

Aggregates Vulnerability Exploitability eXchange (VEX) documents from open-source projects. Organizes by PURL for automated security tool integration.

Tool to identify the best mechanisms for privately disclosing a security vulnerability for a package/project.

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

GitHub Actions Pipeline Enumeration and Attack Tool

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation