npm package vulnerability check
Known vulnerabilities for one package version from OSV.dev, with CISA exploited-in-the-wild flag and the fixed version. Should I install this? Pass ?package=lodash&ecosystem=npm&version=4.17.15 (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex, Pub) and get every known advisory for that exact version from OSV.dev (GitHub, PyPA, Go and RustSec databases), whether any of them is on CISA's Known Exploited Vulnerabilities list, severity, and the version that fixes each.
Listing completeness · 80/100
Presence of published information only. Not a security, reliability or performance score. Same rules for Datoka and external listings.
- Name and traceable source
- 10/10 · Present
- Meaningful description
- 10/10 · Present
- Connection or installation reference
- 20/20 · Present
- Dedicated documentation or source repository
- 0/15 · Missing or insufficient
- Explicit free access or numeric tariff
- 20/20 · Present
- Declared integration protocol
- 10/10 · Present
- Source updated within 90 days
- 10/10 · Present
- Declared capability names
- 0/5 · Missing or insufficient
Evaluated 2026-10-08 · Method listing-completeness-1. Scoring rules
Connect & use
Connect through the publisher’s supported interface. Any credentials or payments are handled by the provider.
x402 resource
https://apexfaucet.xyz/api/x402/software-riskRead the current payment requirements with a compatible client before authorizing a call.
Categories and declared capabilities
Topic categories are derived from publisher text for discovery, not independently verified capabilities.
The registry does not provide a verified tools list. See the observations, when available, for any tools/list check; a published tools list does not establish that execution succeeds.
Evidence, with its limits.
This listing is indexed. Any domain claim or endpoint observation appears separately with its date and limited scope. No payment execution, factual accuracy or safety certification is inferred.