Your package.json looks clean. Your node_modules is a graveyard. Stack Graveyard tracks 155 npm packages with live risk scores from THRIVING to TOMBSTONE π and our Ghost Detection engine scans your entire dependency tree to find deprecated packages hiding 2-3 levels deep that you never installed. npm audit doesn't see them. We do. Free to try. Pro at $10/mo.
No reviews yetBe the first to leave a review for Stack Graveyard
Maker
π
Hey PH! π Tim here, founder of Stack Graveyard.
Built this after a deprecated transitive dep β one I never installed β took down prod at 2am. It was 3 levels deep in my dependency tree, invisible to npm audit, and completely unmaintained.
Would love your honest feedback on the risk scoring and Ghost Detection. What packages do you want to see tracked next?
Ask me anything ππ
Report
Maker
Hey Product Hunt! π I'm Tim, founder of Stack Graveyard.
Built this after a deprecated transitive dependency β one I never installed β took down my production app at 2am. It was 3 levels deep, invisible to npm audit, and completely unmaintained.
That night I realized no tool existed to show developers what was actually dying in their dependency tree. Not just CVEs β but packages with no maintainer, no patches, trending to zero.
So I built Stack Graveyard.
π 155 npm packages tracked with live risk scores π» Ghost Detection maps your full dependency tree π€ AI analysis powered by Claude Free to try β Pro at $10/mo
Would love your honest feedback and questions. Ask me anything! π
Report
Maker
π¨ 205 npm packages compromised in an active supply chain attack today.
TanStack. UiPath. CI credential-stealing malware injected directly into your dependency tree.
This is exactly why I built Stack Graveyard.
Attackers donβt target the packages you know about. They target the ones hiding 3 levels deep that nobodyβs watching β unmaintained, deprecated, and invisible to npm audit.
Stack Graveyard finds them before attackers do:
π Live risk scores for 155 npm packages
π» Ghost Detection maps your full dependency tree
π€ AI analysis tells you what to migrate and when
Launching on Product Hunt TODAY β would love your support π
Drop this as a comment on your PH page AND as a standalone post. The timing couldnβt be more perfect β this attack is trending right now and youβre live today. π₯πββββββββββββββββ
π¨ 205 npm packages compromised in an active supply chain attack today.
TanStack. UiPath. CI credential-stealing malware injected directly into your dependency tree.
This is exactly why I built Stack Graveyard.
Attackers donβt target the packages you know about. They target the ones hiding 3 levels deep that nobodyβs watching β unmaintained, deprecated, and invisible to npm audit.
Stack Graveyard finds them before attackers do:
π Live risk scores for 155 npm packages
π» Ghost Detection maps your full dependency tree
π€ AI analysis tells you what to migrate and when
Launching on Product Hunt TODAY β would love your support π
https://www.producthunt.com/posts/stack-graveyard/maker-invite?code=gMwgzM
Drop this as a comment on your PH page AND as a standalone post. The timing couldnβt be more perfect β this attack is trending right now and youβre live today. π₯πββββββββββββββββ