Dependency Security Scanner
Upload your package.json, requirements.txt, or composer.json to instantly check for known vulnerabilities using the OSV database.
Upload File
Drag & drop your dependency file here, or click to browse.
How This Tool Works
Upload & Parse
You upload a package.json, requirements.txt, or composer.json. The tool parses it to extract exact dependency names and strips version modifiers to match against strict database entries.
OSV Database Query
We securely send the parsed list (not your files) to the public Open Source Vulnerabilities (OSV) API, an open database maintained by Google and the open source community.
Vulnerability Report
The OSV database checks each dependency version against known CVEs. If a match is found, we display the vulnerability details, aliases, and provide links to security advisories.