Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.
Cost / License
- Free Personal
- Proprietary
Platforms
- Online
Denmark
EU



Sites and apps similar to Libraries.io include GitHub, which has a free version. Other options are NewReleases, Patchdex, Aikido Security and Proscan AppSec. You can choose from more than 10 Vulnerability Scanners like Libraries.io for Windows, Linux, self-hosting, Mac and Android.
Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.



NPMScan is a security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used...




SkillRisk is a specialized security analysis tool designed for the AI Agent ecosystem, specifically focusing on Claude Code and Model Context Protocol (MCP) skills.




Software updates straight to your inbox. Touchpine monitors your applications and libraries - you no longer need to subscribe to dozens of security mailing lists to watch for software updates. Touchpine delivers fully customized notifications to your email.



PackageFix is a free browser-based dependency security fixer. Paste your manifest file and get back a fixed version with every vulnerable package patched — ready to download in one click.



Local command-line scanner that measures dependency, framework and runtime drift, checks known vulnerability advisories, and prioritizes upgrades. It builds a code graph to trace imports and calls, assess change impact, and provide matching docs to AI assistants.




Get notified by a email and a push notification every time a new release of your repository is available.
Dependency Update Automation for npm, composer and docker made easy. Check your git repositories for vulnerabilities now!.



