
Product
PHP and Composer Support Is Now in Beta
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.
Gridproof your UI — automated spacing & grid QA in the agent loop.
Gridproof is an MCP server that renders your running frontend with Playwright, measures the computed geometry of every element, checks it against a spacing/token rule set, and hands back a structured fix report — so a coding agent can close the loop itself: generate, audit, fix, re-audit.
AI coding agents are good at generating UI and bad at keeping it on a grid:
py-[13px] instead of py-3, sibling cards with three different gaps,
icons at 17px next to 24px. None of it breaks anything, so it ships —
because nothing in the agent loop checks for it. Gridproof is that check.
agent generates UI → gp_audit(url) → JSON violations with fix hints
→ agent edits source → gp_audit(url) → clean report = done
The server never touches your source files. It measures a rendered page and points; the agent (which has your codebase open) makes the edit.
# One-time: install the Chromium build Playwright uses (~150MB)
npx playwright install chromium
claude mcp add gridproof -- npx -y gridproof
From a local checkout:
npm install && npm run build
claude mcp add gridproof -- node /absolute/path/to/gridproof/dist/index.js
1. gp_audit — inside the agent loop. The agent calls this MCP tool
directly against your running dev server and gets back structured JSON
(violations + fix hints) to act on.
2. gp_report — MCP tool that also writes an HTML report. Same inputs as
gp_audit, plus it writes a self-contained, shareable HTML file to disk.
3. npx gridproof --report <url> — one-shot CLI. No MCP client needed;
useful for a quick manual check or scripting.
npx gridproof --report http://localhost:5173
# writes ./gridproof-report.html, prints its path
npx gridproof --report http://localhost:5173 --out ./qa/report.html --viewport 375x812
Four rules. All report warn by default — nothing blocks, nothing has
exit-code semantics. Suggest, don't forbid; the one exception is tap
targets, which error because it's an accessibility floor, not a style opinion.
| Rule | Detects | Severity | Example fix |
|---|---|---|---|
spacing-scale | Computed margin/padding/gap that isn't a multiple of the base unit (default 4px) and isn't an allowed value | warn | Snaps to the nearest valid value |
arbitrary-value | Off-scale arbitrary Tailwind classes | warn | py-[13px] → py-3 |
gap-consistency | Siblings in a flex/grid container spaced inconsistently when gap isn't set | warn | Set gap-4 on the container instead of per-child margins |
canonical-size | Icon/interactive-element sizes off the canonical scale, and interactive elements below the tap-target minimum | warn (icons) / error (tap targets) | Snap to canonical size; WCAG 2.5.8 |
Gridproof is built for Tailwind projects — that's where all four rules apply,
since spacing-scale, arbitrary-value, and gap-consistency reason about
Tailwind's spacing scale and utility classes.
On a page it doesn't detect as Tailwind, it auto-falls-back to
accessibility-only checks: canonical-size still runs (tap targets, icon
sizes), the three Tailwind-specific rules are skipped, and the report says so
explicitly rather than silently under-reporting. You can force this with
assumeTailwind: false in config.
Optional gridproof.config.json at your project root (all fields optional;
defaults shown):
{
"baseUnit": 4,
"allowedValues": [1, 2],
"canonicalSizes": [12, 14, 16, 20, 24, 32, 40, 48],
"minTapTarget": 44,
"tapTargetBreakpoint": 768,
"iconTolerance": 2,
"assumeTailwind": "auto",
"rules": {
"spacing-scale": "warn",
"arbitrary-value": "warn",
"gap-consistency": "warn",
"canonical-size": "error"
},
"suppress": [
{ "selector": ".hero-art *", "rules": ["spacing-scale"] },
{ "value": "13px", "reason": "optical correction, logo lockup" }
]
}
Inline suppression: data-gp-ignore (all rules) or
data-gp-ignore="spacing-scale gap-consistency" on any element skips its
subtree for those rules. Suppressed findings are counted, never listed.
Playwright renders the target page headless, a single in-page script walks the DOM and collects computed geometry (margins, padding, gap, rects), and the rule engine checks each value against your config and emits violations with selectors, actual/expected values, and fix hints. It's tuned against roughly 60 real-world sites to keep false positives low — a subpixel rounding tolerance, an allowed-values list, and severity defaults all come out of that calibration, not guesswork.
npm install
npm run build # tsc → dist/
npm test # vitest (unit + Playwright integration)
npm run dev # run the server from TypeScript (tsx)
MIT — v0.1.0
FAQs
Gridproof your UI — automated spacing & grid QA in the agent loop (MCP server).
The npm package gridproof receives a total of 82 weekly downloads. As such, gridproof popularity was classified as not popular.
We found that gridproof demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket’s PHP and Composer support is now in Beta for all customers, with PHP reachability analysis generally available.

Product
Socket is bringing experimental protection to Firefox, scanning 97,000+ extensions in Mozilla's official directory for malware and risky updates.

Research
/Security News
Three compromised Rust crates pulled in a malicious dependency that downloaded and executed cross-platform malware during Cargo builds.