Skip to content

Check packages before you install.

Tapid is a free package manager that verifies downloads against registry checksums and keeps dependency install scripts disabled. Know exactly which packages enter your project.

Available for macOS, Linux, and Windows.

Terminal session running tapid install is-char

What Tapid does during an install

Tapid checks the download before changing your project. It records the result in tapid.lock so you can inspect what entered the dependency tree and reuse the same inputs later.

Verify the download

For supported installs, Tapid compares the package archive with the registry's checksum. A mismatch stops installation.

Record exact dependencies

The lockfile records package identities and dependency relationships. Frozen installs check that record before reusing the verified inputs.

Leave install scripts disabled

Installing a dependency does not automatically run its setup code. Tapid keeps dependency lifecycle scripts disabled.

What you can use today

The CLI is free to use on macOS, Linux, and Windows. It supports a limited set of npm-compatible installs, with experimental JSR support. Check the documentation for the workflows supported today.

AI scanning is in development

A matching checksum can still belong to a malicious package. We are developing AI scanning to examine new dependency versions for signs of malicious code before organizations adopt them.

The scanning service is not available yet. We are considering pricing based on the packages an organization uses; pricing is not final.

The new standard for dependencies.

Start with the free Tapid CLI. Verify downloads, record exact dependencies, and review changes before they reach your project.

Get the free CLI