PackagePulse

Know what you are depending on.

Check any PyPI or npm package for known vulnerabilities, release activity, repository status and supply-chain risk. The evidence comes from five sources at once, and every point of the score shows its reason.

Checking a whole project? Scan a requirements.txt or package.json to get a ranked list of what to fix first.