Know which vulnerable dependency to fix first.
Drop a lockfile. Depmoor finds every known vulnerable package, then ranks them by what attackers actually use: CISA's exploited-in-the-wild list (KEV) and EPSS exploit odds, with the version that fixes each one. Your lockfile is read in your browser. Free: 5 scans a day.
- No sign-up
- npm · yarn · pnpm · pip · Poetry · uv · Cargo · Go · Composer · Bundler · Gradle · NuGet
- Pro from $9/month
Scan a lockfile
Or paste a lockfile
Results
Upgrade plan
One line per package: the version that clears every advisory found, and a same-major option when there is one.
| Package | Now | Upgrade to | Same-major option | Findings |
|---|
Findings
| Priority | Package | Advisory | Severity | EPSS | KEV | Fixed in |
|---|
How the ranking works
Advisories: OSV.dev (GitHub Advisory Database, PyPA, RustSec, Go and more; CC-BY 4.0). Exploited list: CISA KEV, refreshed hourly. Exploit odds: FIRST EPSS, refreshed daily. Duplicate advisories for one issue (GHSA, PYSEC, CVE) are merged.
CI API Pro
Fail a build only when something is worth fixing now. Pro includes 100 API scans a day, Team 2,000. Works in any CI (GitLab CI, GitHub Actions, Jenkins, Bitbucket, CircleCI).
curl -sf -X POST "https://depmoor.cybermax-tools.workers.dev/api/scan?format=sarif&fail_on=fix-now&filename=package-lock.json" \
-H "Authorization: Bearer $DEPMOOR_KEY" --data-binary @package-lock.json -o depmoor.sarif
Formats: json (default: summary, upgrade plan, findings), sarif, csv, md. fail_on = fix-now, fix-soon or any → HTTP 422 when matched, so the step fails. Lockfiles up to 2 MB, or send {"packages":[{"ecosystem","name","version"}]}.
Pricing
Pro · yearly
$7.50 a month, 2 months free
- Unlimited scans
- CSV, SARIF, Markdown, JSON
- Saved projects: "new since last scan"
- CI API: 100 scans a day
Team
- Everything in Pro
- CI API: 2,000 scans a day
- One key for the whole team's pipelines
Secure card checkout by Stripe. Your key appears right after payment. 14-day refund policy. Compare (prices on each site, 1 Oct 2026): Vulert Pro $15 per monitored app per month, Socket Team $25 per developer per month (5 minimum), Debricked Premium $25 per developer per month.
FAQ
Is my lockfile uploaded?
No. It is read in your browser. Only package names and versions go to OSV.dev to look up advisories, and CVE IDs to FIRST's EPSS API. Your source code never leaves your machine. (The CI API reads the lockfile you send it, scans it and keeps nothing but a daily counter.)
How is the priority decided?
Fix now: the CVE is in CISA's Known Exploited Vulnerabilities catalog, or EPSS gives it at least a 10% chance of exploitation in the next 30 days. Fix soon: EPSS at least 1%, or rated critical/high. Plan: everything else. The rules are the same for every scan.
Why not npm audit, pip-audit or Dependabot?
They are free and good at listing advisories. Depmoor adds what they leave out: which findings are exploited in the wild (KEV), how likely the rest are to be exploited (EPSS), one upgrade per package with a same-major option, and one report across npm, Python, Java, Go, Rust, PHP, Ruby and .NET.
Why not Snyk or Socket?
They do much more (code scanning, malware detection, PR bots) and are priced per developer: Socket Team is $25 per developer per month with a 5-developer minimum. If what you need is "which dependency do I fix first", Depmoor is $9 a month for unlimited scans.
Does it see transitive dependencies?
Yes, everything pinned in the lockfile, direct and transitive. requirements.txt only lists what you pin with ==; use a full freeze or a lock (poetry.lock, uv.lock, Pipfile.lock) to see everything.
How do I cancel?
Open Manage subscription with your key: Stripe's billing portal lets you cancel or change your card.