Static analysis engine
Parses any package.json in the browser and runs it against a curated knowledge base: deprecated packages, heavyweight dependencies, wildcard versions, and tooling shipped to production.
Case study — 05
They asked for a dashboard. We shipped something sharper: paste a manifest, get a scored report. No signup, nothing leaves the browser.
The original brief asked for a monitoring dashboard: accounts, integrations, weekly emails. Discovery told a different story — developers wanted an answer in the time it takes to paste. Every login screen between them and the report was churn.
So we said no to the dashboard, and Stackline's founder — in her words — got a product she would not have specified on day one, in the best sense. Audit runs entirely client-side: static analysis with a curated knowledge base, an honest 0–100 score, and recommendations engineers actually act on.
Parses any package.json in the browser and runs it against a curated knowledge base: deprecated packages, heavyweight dependencies, wildcard versions, and tooling shipped to production.
Two date libraries, three HTTP clients, two test runners — Audit spots overlapping packages doing the same job and names the consolidation.
A single 0–100 number with explicit deductions, so teams can track hygiene over time and set a bar in code review.
Every audit exports as clean markdown — pasteable into a PR, a Slack thread, or a sprint ticket. The report is the growth loop.
The most valuable engineering decision on this project was an argument. The founder's dashboard spec was rational — but the discovery interviews kept surfacing the same behavior: developers evaluate tools in one tab, in one minute, with zero patience for onboarding. We proposed inverting the product: instant value first, accounts never.
Client-side analysis was the second deliberate constraint. Manifests can reveal a company's entire technical posture — by keeping every byte on-device, the privacy answer became the marketing headline.
The knowledge base is data, not code: deprecations, heavyweight packages, and duplicate-purpose groups live in versioned tables Stackline's own team extends without touching the engine. We built the product to be owned — read, extended, shipped — without us.
Next step
One call. A concrete next step within 24 hours. No pitch deck.
Start a conversation →No obligation · Intro call · Reply within 24 hours