Free Tool · Powered by OSV API

Dependency Vulnerability
Checker.

Check open-source packages for known vulnerabilities using the Google OSV database. Search by single package or paste your lock file for bulk scanning. Supports npm, PyPI, Go, Maven, and more.

📦

Dependency Scanner

Related free tools

Read next

SCA vs dependency scan: what is the difference?

Why a lockfile lookup misses transitive, vendored and reachability context — and what full SCA adds.

One lockfile, once, is not a process

Scan every lockfile in
every repo, on every push.

AquilaX SCA resolves the full transitive tree across npm, pip, Maven, Go, Cargo and more, flags licence conflicts, and opens upgrade PRs for vulnerable packages — with Securitron AI suppressing the unreachable ones.

Free plan is permanent · unlimited scans · GitHub, GitLab, Bitbucket & Azure DevOps