Depflush

Guide · Dependencies

Delete node_modules and vendor from old projects on a Mac

Every JavaScript and PHP project carries its own copy of its dependencies. Twenty client projects later, that is easily 10 GB of folders you can rebuild in a minute. Here is how to find them and remove them without breaking anything.

Why it is safe, and when it is not

A node_modules folder next to a package.json, or a vendor folder next to a composer.lock, is generated. The lock file records the exact versions, so you can restore the same folder later:

npm install          # or: npm ci, pnpm install, yarn
composer install

Be careful in two cases:

Find the big ones

List every node_modules folder under your projects folder with its size, largest last:

find ~/Sites -name node_modules -type d -prune -exec du -sh {} + | sort -h

The same for Composer:

find ~/Sites -name vendor -type d -prune -exec du -sh {} + | sort -h

Replace ~/Sites with wherever your projects live, for example ~/Projects or ~/Developer.

Only projects you are not working on

Deleting dependencies of the project you open tomorrow only costs you a reinstall. The real gain is in dormant projects. A simple rule: if none of the project's own files changed in a year, its dependencies can go. When you check the date, ignore vendor, node_modules and .git themselves, because tools touch them all the time.

Delete

For a single project:

rm -rf ~/Sites/old-project/node_modules

For node_modules across many projects, npkill is a free command-line tool that lists them with size and last change and deletes the ones you select:

npx npkill

Don't forget the global caches

Package managers also keep a download cache in your home folder. Clearing it is safe; packages are downloaded again when needed.

npm cache clean --force
composer clear-cache
pnpm store prune

The same, with a preview

Depflush scans your project folders, lists vendor and node_modules only when a composer.lock or package.json sits next to them, and preselects them only for projects untouched for 12 months (you choose the threshold). Dependencies inside plugins are shown with a warning and never preselected. By default everything goes to the Trash. It is free and open source.