Available worldwide
What is pnpm?
A JavaScript package manager that emphasizes rapid installation speeds and disk efficiency through a content-addressable store, with robust monorepo support and built-in supply-chain protection features.
pnpm pricing
We don't have pnpm's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
What pnpm does
The capabilities that matter for package registries, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- Role
- Package manager client
- Ecosystem / language
- JavaScript
- Deployment
- CLI-local
- Package formats supported
- Many formats
- Private / scoped packages
- ✓
- Upstream proxy / caching
- ✓
- Lockfile / deterministic installs
- ✓
- Workspaces / monorepo
- ✓
- Content-addressable store
- ✓
- Supply-chain integrity
- ✓
- Vulnerability / licence scanning
- -
- Openness
- Open-source
- Pricing model
- Free / OSS
Platform & deployment
Independently observed- CLI
- Self-hosted
Integrations (11)
Independently observed- GitLab CI←
- Jenkins←
- Semaphore←
- Travis CI←
- GitHub Actions
- AppVeyor
- Azure Pipelines
- Bitbucket Pipelines
- CircleCI
- npm
- JSR
Security & compliance
Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality
pnpm FAQ
Common questions about pnpm, answered from independent, dated evidence.
What is pnpm?
A package manager for JavaScript projects that emphasizes fast performance and minimal disk space requirements. It is indexed under Package Registries.
Source: https://pnpm.io
Is pnpm free to use?
pnpm is open source, so it can be self-hosted and used at no licence cost. It is released under the MIT licence. Pricing changes often, so verify at source before relying on it.
Source: https://pnpm.io
What platforms does pnpm support?
pnpm supports a command-line interface. Platforms we have not confirmed are simply not listed here rather than ruled out.
Source: https://pnpm.io
Can pnpm be self-hosted?
Yes. pnpm can be deployed self-hosted, so it does not have to run on the vendor's infrastructure.
Source: https://pnpm.io
What does pnpm integrate with?
We have confirmed 7 integrations for pnpm, including GitHub Actions, AppVeyor, Azure Pipelines, Bitbucket Pipelines, CircleCI, npm and JSR. This is what we could verify from public sources, so the vendor may support others we have not indexed.
Source: https://pnpm.io
Is pnpm open source?
Yes. pnpm is published under the MIT licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.
Source: https://github.com/pnpm/pnpm
pnpm alternatives
Other package registries we track, ranked by the same independent score.
- BunA unified JavaScript runtime with integrated package management, bundling, and testingmedium · 56%
- VerdaccioA self-hosted npm registry with package caching and proxying capabilitieshigh · 78%
- RubyGemsThe public repository and package manager for Ruby codelow · 31%
- uvmedium · 62%
- pipPackage installer for Pythonmedium · 68%
- Composer/PackagistA package and dependency manager for PHP projectsmedium · 52%
Compare pnpm
Side by side against other package registries, attribute by attribute, with a source on every value.
The vioscaleAI score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for pnpm, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Package downloads | 100 | 0.15 | 14.9 | ✓ |
| Capabilities | 81 | 0.09 | 7.1 | ✓ |
| Development activity | 63 | 0.11 | 6.8 | ✓ |
| Security score | 66 | 0.08 | 5.3 | ✓ |
| Dependent projects | 46 | 0.07 | 3.1 | ✓ |
| Stars | 86 | 0.03 | 2.3 | ✓ |
| Integrations | 30 | 0.05 | 1.6 | ✓ |
| Release cadence | 0 | 0.07 | 0.0 | - |
| Security posture | 5 | 0.18 | 0.0 | - |
| Developer Q&A activity | 0 | 0.05 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 100 | mediumsource · 2026-09-11 · 65% |
Adoption
Content
| Attribute | Value | Evidence |
|---|---|---|
| Faq | 6 items | mediumsource · 2026-09-10 · 67% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Role: manager_client · Ecosystem: js · Deployment: cli_local · Workspaces: Yes · Open source: oss · Pricing model: free | mediumsource · 2026-09-14 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 10 | mediumsource · 2026-09-14 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Rust | highsource · 2026-09-11 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | MIT | highsource · 2026-09-11 · 99% |
Market
| Attribute | Value | Evidence |
|---|---|---|
| Availability | PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: … | highsource · 2026-08-13 · 75% |
Pricing
Release
| Attribute | Value | Evidence |
|---|---|---|
| History | 20 items | mediumsource · 2026-09-11 · 70% |
Security
| Attribute | Value | Evidence |
|---|---|---|
| Disclosure policy | Yes | mediumsource · 2026-09-14 · 60% |
| Scorecard | 6.6 | highsource · 2026-09-11 · 90% |
| Vulnerabilities | Count: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=npm&package_name=%40pnpm%2Ferror&per_page=100 · Last 12m: 0 | highsource · 2026-08-26 · 90% |
| Trust center | https://pnpm.io/blog/tags/security | mediumsource · 2026-09-14 · 60% |
Is pnpm the right choice for you?
Tell us the job, the constraints and what you weigh most, and we will rank pnpm against the rest of the package registries we index, using the same dated evidence weighted your way.
Free to run, no account needed to start. How the evaluation works
Is this your product?
This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves pnpm up or down: nobody can buy rank here, including you.
Take the badge
Live, always current, and free to use on your own site. It shows pnpm's independent score and links back to this profile.
<a href="https://www.vioscale.ai/software/pnpm" target="_blank" rel="noopener">
<img src="https://www.vioscale.ai/badge/software/pnpm.svg" alt="pnpm, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>Markdown, for a README →
[](https://www.vioscale.ai/software/pnpm)Claim the profile
Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing pnpm. Free, and it does not change the score.
- Correct anything wrong, with evidence
- Point our crawler at the pages that matter
- See which AI systems are reading this profile
Not the owner? How vendor profiles work