Overview
Scan a dependency manifest for known-vulnerable and confirmed-malicious packages. POST /v1/scan with a raw lockfile or a components array and get per-dependency verdicts (malicious, vulnerable, suspicious, clean) from OSV.dev and the OpenSSF Malicious Packages feed, each with a summary and snapshot timestamp. Pay per request in USDC; no account, no API key.
Health
Also available via
Recent Health Checks
| Time | Status | HTTP | Latency | Error |
|---|---|---|---|---|
| 2026-09-30 01:23:36 | healthy | 402 | 69ms | |
| 2026-09-29 19:33:41 | healthy | 402 | 149ms | |
| 2026-09-29 14:51:00 | healthy | 402 | 62ms | |
| 2026-09-29 04:51:55 | healthy | 402 | 92ms | |
| 2026-09-29 01:26:29 | healthy | 402 | 86ms | |
| 2026-09-28 14:12:39 | healthy | 402 | 160ms | |
| 2026-09-28 05:02:31 | healthy | 402 | 20ms | |
| 2026-09-27 23:34:26 | healthy | 402 | 96ms | |
| 2026-09-27 14:26:17 | healthy | 402 | 68ms | |
| 2026-09-27 05:31:21 | healthy | 402 | 77ms |