Find dependency declarations that have no use in a configured, statically understood local source graph. The result is evidence for review, not an instruction to uninstall anything. It reads exported files only, runs offline, and never edits a manifest, fixture, or source file.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/unused-dependency-auditor.mjs --root examples/clean --config examples/clean/audit.json
node bin/unused-dependency-auditor.mjs --root examples/failing --config examples/failing/audit.json --json
npm run checkRead the result
The first command exits 0 (pass); the second exits 1 (fail) and points to one potentially unused declaration. --help prints usage. JSON is always stdout. By default a fixed human summary is also sent to stderr; --json suppresses only that summary. Invalid options/configuration exit 2 with empty stdout and a fixed diagnostic. Named input that cannot be read or interpreted exits 2 with an incomplete JSON report. There is intentionally no output-file option.
Where this check stops
Defaults: manifest 1,048,576 bytes; config hard cap 65,536 bytes; each source 262,144 bytes; total source 4,194,304 bytes; 256 reached files; 512 declarations; relative-import depth 32; 50,000 lexical tokens; 2,000 elapsed milliseconds. Exact limits pass at N and become incomplete at N+1. The report shows at most 1,024 findings; beyond that it replaces omitted rows with finding-limit, an omitted count, and incomplete status. Optional limits may set positive safe-integer values for maxManifestBytes, maxConfigBytes (only to lower the hard cap), maxSourceBytes, maxTotalSourceBytes, maxFiles, maxDependencies, maxDepth, maxTokens, and maxMilliseconds. The library accepts an injected now function; nonfinite or backward readings are invalid configuration. JSON is strict UTF-8 and rejects duplicate keys and rounded numeric tokens.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.