Snyk's Package Health Score evaluates code quality, maintenance activity, and community engagement. It gives chalk 81/100 — healthy. Chalk has one npm publisher controlling 445 million downloads per week. That's the exact attack profile exploited in every major 2026 npm supply chain incident.
Catches what's broken
Catches
Misses
Catches what's exposed
Catches
Misses
Chalk is excellent software. The CRITICAL flag isn't about code quality — it's about credential concentration. One stolen npm token, one compromised laptop, one phishing email reaches every project that depends on chalk. That's 445 million installs per week behind a single set of credentials.
Five packages. Live Commit data. Snyk Package Health scores shown as-of analysis.
Loading live data…
Failed to load data.
No. They measure different things. Snyk tracks known CVEs and gives you fix paths — that's irreplaceable. Commit measures structural exposure: credential concentration, publisher count vs download volume, release patterns. A dependency can have zero CVEs and still be CRITICAL on Commit because one person controls 400M weekly installs. Use both.
Community engagement, maintenance activity, code quality signals, and known CVEs. Snyk's model answers "is this package well-maintained and free of known vulnerabilities?" That's a completely different question from "is this package's publish access concentrated in a way that makes it a high-value target?"
Because publisher concentration isn't in Snyk's model. Snyk measures what it's designed to measure — code quality, maintenance activity, CVE coverage. It has no signal for "one set of credentials controls 445M downloads/week." That's a gap, not a flaw. Different tools, different scope.
The CLI, web audit, and API are free. Paid plans from $15–$29/mo add batch scanning, continuous monitoring, Slack/webhook alerts, and GitHub Action integration. See pricing →
Paste your dependencies. See which ones are structurally exposed.
npx proof-of-commitment --file package.json