Cheaper than one incident response.

A single credential-stealer that reaches a developer machine costs days of rotation, review and explaining. Start free and stay free if that is all you need.

Free

Everything you need to stop installing known-bad versions.

$0

free forever · no card required

  • Secure installs through the proxy
  • Live vulnerability & malware filtering
  • Blocks Critical and High severity
  • Activity dashboard, 7-day log
  • One registry token

Pro

most popular

For working engineers who want the policy under their own control.

$9per month

14-day free trial · monthly billing · cancel anytime

  • Everything in Free
  • Configurable severity policy
  • Release quarantine & package-age rules
  • Package allow / block rules
  • Activity dashboard & 90-day audit log
  • Unlimited registry tokens

Team

One policy every engineer inherits, with no per-developer drift.

$15per seat / month

starts at 2 seats · billed from day one · add more any time

  • Everything in Pro
  • Org-wide policy: severity, quarantine, allow/block rules
  • Slack alerts whenever a version is kept out
  • Centralized member & token management
  • Team-wide audit log

Prices in USD, billed monthly, cancel any time. Last updated 2026-08-22. Plain-text version for scripts and agents.

Billing questions, answered.

Something else? support@installsafe.io

01Is the Free plan really free?

Yes. No card, no trial clock. It blocks Critical and High severity advisories plus confirmed malware on one registry token, and keeps seven days of activity.

02What does Pro add over Free?

Control. You choose the severity threshold, quarantine releases younger than N days, write per-package allow and block rules, keep 90 days of audit log, and create as many registry tokens as you need.

03How is Team billed?

$15 per seat per month, starting at 2 seats. Buy more seats from the team page whenever you invite more people than you have seats for. Every member inherits the organisation policy and shares one audit log.

04Can I cancel?

Any time, from the billing portal. Your policy and registry tokens keep working until the end of the period you have paid for.

Ship code, not CVEs.

Two minutes from now, every npm install on your machine can be immune to known vulnerabilities and malware.