
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@optiprune/cli
Advanced tools
CLI for resilient static dead-code analyzer for TypeScript and JavaScript workspaces.
Most dead-code analyzers just guess. They look at import graphs and hope they don't miss anything critical. This leads to false positives, broken builds, and developer frustration.
OptiPrune is different. We use formal logic, isolated execution, and a high-performance engine to not just find dead code, but to mathematically prove it.
"Stop Guessing, Start Proving."
While other tools are throttled by the N-API bottleneck, OptiPrune utilizes the Yuku Engine written in Zig. It minimizes the overhead between native performance and the JavaScript runtime.
OptiPrune is the first analyzer to use a real SMT Solver (Z3). We don't just analyze if a function is exported; we analyze if the code inside the function is logically reachable.
if conditions) that are completely invisible to Knip.Dynamic imports are the final boss of static analysis. OptiPrune solves this through a WASM-based QuickJS sandbox. We securely execute critical code snippets to resolve paths at runtime.
| Feature | Knip | OptiPrune |
|---|---|---|
| Engine | Babel / OXC (Standard) | Yuku / Zig (Hyper-Speed) |
| Logic Analysis | Heuristics (Guessing) | Z3 SMT Solver (Proving) |
| Dynamic Paths | Pattern Matching | WASM Sandbox Execution |
| Interface Audit | Ignores Members | Deep Member-Level Analysis |
| Framework Support | Plugins (Core-Level) | 7-Layer Semantic Context |
| False Positives | High (in complex setups) | Near-Zero (Context Aware) |
OptiPrune operates in seven specialized layers to guarantee maximum accuracy:
Tested on a NestJS project with 1000+ files.
Install Optiprune as a dev dependency via pnpm, npm, or yarn:
pnpm add -D @optiprune/core
# or
npm install --save-dev @optiprune/core
# or
yarn add -D @optiprune/core
---
## Usage
Run Optiprune from your project root:
```bash
npx @optiprune/cli
| Flag | Description | Default |
|---|---|---|
-r, --rootDir | Project root directory | process.cwd() |
-e, --entry | Entry point patterns (glob) | [] |
-i, --ignore | Patterns to ignore | [] |
--no-report-unused-exports | Disable unused export reporting | false |
--fail-on | Fail on confidence (high/medium/low/none) | high |
--json | Output as JSON | false |
--sarif | Output as SARIF | false |
--skip-3 | Skip Layer 3 (SMT Constraint Solver) | false |
--skip-4 | Skip Layer 4 (Concolic Execution Proofs) | false |
OptiPrune isn't just a tool. It's a technical statement. Help us save the world from dirty code.
GitHub: DreamLongYT/optiprune Web: opti.drml.int.yt
To setup OptiPrune, see config.md for more
FAQs
CLI for resilient static dead-code analyzer for TypeScript and JavaScript workspaces.
The npm package @optiprune/cli receives a total of 173 weekly downloads. As such, @optiprune/cli popularity was classified as not popular.
We found that @optiprune/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.