Try:
See what's inside any npm package
without installing it
Static analysis + sandboxed execution in isolated V8 isolates at the edge. Zero network access.
sandboxscan — hono@^4.0.0