Package Scanner
Supply-chain trust + typosquat + CVE check for any package.
The problem
Every install pulls 100+ transitive deps. Typosquats are a real attack path; CVEs hide in indirect dependencies.
What it does
Submit a package name; we pull registry metadata, compute typosquat distance to popular packages, surface CVEs via OSV, score maintainer trust, and list top dependents for blast-radius.
Capabilities
- Trust score with maintainer signals
- Typosquat distance to popular packages
- CVE surface (direct + transitive) via OSV
- npm + PyPI supported; cargo / RubyGems on the roadmap
How you run it
Part of PlayCISO Pro: type a package name in the browser; trust report renders in seconds. API keys for CI checks are on the roadmap.
Roadmap
- npm + PyPI lookup
- CVE join via OSV
- In-browser lookup form
- Subscriber API keys for CI
Related tools
FAQ
What does the Package Scanner check?
It checks npm and PyPI packages for known vulnerabilities in the versions you use, malicious- or suspicious-package indicators (such as risky install scripts and typosquatted names), and licence conflicts โ the three risks that matter most in a dependency supply chain.
Is npm audit enough on its own?
No. npm audit catches known vulnerabilities but not brand-new malicious packages, typosquats, or fresh compromised updates. A complete approach adds malicious-package and provenance checks on top of known-vulnerability scanning, which is what this scanner does.
How should I use package scanning?
Run it in CI on every pull request, fail builds on high-severity findings, pin and verify dependencies with a committed lockfile, and sandbox or disable install scripts for untrusted packages so a bad dependency is caught before it ships.
Package Scanner runs inside PlayCISO for subscribers. The source stays private โ no public repos, nothing to fork, nothing for attackers to study. Weekly, monthly, and yearly plans all include every tool.