# Veln

> Block bad packages. Before they download.

- **Website**: https://veln.sh
- **Uneed Page**: https://www.uneed.best/tool/veln
- **Pricing**: Paid
- **Category**: Development
- **Tags**: Freelance, Development, Security
- **Submitted by**: @paleksic
- **Launch Date**: 2026-09-30
- **Social Links**: [Twitter](https://x.com/velnsh)

## About

Over 20 trust signals score every npm and pip install — CVEs, maintainer drift, install scripts, hidden payloads. Bad packages refused befoSupply chain attacks on npm and PyPI keep landing in production — usually hours before any threat feed catches up. Veln is a local proxy that scores every install against 20+ trust signals (CVEs, maintainer changes, install scripts, hidden payloads) before a single byte hits your disk. Same commands, same lockfiles, zero workflow change.