Free Tool

Am I Vulnerable?

Paste a CVE or GHSA ID and your lockfile. We'll check every dependency against the advisory using the OSV.dev database — nothing is uploaded or stored.

Run a check

Also accepts Hextrap advisories (e.g. HX-2026-0001) for packages we've flagged before a CVE/GHSA exists.

Choosing a file just reads it into this box in your browser — nothing is uploaded.

🔎

Supported formats

Python requirements.txt & uv.lock, npm package-lock.json, Rust Cargo.lock, and Go go.mod.

Pinned versions only

Real lockfiles are always checked exactly. An unpinned requirements.txt line (e.g. requests>=2.20) is reported as "can't determine" rather than guessed.

🛡

Want continuous protection?

Hextrap Firewall blocks vulnerable and malicious packages automatically, before they ever install.

Explore the Firewall →