product
Technical people in and around the JavaScript ecosystem: application developers, npm package maintainers, security-minded engineers, and technical leads. Some users will use the tool for their own package choices; others will share a configured link with managers or leadership to make dependency-risk work easier to justify.
npm.tax is a simple, opinionated supply-chain risk analysis tool. It turns dependency count, compromise probability, and time horizon into a clear cumulative-risk story for npm packages and projects. Success means a technical user can quickly explain why dependency footprint and package security work deserve attention without pretending the model is a precise forecast.
Direct, analytical, and urgent without being alarmist. The interface should feel like a sharp technical explainer: current with the npm supply-chain breach zeitgeist, confident about the point it is making, and restrained enough to stay credible.
Not SaaS marketing. Not a generic Geist or Vercel clone. Not maximalist. Not crypto or fintech terminal aesthetics. Not an academic calculator with no point of view. Not security-dashboard doom, fearmongering, or overboard FUD.
- Tell the risk story quickly, then let the controls prove it.
- Keep the model transparent: simple assumptions, plain language, visible math.
- Make shareable states feel intentional, since persuasion is part of the workflow.
- Use severity cues carefully: warn when the numbers justify it, stay neutral when they do not.
- Prefer technical credibility over decorative drama.
Aim for WCAG AA contrast and keyboard-operable controls. Do not rely on colour alone to communicate risk severity. Respect reduced-motion preferences. Keep copy readable for technical users who are not security specialists.