DepShield checks live OSV vulnerability data, suspicious typo packages, and risky licenses in one report.
Queries OSV.dev in real time for known vulnerable package versions.
Flags suspicious names that look like common packages used in supply-chain attacks.
Spots restrictive GPL/AGPL-style licenses before they become legal debt.
DepShield pulls live registry and vulnerability data. A prompt-only tool cannot verify real package versions against current CVE databases.
No. Paste only your dependency manifest (package.json or requirements.txt).
Beta scans are free. Premium remediation reports will be $1.99.