Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>Nifty Dependency Guard: Package Security CheckNew to Visual Studio Code? Get it now.
Nifty Dependency Guard: Package Security Check

Nifty Dependency Guard: Package Security Check

Nifty

| (0) | Free
Catch risky dependencies before you install them: made-up (AI-hallucinated) packages, lookalike names, brand-new versions, install scripts and deprecations, in package.json and requirements.txt.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Nifty Dependency Guard

Catch risky dependencies before you install them: made-up (AI-hallucinated) packages, lookalike names, brand-new versions, install scripts and deprecations, in package.json and requirements.txt.

Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.

Features

A package.json with a made-up package, a typosquat of axios, a deprecated package, a two-day-old release and an install script flagged

A requirements.txt with a misspelled requests and a package that doesn't exist on PyPI

Open a package.json or requirements.txt and risky dependencies are underlined before you install them:

  • Packages that don't exist. AI assistants sometimes suggest packages that were never published, and attackers register those names ("slopsquatting"). A dependency that isn't on npm or PyPI is marked as an error. Scoped packages missing from the public registry are treated as private.
  • Lookalike names. expresss, lodahs, reqeusts, cross_env: names one or two keystrokes away from a popular package are flagged, unless the package is itself widely used.
  • Brand-new releases. When the version you'd install came out in the last 7 days, you're warned. That's the window in which hijacked maintainer accounts publish malicious updates. You're also warned when the package itself is less than 30 days old.
  • Install scripts. Versions that run preinstall, install or postinstall scripts are pointed out, with the command they run.
  • Deprecated and yanked versions, with the maintainer's deprecation message.
  • Hover over a dependency for its latest version, when the resolved version was published, weekly downloads, maintainer count and a link to the registry page.
  • Check the whole workspace in one go, and quick-fix Don't flag this again for packages you trust.
  • Works in the browser on vscode.dev and github.dev.

For AI coding agents

The same checks run as a command-line tool, nifty-guard on npm, that can stop an agent before it installs a made-up package. Install it once:

npm install -g nifty-guard

For Claude Code, add it as a hook in ~/.claude/settings.json, and every npm, pnpm, yarn, bun, npx, pip, uv, poetry or pipx install Claude runs is checked first:

{
  "hooks": {
    "PreToolUse": [
      { "matcher": "Bash", "hooks": [{ "type": "command", "command": "nifty-guard hook claude", "timeout": 30 }] }
    ]
  }
}

Made-up and lookalike names are blocked, and Claude is told why so it can find the right package. Brand-new packages and releases ask you first. Anything else runs as normal. You can also check a command yourself: nifty-guard npm install left-pad lodahs.

Commands

Command What it does
Nifty Dependency Guard: Check Dependencies in This File Check the open package.json or requirements.txt
Nifty Dependency Guard: Check All Dependencies in Workspace Check every manifest and list problems in the Problems panel
Nifty Dependency Guard: Forget Cached Registry Data Fetch fresh data on the next check

Settings

Setting Default What it does
nifty.guard.checkOn open Check when a manifest is opened (and saved), only on save, or manual
nifty.guard.newVersionDays 7 Warn about versions newer than this
nifty.guard.newPackageDays 30 Warn about packages newer than this
nifty.guard.lookalikeMinDownloads 10000 Weekly npm downloads above which a lookalike name isn't flagged
nifty.guard.ignore [] Package names (or prefix*) never to flag
nifty.guard.hover true Show registry details on hover
nifty.guard.npmRegistry, npmDownloadsUrl, pypiUrl public registries Where to look packages up (point these at a mirror if you use one)
nifty.guard.timeoutMs 10000 How long to wait for the registry

Privacy

To check a dependency, the extension asks the public registry about that package name. That's the same request npm install or pip install would make. Nothing else is sent, and there's no telemetry. Answers are cached for an hour.

Install

  • VS Code: search for "Nifty Dependency Guard" in the Extensions view, or install from the Visual Studio Marketplace.
  • Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.

More Nifty tools

  • Nifty Extension Audit: Extension Security Check: See what your installed extensions can do: activation, processes, network, native code, telemetry and secrets access, scored and reported, with an allowlist policy for teams. (Open VSX)
  • Nifty Licenses: Dependency License Checker & SBOM: See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices. (Open VSX)
  • Nifty Node Search: Search Files in node_modules: Fuzzy-find and open files inside node_modules, jump to a package's README, and see installed versions. (Open VSX)
  • Nifty Agent Config: AGENTS.md, Rules & MCP Files: See which AGENTS.md, CLAUDE.md, Cursor, Copilot, Windsurf and Gemini rules apply to the file you are editing. Lint rule and MCP files for hidden text, secrets and broken links, and keep them in sync. (Open VSX)
  • Nifty AI Review: Review AI Agent Changes: Review what an AI agent changed, hunk by hunk: checkpoints before it runs, accept or reject each change, leave comments, and send your feedback back to the agent. (Open VSX)
  • Nifty Code Metrics: Complexity & Hotspots: Complexity and size for every function in any language, as CodeLens and warnings, plus a hotspots view of the complex files that change most often. (Open VSX)

See all 100+ Nifty extensions and web tools at https://getnifty.dev

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft