Suspicious Package
Suspicious Package is a macOS utility for opening installer packages and showing what they contain before you run them.
What is Suspicious Package?
Suspicious Package is a macOS utility that helps users inspect installer packages before installing them. It is designed for people who want to understand what a .pkg installer will place on a Mac, who signed it, what scripts it may run, and whether Apple notarized it. The app lets you browse installed files, review package metadata, inspect receipts, and check potential issues without performing the installation itself. It also includes a Quick Look extension so package details can be previewed directly from Finder. This makes it useful for cautious home users, Mac administrators, and developers who regularly evaluate third-party installers. Suspicious Package is published by Randy Saldinger through Mothers Ruin Software and is built specifically for macOS.
Key features
- Open macOS installer packages without installing them
- Browse the files and folders an installer would place on your Mac
- View signing, download source, notarization, and Apple Silicon details
- Inspect installer scripts and receipts included in a package
- Preview package contents with a Finder Quick Look extension
- Open or export selected text files, property lists, and other package items
Review app leftovers with diCleaner
Inspect caches, support files, containers, and login items before cleaning.
Safety overview
Status: Safe
Suspicious Package is a legitimate macOS inspection tool whose behavior matches its purpose: it reads installer packages so you can review their contents before installation. It does not install the package you open just by inspecting it. The developer also states that the app is not an anti-malware product, so it is best used as an information and review tool rather than as a guarantee that a package is safe.
Recommendation: Keep Suspicious Package if you download or review macOS .pkg installers and want a safer way to inspect them before running them. If you never work with installer packages, removing it is usually fine and only takes away its package-inspection and Quick Look features.
Common paths
/Applications/Suspicious Package.app
Preference paths
~/Library/Preferences/com.mothersruin.SuspiciousPackageApp.plist
Share your experience
Be the first to share your experience.