npm LL
Free Works in VS Code, Cursor and Windsurf

Your packages. The whole picture.

npm LL is a package manager for Node.js workspaces in VS Code. Search the registry, install into every workspace package that needs it, and keep updates and vulnerabilities in view, all through the npm CLI already on your machine.

  • No backend
  • No telemetry
  • Runs locally
  • Open source
express-rate-limit
Get started

Install, open a workspace, add a package.

npm LL lives in the activity bar. There is nothing to sign in to: it reads the packages in your workspace and talks to the registries you already use.

Install the extension

From the Marketplace, or straight from your terminal.

$ code --install-extension piyushdoorwar.npmll

Open a Node.js workspace

Open a folder with a package.json and select the npm LL icon. Workspace packages, workspaces monorepo members, dependencies and .npmrc registries are detected automatically.

Browse, pick packages, install

Open the dashboard, search the npm registry, choose a version, a dependency type and the workspace packages that need it, and press Install. Updates and vulnerability checks are one click away.

Requires Node.js and npm

npm LL drives the npm CLI, so npm --version needs to work from your PATH. Run an install first so resolved versions and audit results reflect node_modules.

Other editors

npm LL runs anywhere VS Code extensions do, including Cursor and Windsurf. Install it from your editor's extension view.

Features

Every dependency, in one dashboard.

The package workflow you know from Visual Studio, built for npm and every package in the workspace.

Workspace scanner

Finds every package.json, including workspaces monorepo members, and every .npmrc across your workspace folders, always skipping node_modules.

Browse and search

Search registry.npmjs.org or your configured registry, with prerelease and exact-name filters and an npm search fallback.

Install across packages

Pick a version and the workspace packages that need it, then install, update or remove in one step, with a confirmation before multi-package changes.

Updates with context

Outdated packages from npm outdated are split into patch, minor and major, so you can take the safe bumps in a batch and review the rest.

Vulnerable and deprecated

Run npm audit and registry deprecation checks, see severity per package, open the advisory and copy a report.

Dependency types

dependencies, devDependencies, peerDependencies and optionalDependencies are shown per package and respected on install.

Registry inspector

See the default and scoped registries from your .npmrc files, whether auth is configured, and jump to the file that defines each one.

Install anywhere

Run npm install for the whole workspace or a single package, with progress in the panel and the full output in the log.

Sidebar at a glance

The activity bar view counts packages, dependencies, outdated and vulnerable dependencies, and opens the right dashboard tab in one click.

Library Lens

Know what you're adding before you add it.

Select any search result or installed package and the details sit right beside the list, including which of your workspace packages already depend on it.

  • Every published version, with license, author, homepage and keywords.
  • Dependencies, peer dependencies and optional dependencies, with their ranges.
  • Deprecation notices straight from the registry.
  • The workspace packages that already use it, and the version resolved in node_modules.
express Fast, unopinionated, minimalist web framework
5.1.0
License
MIT
Versions
280+
Dependencies
28

Used in this workspace

  • api4.21.2
  • worker4.21.2
  • web4.19.2older

Dependencies

body-parsercookiedebugroutersend
Privacy first

Your workspace stays on your machine.

npm LL has no backend. It reads your package files locally and only talks to the npm registries you configure.

No extension server

Search and metadata requests go straight from VS Code to registry.npmjs.org or your own registry. Nothing passes through an npm LL service.

Your local npm CLI

Installs, updates and health checks run through npm on your machine, spawned with argument arrays, never a shell.

Tokens stay put

npm LL never reads or stores .npmrc auth tokens, it only detects whether auth is set up. URL-embedded credentials are masked in the log and the UI.

You approve shared edits

Edits stay inside your workspace, and the workspaces-root package.json changes only after you confirm.

Add npm LL to VS Code.

npm LL is a free VS Code extension. Install it from the Visual Studio Marketplace, or open it straight in VS Code, then manage every package from the activity bar.