Detect Abandoned & Vulnerable Dependencies Instantly
Scan your dependency files for CVE vulnerabilities, unmaintained packages, and supply chain risks. Get risk scores, bus factor analysis, and replacement suggestions. All running 100% in your browser.
How to Scan Your Dependencies for Security Risks
No signup required. No data leaves your browser. Paste, upload, or connect GitHub. Scan in seconds.
Add Your Dependencies
Paste your package.json, upload a file, enter a GitHub repo URL, or connect your GitHub account to select any repository.
Automated CVE & Risk Analysis
We check each package against the OSV vulnerability database, registries for staleness, deprecation, bus factor, and 5 other risk signals.
Actionable Risk Report
Get a prioritized dashboard with risk scores, CVE details with severity ratings, and curated replacement suggestions for every risky package.
Scan Dependencies Across 5 Ecosystems
One tool for all your dependency files. Just paste or upload, and we auto-detect the ecosystem.
package.jsonNode.js packages
requirements.txtPython packages
GemfileRuby gems
go.modGo packages
Cargo.tomlRust crates
The Most Complete Dependency Risk Scanner
Go beyond CVE scanning. Detect abandoned packages, single-maintainer risks, and deprecated libraries before they compromise your software supply chain.
CVE Vulnerability Scanning
Checks every dependency against Google's OSV database for known security vulnerabilities with CVSS severity ratings.
Deadware Risk Score
Every package gets a 0-100 risk score based on 7 weighted factors: staleness, bus factor, archived status, CVEs, deprecation, and more.
Bus Factor Analysis
Identify single-maintainer packages, the #1 predictor of future abandonment and supply chain incidents.
5 Ecosystems Supported
npm (package.json), PyPI (requirements.txt), RubyGems (Gemfile), Go Modules (go.mod), and Cargo (Cargo.toml).
50+ Replacement Suggestions
Get curated, actively-maintained alternatives for every risky package, from "moment" to "date-fns".
Deprecation Detection
Instantly detect npm deprecated packages with the exact deprecation message from maintainers.
PDF, JSON & CSV Export
Export reports as PDF for stakeholders, JSON for CI/CD, or CSV for spreadsheets.
Privacy-First (BYOK)
All analysis runs in your browser. Bring your own GitHub token for richer data. Nothing ever leaves your machine.
GitHub Integration
Scan any public repo by URL, or connect your account to browse and scan private repos.
CI Health Badge
Embed a shields.io badge in your README showing your dependency health score.
Sort, Filter & Search
Sort by risk, name, or staleness. Filter by level. Find the most dangerous dependencies instantly.
Instant Results
Scans complete in seconds with parallel registry and CVE lookups. No queues or accounts needed.
Enterprise Security, Indie-Hacker Price
The same vulnerability + abandonment scanning that enterprises pay $400/mo for, starting at $0.
Free
No credit card required
- 5 scans per month
- CVE vulnerability detection
- Abandonment risk scoring
- Replacement suggestions
- npm, PyPI, Go, Cargo, Ruby
- Share results link
Pro
Save $390/mo vs Snyk
- Unlimited scans
- All 5+ ecosystems
- PDF, CSV & JSON export
- SBOM export (CycloneDX)
- CI badge & GitHub Actions YAML
- Scan history (50 reports)
- GitHub enrichment (BYOK)
- Priority support
Cancel anytime. No lock-in.
Team
$3/seat, cheaper than a coffee
- Everything in Pro
- Up to 10 team members
- Shared scan dashboard
- Slack/webhook notifications
- Custom risk thresholds
- Priority support
- Annual billing discount
Trusted by developers scanning dependencies across
How We Compare
Most security tools focus only on CVEs. Deadware Risk Scanner goes further, detecting abandoned packages before they become a problem.
| Feature | Deadware | Snyk | Dependabot | Socket.dev |
|---|---|---|---|---|
| Deadware / abandonment detection | ||||
| CVE vulnerability scanning | ||||
| Bus factor / maintainer analysis | ||||
| Replacement suggestions | ||||
| 100% client-side (no data sent) | ||||
| No account required | ||||
| Multi-ecosystem support | ||||
| CI badge generation | ||||
| PDF / CSV / JSON export | ||||
| Free tier available | ||||
| Open-source | ||||
| License risk detection |
Frequently Asked Questions
Everything you need to know about scanning your dependencies for risks.
Stop Gambling on Dead Dependencies
Join developers who scan their dependencies for vulnerabilities, abandoned packages, and supply chain risks. Free, with zero setup.