Look at the tree, extras, OSV findings, licenses, dependents, similar packages, and health before you edit requirements. PyDeps puts those on one page. If you already have a requirements or lockfile, Analyze Project parses it in the browser. Keep pip-audit in CI after you lock.