Supply chain risk scanner

Paste your dependencies.
See what's hiding.

Three packages in a typical project are CRITICAL right now: chalk (399M downloads/week, 1 maintainer), zod (139M, 1 maintainer), axios (96M, 1 maintainer — attacked April 1st). Stars and READMEs don't show this. Behavioral signals do.

No install. No API key. Data from npm registry + PyPI. Source code →

What the score measures

Longevity How long has this package existed? Abandoned projects get reactivated for attacks.
Maintainer depth Single maintainer + millions of weekly downloads = the attack surface LiteLLM exploited.
Release consistency Regular releases signal active oversight. Long gaps = vulnerability accumulation.
Download trend Growing packages attract more scrutiny (and attacks). Stable = lower profile.

Risk flags: CRITICAL = single maintainer + >10M weekly downloads (exact LiteLLM/axios attack profile). HIGH = package <1yr old + rapid adoption. WARN = no release in 12+ months.