Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.
Cost / License
- Free Personal
- Proprietary
Platforms
- Online



Snyk is described as 'Continuously find & fix vulnerabilities in your dependencies' and is a vulnerability scanner in the security & privacy category. There are more than 25 alternatives to Snyk, not only websites but also apps for a variety of platforms, including SaaS, Mac, Windows and Self-Hosted apps. The best Snyk alternative is GitHub, which is free. Other great sites and apps similar to Snyk are Patchdex, Artemis Security Scanner, Mend Renovate and Metaport.
Depfu continuously updates your dependencies one at a time and creates a pull request with all the info you need. You stay in control.



Vulners is a high-quality correlated database of software vulnerabilities. Users can create a custom VM solution using our consolidated database through API, multiple vulnerability scanners, plugins, and many other security tools and integrations.



Pipelock is an open-source agent firewall written in Go. It runs as a sidecar or local service between an agent and the network, scanning HTTP, WebSocket, and Model Context Protocol traffic through an 11-layer pipeline.


PrivJs Safe helps secure projects by blocking the installation of vulnerable javascript packages. PrivJs Safe also provides an ESLint plugin @privjs/eslint-plugin-safe to actively detect the import of vulnerable npm packages in the projects.


Mend.io offers the first AI native application security platform, purpose-built to secure AI-generated code and embedded AI components. Our unified platform enables companies to manage application risk effectively in modern software development.



Unlimited vulnerability scanning with flat-rate pricing. Built-in CISA KEV and EPSS threat intelligence, compliance reporting for PCI-DSS, Cyber Essentials, and ISO 27001. No per-IP fees.
Dependency Update Automation for npm, composer and docker made easy. Check your git repositories for vulnerabilities now!.



AquilaX Ultimate is a comprehensive software security scanner, designed to detect a wide range of security vulnerabilities in the source code of any application. Is committed to change how contextual analysis is done to eliminate virtually any false positive.

NPMScan is a security analysis tool for the JavaScript ecosystem. It scans npm packages for malicious behavior and supply chain risks that are often invisible to developers. The scanner inspects scripts, dependencies, encoded payloads, metadata, and common attack patterns used...




A single pane of glass for understanding and mitigating risks across your entire codebase and supply chain.

Dependency Track SaaS provided by YourSky.blue is the managed cloud solution of the popular open-source Dependency-Track. Always up to date with the latest security bulletins, it allows to easily monitor all the chain of software components through powerful dashboards and...

vet is a tool for protecting against open source software supply chain attacks. To adapt to organizational needs, it uses an opinionated policy expressed as Common Expressions Language and extensive package security metadata including:



I like PrivJs Safe because it blocks the installation of vulnerable npm packages. And the ESLint plugin to detect vulnerabilities is brilliant