Audit a whole dependency manifest in one call before installing or upgrading. Send a package.json, a requirements.txt, or npm and PyPI package lists (up to 50 packages). Per dependency: latest version and publish date, whether your pin is behind, license, deprecation or yanked status, weekly npm downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM. Use before adding or bumping deps or when reviewing a lockfile change.
Audit a whole dependency manifest in one call before installing or upgrading. Send a package.json, a requirements.txt, or npm and PyPI package lists (up to 50 packages). Per dependency: latest version and publish date, whether your pin is behind, license, deprecation or yanked status, weekly npm downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM. Use before adding or bumping deps or when reviewing a lockfile change.
Top-selling x402 bazaar services by unique paying buyers in the last 30 days. Send {"limit":25}, optionally with {"query":"weather"} or {"max_price_usd":0.01}. Per listing: resource URL, host, price, networks, 30-day calls and unique payers, last call time, and description, plus a host leaderboard. Skips listings whose only payment is their own indexing call. From Coinbase discovery metrics, refreshed every 6 hours.
Check an x402 niche before you build or buy. Send {"query":"pdf to markdown"}. Returns matching bazaar listings and hosts, how many have outside paying buyers in the last 30 days, max and median unique payers, price quartiles overall and among listings with demand, top listings and hosts by payers, and a verdict: empty, no-demand, thin-supply, contested, or incumbent-dominated. From Coinbase discovery metrics, refreshed every 6 hours.
Check npm packages before you install or upgrade. Send {"packages":["lodash@4.17.20","express"]} or a package.json (dependencies and devDependencies), up to 50 packages. Per package: latest version and publish date, whether a pinned version is behind, license, deprecation notice, weekly downloads, and known vulnerabilities from OSV with severity and first fixed version. Deterministic registry data, no LLM.
0.005 USD Coin / request · eip155:8453
POSTx402 · listed
https://audit.152-53-82-29.sslip.io/v1/pypi
Check Python packages from PyPI before you pip install or bump versions. Send {"packages":["requests==2.25.0","flask>=2.0"]} or {"requirements":"<requirements.txt text>"}, up to 50 packages. Per package: latest release and date, whether a pinned version is behind, license, yanked status, requires_python, and known vulnerabilities from OSV with severity and first fixed version. Deterministic, no LLM.
0.005 USD Coin / request · eip155:8453
POSTx402 · listed
https://audit.152-53-82-29.sslip.io/v1/vulns
Known vulnerabilities for a list of dependencies, npm and PyPI, in one call. Send {"npm":["lodash@4.17.20"],"pypi":["django==3.2.0"]} or a package.json or requirements.txt, up to 50 packages. Returns only packages that have advisories: OSV and GHSA ids, CVE aliases, severity, summary, and the first fixed version, plus counts. Unpinned packages are checked at their latest version. Deterministic OSV data, no LLM.