Vendor Dossier PDF

A pro-grade, 6-8 page security / vendor review dossier for any npm package. The same data the free /health pages use, plus security advisories from OSV, release cadence, and a decision matrix scoped to your use case (load-bearing / peripheral / defer / sunset). PDF + raw JSON, delivered within 24 h.

$9 per package

Get a dossier

You get the lodash sample dossier instantly + a custom dossier for the npm package of your choice. 7-day refunds.

Buy a Vendor Dossier ($9) See free /health snapshots first

What's in a dossier

  1. Executive summary with the depmedic 0-100 health score (popularity, maintenance, quality, risk) + letter grade.
  2. Identity and ownership: publisher, maintainers, license, repository, types support.
  3. Adoption signal: downloads, dependents, stars, forks, open vs closed issues.
  4. Release cadence: last 12 versions with days between - shows whether maintenance is alive or stalled.
  5. Known security advisories from OSV.dev: ID, summary, severity, dates.
  6. Decision matrix: GO / CAUTION / NO for load-bearing, peripheral, defer, sunset use cases.
  7. Vendor questionnaire: the questions to ask the maintainer in a security review.
  8. Operational mitigations: pin, mirror, watch, allowlist.
  9. Sources and methodology: every input named so an auditor can reproduce.

How it works

  1. Buy ($9). You get the bundle download instantly: sample-lodash.pdf showing the format, plus the request guide.
  2. Reply to your Polar receipt with the npm package name. Subject: Vendor Dossier - <package>.
  3. Receive your dossier within 24 hours, usually same day. PDF + raw JSON.

Compared to writing it yourself

YourselfVendor Dossier
Time2-4 hours per package~1 minute (forward the receipt)
FormatWhatever you can paste togetherConsistent printable PDF, comparable across packages
OSV advisory pullManual, click click clickAuto, every advisory in one table
Decision matrixFrom memoryScored against load-bearing / peripheral / defer / sunset
ReproducibleHard, depends on which tab you openedYes, raw JSON included; methodology cited
Cost$200+ at typical engineer rate$9

Bigger needs?

Org Dep Health Monitor - $19/mo

Up to 200 packages monitored continuously. Weekly digest + same-day alerts on grade drops, deprecations, advisories. Includes 4 Vendor Dossier PDFs per quarter (a $36 standalone value). Slack webhook supported.

Subscribe ($19/mo) Read more