Is this package safe? Ask your AI assistant.
DepScout lets ChatGPT, Claude and other AI assistants check open-source packages against live vulnerability and malware data while you work, so answers don't rely on what a model remembers. It covers npm, PyPI, Go, Maven, crates.io and NuGet.
Packages and versions reported as malware (OSV MAL- advisories and GitHub malware advisories) are flagged first.
CVE and GHSA advisories for a specific version, with severity, the version that fixes each one, and the minimum version that clears them all.
Latest stable version, whether your version is outdated or deprecated, last release date, licences and the repository's OpenSSF Scorecard.
Paste up to 50 entries from package.json, requirements.txt, go.mod or similar and get back only the ones with problems.
Try asking
- "Is lodash 4.17.15 safe to use?"
- "Check these requirements.txt pins for vulnerabilities: requests==2.19.0, django==3.2.0, flask==2.3.3"
- "What is CVE-2021-44228 and which log4j version fixes it?"
Good to know
A clean result means no advisory is known in OSV.dev for that exact version; it isn't a guarantee of safety. Newly published malware can take time to be reported. DepScout checks the packages you list, not their transitive dependencies.