DependencywatchDependencywatch
Dependencywatch

Dependencywatch

Scan lockfiles for npm/PyPI compromises, free and in-browser.

Active

About

DependencyWatch is a free, in-browser tool that allows users to paste their lockfiles (e.g., `package-lock.json`, `yarn.lock`, `Pipfile.lock`, `poetry.lock`) to instantly check if their dependencies have been compromised by known security vulnerabilities, particularly focusing on recent threats like the 2026 npm or PyPI compromises. It requires no signup and operates entirely client-side for user privacy and ease of use.

Technology stack

detected 2026-06-16
Est. monthly stack spend~$160/mo
CDN
Vercel
Emailnone
Hosting
Vercel
Stack
Next.jsTailwind CSS
Comments

No comments yet. Be the first to share your take.

Frequently asked

What does Dependencywatch do?

DependencyWatch is a free, in-browser tool that allows users to paste their lockfiles (e.g., `package-lock.json`, `yarn.lock`, `Pipfile.lock`, `poetry.lock`) to instantly check if their dependencies have been compromised by known security vulnerabilities, particularly focusing on recent threats like the 2026 npm or PyPI compromises. It requires no signup and operates entirely client-side for user privacy and ease of use.

What industry does Dependencywatch operate in?

Dependencywatch operates in Cybersecurity, Developer Tools, Open Source, Security, Threat Detection.