Supply-chain security
Scan your dependencies for malicious code
Drop in a lockfile or manifest from npm, Python, Rust, Go, Ruby or PHP. Every package is downloaded and its source is read by an AI model looking for malware, exfiltration and backdoors.
- Priced per token, quoted upfront
- Files scanned before are free
- Pay in USDC on Base, or get monthly access via Ko-fi
1
Upload a dependency file
Parsing is free and happens on the server
or check a single package
2
Review & quote
See what's cached and what the scan will cost
Upload a dependency file to see what's in it
3
Results
Findings from the scan, by severity
Results appear here after the scan