Dependency CVE Scanner

Paste package.json, requirements.txt, pom.xml or go.mod and see which of your dependencies have published security advisories, with the severity, the CVE number and the version that fixes it. Powered by the free Google OSV database.

Supports package.json, package-lock.json, requirements.txt, pom.xml and go.mod. Paste the file contents, not a description.

Free · No signup · Powered by Creative Nexus AI

Your results will appear here.

Frequently asked

Where do the results come from?

The Google OSV database at osv.dev, which aggregates advisories from GitHub, PyPI, Maven, the Go vulnerability database and others. Every finding links to the source advisory, so nothing here is a model's guess.

Is my code sent anywhere?

Only package names and version numbers are sent to the OSV API so it can look them up. Nothing is stored on our side and no source code is transmitted, because a manifest contains no source code.

Why does it say it checked the lowest version in a range?

A manifest entry like ^4.17.15 means 4.17.15 or a newer compatible release, so the exact installed version is in your lockfile rather than the manifest. Paste package-lock.json instead and you will get exact installed versions.

No results came back, am I safe?

It means none of the packages checked have a published advisory affecting that version. It does not cover your own code, private packages, transitive dependencies missing from a plain manifest, or vulnerabilities nobody has reported yet.

More site security tools

Want this done for your whole site, automatically?

Creative Nexus audits your site, writes the fixes, and keeps you ranking on Google and cited by AI search.

Run a free audit