Package Vulnerability Checker (OSV)

by prawiefiolekGitHubUpdated Oct 6, 2026

Check any package version — npm, PyPI, Go, Maven, and more — for known vulnerabilities via the OSV.dev database, or scan a full SBOM of up to 50 dependencies in one call. Returns CVE IDs, summaries, CVSS scores, severity ratings, fixed versions, and publication dates. No API key needed.

security
vulnerability
cve
+3
|

How to pay

Pick whichever fits your workflow — you can switch any time.

Subscribe

Monthly billing

Free

Predictable monthly cost with included usage. Best for steady, high-volume traffic.

  • Unlimited tools within plan limits
  • One API key, billed once a month
  • Cancel any time

Pay-per-call

Agent-native

$0.02 per call

Charge agents in USDC the moment they call a tool. No subscriptions, no signup — pay only for what you use.

  • 2 priced tools available
  • Settled in USDC on Base
  • No account or API key required

Check any package version — npm, PyPI, Go, Maven, and more — for known vulnerabilities via the OSV.dev database, or scan a full SBOM of up to 50 dependencies in one call. Returns CVE IDs, summaries, CVSS scores, severity ratings, fixed versions, and publication dates. No API key needed.