npmjs.org favicon

npmjs.org

Category: Technology

Scanned: Jul 14, 2026, 03:58 AM UTC · First seen: Jul 14, 2026 · Threat Engines: 0 / 91 · Times Scanned: 1
96 / 100 Trust Score Based on scan findings at the time of analysis
No Threats Found
0 - High Risk50 - Moderate100 - No Threats
Fresh scan recommended
Last scanned 18 days ago - security status may have changed since then.
Not scanned has not been scanned yet. Hit Scan Now to check it.

Scans can take up to 5 minutes to complete. Please keep this tab open - we'll redirect you to the report when it's ready.

Failed
Scan unavailable
Scan failed
Screenshot of npmjs.org Captured Jul 14, 2026
https://npmjs.org
Screenshot of npmjs.org
16 years
Very Popular - #4,424 Tranco rank (>10M monthly visitors)
Not listed (91 checked)
✓ Valid (TLS)
Cloudflare, Inc.
Toronto, Canada
cloudflare
Unknown
104.16.1.34
Domain & WHOIS Information
Registrar MarkMonitor Inc.
Registered March 19, 2010
Expires March 19, 2031
Name Servers bayan.ns.cloudflare.com
DNSSEC Unsigned
Hosting Cloudflare, Inc.
Reputation & Threat Check 91 security engines checked
File Scan Summary Powered by Quttera Engine
4 files scanned
No threats
3
Low Risk
1
Medium Risk
0
High Risk
0
No threats Low Risk Medium Risk High Risk
/index Flagged: low risk
www.npmjs.com.http-redirect 78 B No threats
www.npmjs.com/# 5.3 KB No threats
www.npmjs.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=a1ad9a507de4f468 212.7 KB No threats
Quttera flagged low risk files - is this your website?
Investigate and remove potential threats with Quttera
Remove Malware

Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.

External Links & Domains
1
External Links
All Clean
0
Iframes
Clean
1
Referenced Domains
All Clean
0
Flagged Resources
None Detected
http://npmjs.org/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray%3Da1ad9a507de4f468Not flagged
npmjs.orgNot flagged
npmjs.org Overview

Description of npmjs.org

npmjs.org appears to be the web presence for npm, a widely used JavaScript package registry and developer platform. The homepage shown in the scan includes package search, documentation, account access, and subscription options such as Pro and Teams, which indicates a service centered on software package distribution and developer tooling.

Based on the page content, the platform appears to be operated in connection with GitHub and serves developers who publish, discover, and manage JavaScript packages. Its long registration history, strong traffic ranking, and established branding are consistent with a well-known technology service rather than a temporary or single-purpose website.

Safety Assessment for npmjs.org

The scan results are broadly reassuring at this point in time. No detections were reported by 0 out of 91 security engines, and the domain was shown as clean across the checked malware and phishing blacklist databases. The site is also long-established, with a registration age of roughly 16 years, which generally reduces the likelihood of throwaway abuse patterns.

One automated malware scan did mark the homepage path as "potentially suspicious," but no specific malware family or confirmed threat name was provided, and that signal was not corroborated by the broader engine consensus or by blacklist data. In context, this appears to be a low-confidence heuristic finding rather than strong evidence of harmful activity.

Based on available data, no threats were detected at the time of this scan. The isolated heuristic alert may warrant routine caution, but the overall findings suggest a low-risk profile at this time.

Technical Description

The domain uses a valid SSL/TLS certificate and is served through Cloudflare infrastructure, with nameservers also pointing to Cloudflare. The resolved server IP in this scan was 104.16.1.34, geolocated to Toronto, Canada, and the web server was identified as Cloudflare. This setup is common for large, high-traffic websites that use CDN and edge protection services.

DNSSEC appears to be unsigned, which means DNS responses may not benefit from DNSSEC validation. While that is not uncommon and does not by itself indicate a security problem, signed DNSSEC would provide an additional layer of DNS integrity assurance. No major server-side security issues were evident from the provided scan data.

HTTP Redirect Chain
301 https://npmjs.org/
307 https://www.npmjs.com/
301 https://npmjs.org/
403 https://www.npmjs.com/
Website Insights
#4,424
Tranco Rank
Very Popular
Visitors >10M/mo
Category: Technology
Rank History (30 days)
Jun 8 Jul 13
2 cookies detected
Essential2
Analytics0
Advertising0
Social0
1 1st party cookie
1 3rd party (tracker)
Dispute This Score For website owners
Believe this score is inaccurate?
If you are the website owner and believe the scan results contain errors or false positives, you can submit a dispute for manual review. Our team typically responds within 1-2 business days.
You will be asked to verify your email before the dispute can be processed.
By submitting this form, you confirm that the information provided is accurate. Disputes are reviewed manually and results may take up to 48 hours to update.
One more step…
To submit your dispute for npmjs.org, please click the verification link we just emailed you. Once verified, we'll review it within 1-2 business days.
This report was generated automatically and is provided for informational purposes only. Results are based on a point-in-time scan and may contain false positives or incomplete data. This does not constitute a security audit or certification. No vendor in the market can guarantee a 100% detection rate. If you believe this report is inaccurate, please submit a dispute.

Share your experience with this website. Was it safe? Did you encounter any issues?