Free tools

Package vulnerability lookup.

Look up known vulnerabilities for an npm or PyPI package version in the OSV.dev database, with severity and the versions that fix them.

What it checks

Checks

  • Published advisories in OSV.dev that affect the exact version you enter, or every version when you leave it blank.

  • Each advisory's severity, from its reviewed rating or its CVSS v3 score.

  • The versions that fix it.

Doesn’t check

  • The package's own dependencies, or the rest of yours.

  • Whether your code reaches the vulnerable function.

  • Malicious or compromised packages that are not yet in OSV.dev.

Questions

Where does the data come from?

OSV.dev, an open database run by Google that collects advisories from the GitHub Advisory Database, the Python Packaging Advisory Database and others.

Can I check a whole lockfile?

Not here. This tool checks one package and version at a time.

Why does a severity say Unknown?

Some advisories carry no reviewed rating and no CVSS v3 score. Read the advisory to judge it.

Is the package name sent anywhere?

To OSV.dev, as the query. Nothing is sent about you or your project.

Is what I enter stored?

No. Your IP address is used only to count requests for rate limiting, for one minute, and what you enter is not logged or kept.

Check a whole repository,
free.