NPMScan Alternatives

NPMScan is described as 'Security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used' and is an website in the security & privacy category. There are more than 25 alternatives to NPMScan, not only websites but also apps for a variety of platforms, including SaaS, Mac, Self-Hosted and Windows apps. The best NPMScan alternative is GitHub, which is free. Other great sites and apps similar to NPMScan are Artemis Security Scanner, Mend Renovate, Libraries.io and Aikido Security.

Copy a direct link to this comment to your clipboard
NPMScan alternatives page was last updated

Alternatives list

  1. Mend.io icon
     7 likes
    Copy a direct link to this comment to your clipboard

    Mend.io offers the first AI native application security platform, purpose-built to secure AI-generated code and embedded AI components. Our unified platform enables companies to manage application risk effectively in modern software development.

    Cost / License

    • Subscription
    • Proprietary

    Application type

    Platforms

    • Online
    • Self-Hosted
    • Software as a Service (SaaS)
     
    • Mend.io is the most popular commercial alternative to NPMScan.

    • Mend.io is Paid and ProprietaryNPMScan is Free and Proprietary
  2. AquilaX icon
     1 like
    Copy a direct link to this comment to your clipboard

    AquilaX Ultimate is a comprehensive software security scanner, designed to detect a wide range of security vulnerabilities in the source code of any application. Is committed to change how contextual analysis is done to eliminate virtually any false positive.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Application type

    Platforms

    • Online
    • Software as a Service (SaaS)
     
  3. Copy a direct link to this comment to your clipboard

    A single pane of glass for understanding and mitigating risks across your entire codebase and supply chain.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Application type

    Platforms

    • Software as a Service (SaaS)
     
  4. Copy a direct link to this comment to your clipboard

    Dependency Track SaaS provided by YourSky.blue is the managed cloud solution of the popular open-source Dependency-Track. Always up to date with the latest security bulletins, it allows to easily monitor all the chain of software components through powerful dashboards and...

    Cost / License

    • Subscription
    • Open Source

    Application type

    Platforms

    • Online
    • Software as a Service (SaaS)
     
  5. Copy a direct link to this comment to your clipboard

    The most proven open source scanning solution to help organizations understand their license compliance and security vulnerability risks.

    Cost / License

    • Pay once or Subscription
    • Proprietary

    Application type

    Platforms

    • Mac
    • Windows
    • Software as a Service (SaaS)
     
  6. Copy a direct link to this comment to your clipboard

    PrivJs Safe helps secure projects by blocking the installation of vulnerable javascript packages. PrivJs Safe also provides an ESLint plugin @privjs/eslint-plugin-safe to actively detect the import of vulnerable npm packages in the projects.

    Cost / License

    • Subscription
    • Proprietary

    Application type

    Platforms

    • Online
    • Software as a Service (SaaS)
     
  7. Codario.io icon
     2 likes
    Copy a direct link to this comment to your clipboard

    Dependency Update Automation for npm, composer and docker made easy. Check your git repositories for vulnerabilities now!.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Software as a Service (SaaS)
     
  8. Copy a direct link to this comment to your clipboard

    RankedRight is the triage tool that automatically ranks vulnerabilities based on the rules set by its user, factoring in what is critical to the business, and delegating it to the most appropriate person to resolve.

    Cost / License

    • Pay once
    • Proprietary

    Application type

    Platforms

    • Online
     
  9. SecDash icon
     Like
    Copy a direct link to this comment to your clipboard

    SecDash automatically detects security vulnerabilities in applications created with ChatGPT, Claude, and other AI tools, providing clear and actionable guidance.

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Application type

    Platforms

    • Online
     
  10. Vigiles icon
     1 like
    Copy a direct link to this comment to your clipboard

    Timesys Vigiles is a Software Composition Analysis (SCA) tool that helps generate and analyze a Software Bill of Materials (SBOM) for publicly known cybersecurity vulnerabilities, particularly CVEs. Vigiles is optimized for embedded systems, and it provides a complete...

    Cost / License

    • Freemium (Subscription)
    • Proprietary

    Platforms

    • Online
    • Software as a Service (SaaS)
     
  11. Copy a direct link to this comment to your clipboard

    GuardRails continuously scans your GitHub & GitLab repositories to alert you of any vulnerabilities and security issues. Get started in minutes.

    Cost / License

    • Subscription
    • Proprietary

    Application type

    Platforms

    • Online
    • Self-Hosted
    • Software as a Service (SaaS)
     
You are at page 2 of NPMScan alternatives