What it is
Rather than simply matching versions against a CVE database, it analyses the package's own behaviour: whether it adds install scripts, whether it reaches the network or the file system, or whether maintainers change in a suspicious way.
Best for
Catching a malicious package before you install it.
What the free plan includes
- Public repositories at no cost
- A GitHub app that comments on pull requests
- Paid plans for private organisations
Free plans change often. Confirm the limits on the official page before deciding.