Guide · Dependencies
Delete node_modules and vendor from old projects on a Mac
Every JavaScript and PHP project carries its own copy of its dependencies. Twenty client projects later, that is easily 10 GB of folders you can rebuild in a minute. Here is how to find them and remove them without breaking anything.
Why it is safe, and when it is not
A node_modules folder next to a package.json, or a vendor folder next to a composer.lock, is generated. The lock file records the exact versions, so you can restore the same folder later:
npm install # or: npm ci, pnpm install, yarn
composer install
Be careful in two cases:
- No lock file. Without
package-lock.json,pnpm-lock.yaml,yarn.lockorcomposer.lock, a reinstall can pull newer versions than the ones the project was built with. - Committed or shipped dependencies. Some plugins and themes ship their
vendorfolder, for example extensions that are uploaded to a shop as a ZIP. Ifgit ls-files vendorlists files, the folder is part of the project; leave it.
Find the big ones
List every node_modules folder under your projects folder with its size, largest last:
find ~/Sites -name node_modules -type d -prune -exec du -sh {} + | sort -h
The same for Composer:
find ~/Sites -name vendor -type d -prune -exec du -sh {} + | sort -h
Replace ~/Sites with wherever your projects live, for example ~/Projects or ~/Developer.
Only projects you are not working on
Deleting dependencies of the project you open tomorrow only costs you a reinstall. The real gain is in dormant projects. A simple rule: if none of the project's own files changed in a year, its dependencies can go. When you check the date, ignore vendor, node_modules and .git themselves, because tools touch them all the time.
Delete
For a single project:
rm -rf ~/Sites/old-project/node_modules
For node_modules across many projects, npkill is a free command-line tool that lists them with size and last change and deletes the ones you select:
npx npkill
Don't forget the global caches
Package managers also keep a download cache in your home folder. Clearing it is safe; packages are downloaded again when needed.
npm cache clean --force
composer clear-cache
pnpm store prune
The same, with a preview
Depflush scans your project folders, lists vendor and node_modules only when a composer.lock or package.json sits next to them, and preselects them only for projects untouched for 12 months (you choose the threshold). Dependencies inside plugins are shown with a warning and never preselected. By default everything goes to the Trash. It is free and open source.