Developer

Dependency Risk Scanner

A dependency risk scanner reads a package.json or requirements.txt and flags the problems that scanners exist to catch: versions below a known-fixed release, wildcard and caret ranges that resolve to anything, dependencies pulled from git URLs, and packages that are abandoned. It parses the file rather than matching strings.

Last reviewed by the Radiatus Cloud team



Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

What it parses

Paste JSON and it reads dependencies, devDependencies, peerDependencies and optionalDependencies, plus the packages map from a package-lock. Paste a requirements.txt and it reads each pinned or ranged line. Each dependency is compared against a built-in advisory list of common packages with a known-fixed version, and its version is compared numerically, so lodash 4.17.15 is flagged while 4.17.21 is not.

The advisory list

The list covers widely used packages across npm, PyPI and Maven with real fixed versions and a one-line reason: lodash prototype pollution, axios SSRF, minimist and qs pollution, PyYAML arbitrary code execution via full_load, Log4Shell, the Next.js middleware bypass and others. It is maintained by hand and is not the full CVE database; it exists to catch the handful of packages that appear in most real audits.

Structural checks

  • Wildcard versions (*, latest) that resolve to whatever is newest at install time.
  • Git, http or file dependencies with no integrity guarantee.
  • Caret ranges on 0.x versions, where the API is declared unstable.
  • Abandoned packages such as request and node-uuid, flagged regardless of version.

Use it alongside the real scanners

This runs offline and gives an instant read on a pasted manifest, which npm audit and pip-audit cannot do without your project installed. But those tools carry the complete advisory databases and see your full dependency tree including transitive packages. Run osv-scanner or npm audit for coverage; use this for the structural issues they do not report and for a fast first look.

Related tools

  • Dependency License Check — A new tool extracted from the codebase.
  • SemVer Bump Calculator — Compute the next semantic version for major/minor/patch bumps and optionally add prerelease/build metadata.
  • Gitignore Generator — Generate a .gitignore file for common stacks (Node, Python, PHP, Java, .NET) and OS files.
  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.

Frequently Asked Questions

Does this replace npm audit or pip-audit?

No. Those carry the full vulnerability databases and resolve your entire dependency tree, including transitive dependencies this tool cannot see from a manifest alone. Use them for coverage and this for a quick structural check and the issues they skip.

How current is the advisory list?

It is a hand-maintained list of the packages that appear most often in audits, with fixed versions as of the tool's last update. It is not the live CVE feed, so a clean result is not a guarantee of no vulnerabilities.

Is my manifest uploaded?

No. Parsing and comparison run in your browser. You can paste a private package.json without it leaving the page.

Why does it flag unpinned versions?

A caret, tilde or wildcard range means the installed version depends on when you installed. That makes builds non-reproducible and lets a compromised release enter without a code change. Pinning exact versions with a lockfile is the fix.

What formats does it accept?

npm package.json and package-lock.json extracts, and Python requirements.txt. It auto-detects JSON versus a requirements list and picks the matching advisory set.

Privacy & Security

Processed locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.