Every known vulnerability
starts as a version number.
Outdated dependencies deserve a closer look. We match detected technology versions against public vulnerability records and show the evidence worth investigating.
Matched against osv.dev
Every detected package and version is checked against the open vulnerability database. Not our list - the same public record the maintainers publish to, so you can verify any finding yourself.
osv.devThe release line stopped getting fixes
A version without a matching advisory may still be out of support. Where support-window data is available, we flag release lines that have reached their published end-of-life date.
How far behind, and for how long
Each version is placed in its own release history, so "behind" is a distance and not an opinion. TLS certificate expiry is checked in the same pass.
We audit the stack, not the traffic.
If you came looking for one of these, we are the wrong tool and would rather say so now than after you have signed up:
- Malware or virus scanning. We do not inspect files or scripts for malicious code.
- Phishing detection. We do not judge whether a site is impersonating another.
- Penetration testing. Nothing here probes, injects or attacks anything - every audit is a read.
- Code review. We see what a site serves publicly. We never see the repository.
What we do is narrower and checkable: read the software a site runs, read its versions, and compare both against the public record.
Audit once, or watch it
A single audit is free and needs no installation - enter an address and read the result in about two minutes. Watching is the part that matters for security: a vulnerability published next month against a version you already run is the one that gets you, and only a scheduled re-audit finds it.
Scheduled alerts for vulnerabilities, end-of-life and version drift are part of the paid plans; a one-off audit is not.