81trust / 100

Software Risk

by npm package vulnerability check in Security & trust

x402 APIPassing, checked 4 h ago

Known vulnerabilities for one package version from OSV.dev, with CISA exploited-in-the-wild flag and the fixed version. Should I install this? Pass ?package=lodash&ecosystem=npm&version=4.17.15 (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex, Pub) and get every known advisory for that exact version from OSV.dev (GitHub, PyPA, Go and RustSec databases), whether any of them is on CISA's Known Exploited Vulnerabilities list, severity, and the version that fixes each.

GET https://apexfaucet.xyz/api/x402/software-risk

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
57 ms typical, 57 ms slowest 5%
Last check
4 h ago
Next check
any minute now

How to call it

# See the payment challenge (nothing is charged)
curl -i -X GET "https://apexfaucet.xyz/api/x402/software-risk?ecosystem=npm&package=lodash&version=4.17.15"
import { wrapFetchWithPayment } from "@x402/fetch";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { privateKeyToAccount } from "viem/accounts";

const client = new x402Client().register(
  "eip155:8453",
  new ExactEvmScheme(privateKeyToAccount(process.env.AGENT_KEY)),
);
const pay = wrapFetchWithPayment(fetch, client);

// Not sure it's safe to pay? Preflight it first for $0.005:
// GET https://toolvet.app/api/v1/check?url=https%3A%2F%2Fapexfaucet.xyz%2Fapi%2Fx402%2Fsoftware-risk
const res = await pay("https://apexfaucet.xyz/api/x402/software-risk?ecosystem=npm&package=lodash&version=4.17.15");
console.log(await res.json());

Example input

{
  "ecosystem": "npm",
  "package": "lodash",
  "version": "4.17.15"
}

Example output

{
  "data": {
    "advisories": 6,
    "ecosystem": "npm",
    "exploited": 0,
    "licenseVerified": true,
    "licenseVerifiedOn": "2026-09-30",
    "note": "Records copied only from databases licen…",
    "ok": true,
    "package": "lodash",
    "sources": [
      {}
    ],
    "verdict": "VULNERABLE: 6 known advisories for this …",
    "version": "4.17.15",
    "vulnerabilities": [
      {}
    ]
  },
  "ok": true,
  "paid": 0.003
}

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTimePrice
4 h agoPassed40257 ms$0.003