81trust / 100
Software Risk
by npm package vulnerability check in Security & trust
x402 APIPassing, checked 4 h ago
Known vulnerabilities for one package version from OSV.dev, with CISA exploited-in-the-wild flag and the fixed version. Should I install this? Pass ?package=lodash&ecosystem=npm&version=4.17.15 (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex, Pub) and get every known advisory for that exact version from OSV.dev (GitHub, PyPA, Go and RustSec databases), whether any of them is on CISA's Known Exploited Vulnerabilities list, severity, and the version that fixes each.
GET https://apexfaucet.xyz/api/x402/software-risk
Last 30 days
All checks passedSome failedAll failedNot checked
- Uptime
- 100%
- Response time
- 57 ms typical, 57 ms slowest 5%
- Last check
- 4 h ago
- Next check
- any minute now
How to call it
# See the payment challenge (nothing is charged)
curl -i -X GET "https://apexfaucet.xyz/api/x402/software-risk?ecosystem=npm&package=lodash&version=4.17.15"import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";
const client = new x402Client().register(
"eip155:8453",
new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);
// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fapexfaucet.xyz%2Fapi%2Fx402%2Fsoftware-risk
const res = await pay("https://apexfaucet.xyz/api/x402/software-risk?ecosystem=npm&package=lodash&version=4.17.15");
console.log(await res.json());Example input
{
"ecosystem": "npm",
"package": "lodash",
"version": "4.17.15"
}Example output
{
"data": {
"advisories": 6,
"ecosystem": "npm",
"exploited": 0,
"licenseVerified": true,
"licenseVerifiedOn": "2026-09-30",
"note": "Records copied only from databases licen…",
"ok": true,
"package": "lodash",
"sources": [
{}
],
"verdict": "VULNERABLE: 6 known advisories for this …",
"version": "4.17.15",
"vulnerabilities": [
{}
]
},
"ok": true,
"paid": 0.003
}Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time | Price |
|---|---|---|---|---|
| 4 h ago | Passed | 402 | 57 ms | $0.003 |