Developer

package.json Validator

Validate an npm package.json against the fields npm actually enforces: name rules, semver validity, dependency ranges, exports and files fields, licence identifiers and the mistakes that break publishing.

Last reviewed by the Radiatus Cloud team

Validation results appear here.

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

npm only complains at the worst moment

Most package.json problems are invisible until you run npm publish, and by then you have a version number burned. A name with a capital letter is rejected outright. A missing files field ships your test fixtures and your .env sample to the registry. A dependency pinned with an equals sign rather than a caret means every consumer gets a duplicate copy in their tree. A main field pointing at a path that does not exist after the build produces a module that installs cleanly and then fails to import.

Where the rules come from

Some constraints are hard: the name must be lower case, at most 214 characters, free of leading dots and underscores, and URL safe. The version must be valid semver, not a range. Others are conventions that matter almost as much: a licence field using a valid SPDX identifier rather than free text, an engines field that says which Node versions you actually test on, and a repository field so the registry page links back to the source.

What this validator reports

Errors are things npm or a consumer will reject. Warnings are things that will work but cost you later, such as a dependency range that cannot deduplicate or a private package with no private flag. Each finding names the field, says what is wrong and states the consequence, so the list is a work queue rather than a score.

Related tools

  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
  • JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
  • HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.

Frequently Asked Questions

Does this check whether my dependencies exist?

No. Resolving package names against the registry requires a network request, and this tool runs entirely in your browser. It validates the manifest structure, the version ranges and the field values, which is where most manifest bugs live.

Why is an exact dependency version a warning rather than good practice?

Exact pins in a library prevent npm from deduplicating, so consumers end up with several copies of the same package. Pin exactly in an application, where the lockfile is committed; use caret ranges in a published library.

What is the files field for?

It whitelists what gets published. Without it npm publishes everything not covered by .npmignore, which routinely leaks test fixtures, build scripts and occasionally credentials. An explicit files array is the safest default.

Are the name rules really that strict?

Yes. npm rejects capitals, spaces, leading dots or underscores, non URL safe characters and names over 214 characters. Scoped names must be @scope/name with the same rules applied to each part.

Does it validate the exports field structure?

It checks that exports, when present, is an object or string, that conditional keys are recognised, and that a default condition appears last, which is the ordering rule that silently breaks resolution when violated.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste your package.json and press Validate to see errors, warnings and publishing advice.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.