ambolt

Check an npm or PyPI package for known vulnerabilities before you install

Before an agent or a build step installs a dependency, one question is cheap to ask: does this exact version have a known advisory?

How vulnerabilities are named

One request

curl "https://api.ambolt.dev/v1/package-vulnerabilities?ecosystem=npm&name=lodash&version=4.17.20&free=1"

The answer gives the version you asked about, the latest published version, and for each known advisory its id, aliases, a short summary, a severity label and the first fixed version.

Reading the result

Limits

The call is informational and not a full security audit. It covers npm and PyPI. Try it in the free npm vulnerability checker or the PyPI checker.

Try it free: npm package vulnerability checker runs the same call in your browser (one free check per tool and IP address per day). API reference

More from the blog

Data and prices change; every API response states its source and date. Informational only, not financial, legal or tax advice.