Free & Open Source Dependency Scanner

Detect Abandoned & Vulnerable Dependencies Instantly

Scan your dependency files for CVE vulnerabilities, unmaintained packages, and supply chain risks. Get risk scores, bus factor analysis, and replacement suggestions. All running 100% in your browser.

100% Client-Side
No Data Sent to Servers
CVE & OSV Scanning
5 Ecosystems
No Signup Required
0+
Ecosystems Supported
0
Risk Factors Analyzed
0+
Package Replacements
0%
Client-Side Processing

How to Scan Your Dependencies for Security Risks

No signup required. No data leaves your browser. Paste, upload, or connect GitHub. Scan in seconds.

01

Add Your Dependencies

Paste your package.json, upload a file, enter a GitHub repo URL, or connect your GitHub account to select any repository.

02

Automated CVE & Risk Analysis

We check each package against the OSV vulnerability database, registries for staleness, deprecation, bus factor, and 5 other risk signals.

03

Actionable Risk Report

Get a prioritized dashboard with risk scores, CVE details with severity ratings, and curated replacement suggestions for every risky package.

Scan Dependencies Across 5 Ecosystems

One tool for all your dependency files. Just paste or upload, and we auto-detect the ecosystem.

npm
package.json

Node.js packages

PyPI
requirements.txt

Python packages

RubyGems
Gemfile

Ruby gems

Go Modules
go.mod

Go packages

Cargo
Cargo.toml

Rust crates

The Most Complete Dependency Risk Scanner

Go beyond CVE scanning. Detect abandoned packages, single-maintainer risks, and deprecated libraries before they compromise your software supply chain.

CVE Vulnerability Scanning

Checks every dependency against Google's OSV database for known security vulnerabilities with CVSS severity ratings.

Deadware Risk Score

Every package gets a 0-100 risk score based on 7 weighted factors: staleness, bus factor, archived status, CVEs, deprecation, and more.

Bus Factor Analysis

Identify single-maintainer packages, the #1 predictor of future abandonment and supply chain incidents.

5 Ecosystems Supported

npm (package.json), PyPI (requirements.txt), RubyGems (Gemfile), Go Modules (go.mod), and Cargo (Cargo.toml).

50+ Replacement Suggestions

Get curated, actively-maintained alternatives for every risky package, from "moment" to "date-fns".

Deprecation Detection

Instantly detect npm deprecated packages with the exact deprecation message from maintainers.

PDF, JSON & CSV Export

Export reports as PDF for stakeholders, JSON for CI/CD, or CSV for spreadsheets.

Privacy-First (BYOK)

All analysis runs in your browser. Bring your own GitHub token for richer data. Nothing ever leaves your machine.

GitHub Integration

Scan any public repo by URL, or connect your account to browse and scan private repos.

CI Health Badge

Embed a shields.io badge in your README showing your dependency health score.

Sort, Filter & Search

Sort by risk, name, or staleness. Filter by level. Find the most dangerous dependencies instantly.

Instant Results

Scans complete in seconds with parallel registry and CVE lookups. No queues or accounts needed.

Save 97% vs enterprise tools

Enterprise Security, Indie-Hacker Price

The same vulnerability + abandonment scanning that enterprises pay $400/mo for, starting at $0.

Snyk$399/mo
Socket.dev$200/mo
WhiteSource$250/mo
Deadware Scanner$9/mo

Free

$0/forever

No credit card required

  • 5 scans per month
  • CVE vulnerability detection
  • Abandonment risk scoring
  • Replacement suggestions
  • npm, PyPI, Go, Cargo, Ruby
  • Share results link
Start Free
MOST POPULAR

Pro

$9/month

Save $390/mo vs Snyk

  • Unlimited scans
  • All 5+ ecosystems
  • PDF, CSV & JSON export
  • SBOM export (CycloneDX)
  • CI badge & GitHub Actions YAML
  • Scan history (50 reports)
  • GitHub enrichment (BYOK)
  • Priority support
Upgrade to Pro

Cancel anytime. No lock-in.

Team

$29/month

$3/seat, cheaper than a coffee

  • Everything in Pro
  • Up to 10 team members
  • Shared scan dashboard
  • Slack/webhook notifications
  • Custom risk thresholds
  • Priority support
  • Annual billing discount
Upgrade to Team

Trusted by developers scanning dependencies across

npmPyPIRubyGemsGo ModulesCargo

How We Compare

Most security tools focus only on CVEs. Deadware Risk Scanner goes further, detecting abandoned packages before they become a problem.

FeatureDeadwareSnykDependabotSocket.dev
Deadware / abandonment detection
CVE vulnerability scanning
Bus factor / maintainer analysis
Replacement suggestions
100% client-side (no data sent)
No account required
Multi-ecosystem support
CI badge generation
PDF / CSV / JSON export
Free tier available
Open-source
License risk detection

Frequently Asked Questions

Everything you need to know about scanning your dependencies for risks.

Deadware refers to software dependencies that are no longer maintained: no updates, no security patches, no bug fixes. If you depend on deadware, you're exposed to unpatched vulnerabilities, compatibility issues, and potential supply chain attacks. Studies show that over 20% of npm packages haven't been updated in 2+ years.
Each package is scored from 0 (healthy) to 100 (critical risk) based on up to 7 weighted factors: release freshness (35%), bus factor/maintainer count (25%), repository archived status (20%), open issue backlog (10%), license type (10%), known CVE vulnerabilities (30%), and deprecation status (25%). The overall score is a weighted average of all available factors.
No. All analysis runs 100% in your browser. We only make read-only requests to public registries (npm, PyPI) and the OSV vulnerability database. Your dependency files, source code, and tokens never leave your machine. This makes Deadware Risk Scanner the most privacy-friendly dependency scanner available.
We support 5 ecosystems: npm (package.json, package-lock.json), PyPI (requirements.txt, Pipfile), RubyGems (Gemfile), Go Modules (go.mod), and Cargo/Rust (Cargo.toml). You can paste content, upload files, scan any public GitHub repo by URL, or connect your GitHub account to scan private repos.
We query the OSV.dev database (maintained by Google) for each package and version in your dependency file. OSV aggregates vulnerability data from GitHub Security Advisories, npm advisories, PyPI advisories, RustSec, and other sources. Each vulnerability is rated by severity (Critical, High, Moderate, Low) based on its CVSS score.
Most security tools focus only on known CVEs. Deadware Risk Scanner goes further by detecting abandoned and unmaintained packages BEFORE they become a security risk. We analyze bus factor, release frequency, repository status, and deprecation, risks that CVE-only tools miss entirely. Plus, we're 100% client-side and free to use, with no signup required.
A GitHub token is optional but recommended. Without it, you get registry data and CVE scanning. With a token (public_repo scope), you also get repository archived status, open issue counts, security policy detection, and the ability to scan your private repositories, making the risk assessment significantly more accurate.
We maintain a curated database of 50+ known abandoned or deprecated packages with actively-maintained alternatives. For example, if you use "moment" for dates, we suggest "date-fns", "dayjs", or "luxon". If you use "request" for HTTP, we suggest "undici", "node-fetch", or "axios". Each suggestion includes a link and reason.
Yes! Export your scan results as JSON and integrate them into your CI pipeline. You can also embed a shields.io health badge in your README using the CI Badge feature (Pro plan). We also provide CSV export for spreadsheet analysis. Full CI/CD GitHub Actions integration is on our roadmap.
Yes! The entire codebase is open source and available on GitHub. You can inspect every line of code, contribute improvements, or self-host it. We believe security tools should be transparent and community-driven.

Stop Gambling on Dead Dependencies

Join developers who scan their dependencies for vulnerabilities, abandoned packages, and supply chain risks. Free, with zero setup.