2s
Security and provenance for an open-source package, composed live from three authoritative sources in one call. Pass ecosystem (npm, pypi, go, maven, cargo, nuget) + name (+ optional version; defaults to latest). Returns: known vulnerabilities from OSV (osv.dev — aggregates GitHub Security Advisories, PyPA, RustSec, Go vuln DB, etc.) each with its id, CVE aliases, summary, severity, and references; the resolved license and deprecation status (deps.dev); and the source repo's OpenSSF Scorecard health score (overall + per-check) plus stars/forks/open-issues. All live — newly-disclosed advisories appear within hours. Distinct from registry.npm-lookup / pypi-lookup (metadata only): this answers "is this dependency safe to add, what license does it carry, and how well-maintained is it."
Listing completeness · 80/100
Presence of published information only. Not a security, reliability or performance score. Same rules for Datoka and external listings.
- Name and traceable source
- 10/10 · Present
- Meaningful description
- 10/10 · Present
- Connection or installation reference
- 20/20 · Present
- Dedicated documentation or source repository
- 0/15 · Missing or insufficient
- Explicit free access or numeric tariff
- 20/20 · Present
- Declared integration protocol
- 10/10 · Present
- Source updated within 90 days
- 10/10 · Present
- Declared capability names
- 0/5 · Missing or insufficient
Evaluated 2026-10-08 · Method listing-completeness-1. Scoring rules
Connect & use
Connect through the publisher’s supported interface. Any credentials or payments are handled by the provider.
x402 resource
https://2s.io/api/security/packageRead the current payment requirements with a compatible client before authorizing a call.
Categories and declared capabilities
Topic categories are derived from publisher text for discovery, not independently verified capabilities.
The registry does not provide a verified tools list. See the observations, when available, for any tools/list check; a published tools list does not establish that execution succeeds.
Evidence, with its limits.
This listing is indexed. Any domain claim or endpoint observation appears separately with its date and limited scope. No payment execution, factual accuracy or safety certification is inferred.