Togoder security

Supply-chain security

Scan your dependencies for malicious code

Drop in a lockfile or manifest from npm, Python, Rust, Go, Ruby or PHP. Every package is downloaded and its source is read by an AI model looking for malware, exfiltration and backdoors.

  • Priced per token, quoted upfront
  • Files scanned before are free
  • Pay in USDC on Base, or get monthly access via Ko-fi
1

Upload a dependency file

Parsing is free and happens on the server

npm
package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, package.json
Python
poetry.lock, uv.lock, Pipfile.lock, requirements.txt, pyproject.toml
Rust
Cargo.lock
Go
go.mod, go.sum
Ruby
Gemfile.lock
PHP
composer.lock
or check a single package

The package and every runtime dependency it installs are checked. Leave the version empty for the latest release.

2

Review & quote

See what's cached and what the scan will cost

Upload a dependency file to see what's in it

3

Results

Findings from the scan, by severity

Results appear here after the scan