Nifty Licenses
See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices.
Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.
Features



- Know what you ship. The Licenses view in the Explorer lists every dependency, direct and transitive, grouped by risk: network copyleft (AGPL, SSPL), copyleft (GPL), weak copyleft (LGPL, MPL), permissive (MIT, Apache, BSD), public domain and unknown.
- All the usual lockfiles:
package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt (pinned), poetry.lock, uv.lock, Cargo.lock, go.sum, packages.lock.json (NuGet) and composer.lock, including monorepos with several of them.
- Accurate licenses. Read from installed packages and lockfiles first, then looked up on deps.dev (only package names and versions are sent; turn it off with
nifty.licenses.online). Results are cached. Messy strings like "Apache 2.0" or "MIT/Apache-2.0" are cleaned up into SPDX.
- Your policy, enforced. Deny licenses by SPDX id (
AGPL-3.0-only), wildcard (GPL-*) or category (copyleft), or allow only a list. Dual licenses are handled properly: MIT OR GPL-3.0 passes because you can choose MIT. Problems appear on the dependency's line in package.json, pyproject.toml, Cargo.toml, go.mod or composer.json, and as a count in the status bar.
- Export a CSV of every dependency, its license and category.
- SBOM export in CycloneDX 1.5 or SPDX 2.3 JSON, with package URLs, for security reviews, customers and the EU Cyber Resilience Act.
- Third-party notices: a
THIRD_PARTY_NOTICES.md listing the packages you ship, grouped by license.
Example policies
// Flag GPL-family licenses too, not only AGPL:
"nifty.licenses.deny": ["copyleft", "network-copyleft"]
// Or allow only a known list:
"nifty.licenses.allow": ["MIT", "ISC", "Apache-*", "BSD-*", "0BSD", "Unlicense"]
Commands
| Command |
What it does |
Nifty Licenses: Check Dependency Licenses |
Scan again (it also rescans when lockfiles change) |
Nifty Licenses: Export License List (CSV)… |
Every dependency and its license |
Nifty Licenses: Export SBOM (CycloneDX / SPDX)… |
CycloneDX 1.5 or SPDX 2.3 JSON |
Nifty Licenses: Export Third-Party Notices… |
A THIRD_PARTY_NOTICES.md grouped by license |
Nifty Licenses: Forget Cached Licenses and Recheck |
Clear the cache |
Settings
| Setting |
Default |
What it does |
nifty.licenses.deny |
["network-copyleft"] |
Licenses or categories to flag |
nifty.licenses.allow |
[] |
If set, flag anything not on this list |
nifty.licenses.flagUnknown |
true |
Flag dependencies without license information |
nifty.licenses.includeDev |
false |
Include development dependencies |
nifty.licenses.online |
true |
Look up missing licenses on deps.dev |
nifty.licenses.showInStatusBar |
true |
Show the issue count |
This is a tool, not legal advice. Check anything important with your lawyer.
Install
- VS Code: search for "Nifty Licenses" in the Extensions view, or install from the Visual Studio Marketplace.
- Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.
Privacy
This extension collects no telemetry and needs no account.
- Nifty Code Metrics: Complexity & Hotspots: Complexity and size for every function in any language, as CodeLens and warnings, plus a hotspots view of the complex files that change most often. (Open VSX)
- Nifty Node Search: Search Files in node_modules: Fuzzy-find and open files inside node_modules, jump to a package's README, and see installed versions. (Open VSX)
- Nifty Pretty Errors: Readable Error Messages: Readable error messages for every language: TypeScript types formatted as code, long C++ and Rust types folded, and a docs link for every error code, in the hover and a side panel. (Open VSX)
- Nifty Problems: Project-Wide TypeScript Errors: See TypeScript and ESLint errors for your whole project in the Problems panel, not just open files. (Open VSX)
- Nifty Whitespace: Indent Rainbow, Invisible Characters & Trim: Indent rainbow, invisible and confusable characters with quick fixes, mixed line endings and tabs, and trimming trailing whitespace only on the lines you changed. (Open VSX)
- Nifty XML: XPath, Formatter & XML to JSON: Evaluate XPath with namespaces, copy the XPath of any element, format, minify, check well-formedness and convert XML to JSON. (Open VSX)
See all 56 Nifty tools at https://getnifty.dev
| |