npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

statikk

v3.1.0

Published

Simple, secure static file server – serve any directory over HTTP

Readme

Statikk NPM statikk package

A simple and secure server for static files.

  • Pithy flags for CORS and Cross-origin isolation.
  • Two smart security defaults:
    1. Your .git files are not exposed. (Whereas ALL other simple http servers do expose this security concern (except serve))
    2. The server isn't accessible outside of localhost. Other folks on your network won't be able to browse it via your internal IP.
  • If you don't specify a port, it'll be deterministically generated based on your working directory. :tada:

Command line usage

$ npm install -g statikk

$ cd ~/Sites/fidgetspin.xyz

$ statikk --cors --open
 🤓 http://localhost:10810  statikk serving locally: ~/Sites/fidgetspin.xyz

Command line options

  • --port NNNN: custom port. If not specified, it'll use a port automagically based on process.cwd(). (So different projects use different ports!)
  • --open: Open the hosted URL in your default browser. (Only supported on Mac OS!)
  • --cors: Add CORS headers
  • --coi: Add cross-origin isolation headers (more)
  • --jsprof: Add document-policy: js-profiling header (for js self-profiling api)
  • --csp VAL: Add a Content-Security-Policy header with value VAL

This weakens security:

  • --expose: expose server to hosts other than localhost.

All non-port options default to false (except --csp which is undefined by default).

Examples

// Start server at http://localhost:9000 serving ./
$ statikk --port 9000

// Start server at http://localhost:60384 (perhaps) serving ~/Sites/project
$ statikk ~/Sites/project

// Start server at a deterministically-chosen port based on the working directory, and open the browser
$ statikk --open

Programmatic ESM usage

import statikk from 'statikk';

const { app, server, options, url } = await statikk({
  root: './public', // Defaults to process.cwd()
  port: 3000,       // Defaults to a deterministic port based on root
  cors: true,
  coi: true,
  csp: "default-src 'self'",
  open: true,       // Open browser on macOS
});

// To stop the server:
// server.close();

Options

statikk accepts an options object:

  • root: The directory to serve. Defaults to process.cwd().
  • port: The port to listen on. If not specified or 0, it will use a port based on root.
  • cors: Boolean, add CORS headers. Defaults to false.
  • coi: Boolean, add Cross-Origin-Opener-Policy and Cross-Origin-Embedder-Policy headers. Defaults to false.
  • jsprof: Boolean, add document-policy: js-profiling header. Defaults to false.
  • csp: String, value for Content-Security-Policy header. Defaults to undefined.
  • open: Boolean, open browser on server start (only supported on macOS). Defaults to false.
  • compress: Boolean, enable gzip compression. Defaults to true.
  • expose: Boolean, allow access from other hosts on the network (listens on 0.0.0.0 instead of localhost). Defaults to false.

Additionally, any options accepted by serve-static can be passed, such as maxAge, dotfiles, etc.

History

This project is a fork of...

  • https://github.com/boardman/statik which is a fork of
  • https://github.com/johnkelly/statik which is a fork of
  • https://github.com/hongymagic/statik (the OG statik on NPM), but unmaintained since 2013.

The original project doesn't correctly exclude all hidden files, which is why I've forked and republished. ~paul irish. june 2017.