Security

Every known vulnerability
starts as a version number.

Outdated dependencies deserve a closer look. We match detected technology versions against public vulnerability records and show the evidence worth investigating.

Known vulnerabilities

Matched against osv.dev

Every detected package and version is checked against the open vulnerability database. Not our list - the same public record the maintainers publish to, so you can verify any finding yourself.

osv.dev
End of life

The release line stopped getting fixes

A version without a matching advisory may still be out of support. Where support-window data is available, we flag release lines that have reached their published end-of-life date.

Drift and certificates

How far behind, and for how long

Each version is placed in its own release history, so "behind" is a distance and not an opinion. TLS certificate expiry is checked in the same pass.

What this is not

We audit the stack, not the traffic.

If you came looking for one of these, we are the wrong tool and would rather say so now than after you have signed up:

  • Malware or virus scanning. We do not inspect files or scripts for malicious code.
  • Phishing detection. We do not judge whether a site is impersonating another.
  • Penetration testing. Nothing here probes, injects or attacks anything - every audit is a read.
  • Code review. We see what a site serves publicly. We never see the repository.

What we do is narrower and checkable: read the software a site runs, read its versions, and compare both against the public record.

How to use it

Audit once, or watch it

A single audit is free and needs no installation - enter an address and read the result in about two minutes. Watching is the part that matters for security: a vulnerability published next month against a version you already run is the one that gets you, and only a scheduled re-audit finds it.

Scheduled alerts for vulnerabilities, end-of-life and version drift are part of the paid plans; a one-off audit is not.