pkg.soopen package index

npm / rank 2570

Install carrot-scan with npm

Command-line tool for detecting vulnerabilities in files and directories. Version 6.0.1 via npm; verified 2025-07-07.

install

Additional install commands

Portable and language managers

npmverified · 100%
npm install -g carrot-scan

local npm package metadata

overview

Package summary

Command-line tool for detecting vulnerabilities in files and directories.

Commands and aliases

  • carrot-scan

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for carrot-scan. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
carrot-scanexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version6.0.1
manager updated2025-07-07
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keynpm:carrot-scan
Version6.0.1
Package managernpm
Homepagehttps://github.com/SonoTommy/carrot-scan#readme
Last updated2025-07-07T09:58:52.520Z
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • cross-ecosystem install command graph
  • pkg.so package database
  • pkgdb category and tag curation