maxh33/PhantomRaven NPM Scanner

Detect PhantomRaven RDD vulnerabilities, typosquatting, and hidden dependencies in npm projects

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathDirectory to scan (default: repository root)no.
fail-on-criticalExit with error code 1 if critical issues foundnotrue
fail-on-highExit with error code 1 if high or critical issues foundnofalse
trusted-domainsComma-separated list of trusted domains (e.g., "nexus.corp.com,artifactory.internal")no""
output-filePath to save JSON reportnophantom-raven-report.json
include-node-modulesScan inside node_modules (slow)nofalse
namedescription
issues-foundNumber of issues found
critical-countNumber of critical issues
high-countNumber of high severity issues
report-pathPath to the JSON report