 0%Waitlist open
โšก

EV Power Bill

Web tool

See your real EV charging bill before you buy the car.

Waitlist 0%Waitlist open
๐Ÿงฎ

LLM Self-host Cost

Web tool

See if self-hosting an LLM actually beats the API bill.

Waitlist 0%Waitlist open
๐ŸŽ

App Store Precheck

Web tool

Paste your app metadata, screenshots, and Info.plist. Get a per-guideline rejection score before you hit Submit for Review.

Waitlist 0%Waitlist open
๐Ÿ›๏ธ

UK Stamp Duty Surcharge

Web tool

Stack the non-resident surcharge, additional property, and first-time buyer relief in one calculator. See your real SDLT before you exchange.

Waitlist 0%Waitlist open
๐Ÿ›ก๏ธ

Vibecode Audit

Web tool

Find the 12 security holes Cursor, Lovable, v0, and Bolt leave open by default. Paste your URL, get a report your investor will not flag.

Waitlist 0%Waitlist open
๐ŸŒถ๏ธ

Spice Graveyard

iOS app

Scan the spice rack once. Get told what to cook tonight with the bottles you already own, and stop buying duplicates.

Waitlist 0%Waitlist open
๐Ÿ 

Home Addition Cost

Web tool

Paste a contractor bid for your home addition. Get a line-by-line read on what is fair, what is padded, and what scope cut drops the total without losing the room.

Waitlist 0%Waitlist open
๐Ÿ’Š

Accutane Tracker

iOS app

Log your Accutane course like the dermatologist would. Daily lip dryness, side-effect severity, dose ladder, blood-draw reminders, and a photo timeline that shows where week 12 actually got you.

Waitlist 0%Waitlist open
๐Ÿงด

PIH Fade Plan

Web tool

Tell us your skin type, breakout history, and how much post-acne brown is left. Get a 16-week active routine that switches between azelaic, niacinamide, vitamin C, and tretinoin based on how your skin actually reacts in week 2, 4, 8, and 12.

Waitlist 0%Waitlist open
๐Ÿงน

Tailwind Exit Plan

Web tool

Paste a Tailwind component or a repo URL. Get a structured CSS migration plan that pulls out reusable classes, scaffolds CSS modules with design tokens, and hands the team a 4-week refactor schedule with the file to open on Monday.

Waitlist 0%Waitlist open
๐Ÿ–ฅ๏ธ

VMware Exit Plan

Web tool

Paste your VMware renewal quote, host counts, and license SKUs. Get a per-hypervisor cost split across Proxmox, Hyper-V, OpenShift, and Nutanix, the migration hour estimate, and a 90-day cutover schedule that names the cluster to drain first.

Waitlist 0%Waitlist open
๐Ÿ‘ถ

Child Investment Planner

Web tool

Type your kid's age, your monthly budget, and your tax bracket. Get a side-by-side projection for 529, UTMA, and Roth IRA at age 18, the contribution that fits your budget, and the one-page memo that names the account to open first.

Waitlist 0%Waitlist open
๐Ÿšช

RMM Escape Plan

Web tool

Paste your NinjaOne invoice, endpoint count, and add-on list. Get your real all-in per-endpoint cost, a dated cancellation letter that respects the 60-day notice clock, and a migration matrix scored to your size across Action1, Level.io, Endpoint Central, and Syncro.

Waitlist 0%Waitlist open
๐Ÿฆ

Bank Freeze Exit Plan

Web tool

Type your monthly cash flow, your balance range, and your current business bank. Get a freeze-risk score for every provider, the morning-of runbook if your account locks, a named backup account at a second institution, and a one-page memo for your bookkeeper.

Waitlist 0%Waitlist open
๐Ÿ”Œ

Host Lock-In Escape

Web tool

Paste your host, plan tier, and what you deploy. Get a lock-in risk score across Netlify, Vercel, Render, Fly.io, and Cloudflare Pages, a redeploy config built from your own env vars and redirects, and a one-page runbook for the morning your account gets suspended with the site still live.

Waitlist 0%Waitlist open
๐Ÿ“‹

After-Death Money Checklist

Web tool

Tell us the state and the rough size of the estate. Get whether you can skip full probate, which bills you actually have to pay and which die with the person, the order to notify the banks and the agencies, and a one-page memo for the family.

Waitlist 0%Waitlist open
๐ŸŒก๏ธ

Heat Safety Planner

Web tool

Tell us who is going outside, what they are doing, and your zip code. Get a clear go, modify, or cancel call for today's heat, the work-rest and water schedule for those conditions, the early heat-illness signs to watch in that specific person, and the safe hours to move it to.

Waitlist 0%Waitlist open

5 more on the waitlist and I build this.

No charge today. Drop your email, lock in the early-access price, and you hear first when it ships.

Email me directly

Built by a real person. No silent vaporware.