Paste package.json or requirements.txt. DepScope checks npm/PyPI, GitHub activity, and OSV vulnerabilities, then gives you a ranked risk report.
Pulls fresh data from npm and PyPI, not stale snapshots.
Flags known CVEs package-by-package with traffic-light status.
Download a polished report you can share with teams or clients instantly.
package.json, requirements.txt style lists, and most plain dependency line formats.
Score combines vulnerability count, GitHub maintenance signals, and package ecosystem metadata.
No. DepScope performs live API calls across registries and vulnerability sources before creating your report.