๐ŸŽ‰ New here? Use code WELCOME10 for 10% off any plan at checkout
All tools
betanpm / PyPI Trust Scanner

Package Scanner

Supply-chain trust + typosquat + CVE check for any package.

In the wildโ€” Package Scanner runsโ€” Issues surfacedโ€” Countriesยท opt-in only

The problem

Every install pulls 100+ transitive deps. Typosquats are a real attack path; CVEs hide in indirect dependencies.

What it does

Submit a package name; we pull registry metadata, compute typosquat distance to popular packages, surface CVEs via OSV, score maintainer trust, and list top dependents for blast-radius.

Capabilities

  • Trust score with maintainer signals
  • Typosquat distance to popular packages
  • CVE surface (direct + transitive) via OSV
  • npm + PyPI supported; cargo / RubyGems on the roadmap

How you run it

Part of PlayCISO Pro: type a package name in the browser; trust report renders in seconds. API keys for CI checks are on the roadmap.

Roadmap

  • npm + PyPI lookup
  • CVE join via OSV
  • In-browser lookup form
  • Subscriber API keys for CI

FAQ

What does the Package Scanner check?

It checks npm and PyPI packages for known vulnerabilities in the versions you use, malicious- or suspicious-package indicators (such as risky install scripts and typosquatted names), and licence conflicts โ€” the three risks that matter most in a dependency supply chain.

Is npm audit enough on its own?

No. npm audit catches known vulnerabilities but not brand-new malicious packages, typosquats, or fresh compromised updates. A complete approach adds malicious-package and provenance checks on top of known-vulnerability scanning, which is what this scanner does.

How should I use package scanning?

Run it in CI on every pull request, fail builds on high-severity findings, pin and verify dependencies with a committed lockfile, and sandbox or disable install scripts for untrusted packages so a bad dependency is caught before it ships.

Included with any PlayCISO plan

Package Scanner runs inside PlayCISO for subscribers. The source stays private โ€” no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.

Package Scanner โ€” npm & PyPI Dependency Trust Scanner ยท PlayCISO