Free tools / npm package vulnerability checker
Free npm package vulnerability checker
Check an npm package version against a public vulnerability database: advisory ids, CVE and GHSA aliases, severity, the first fixed version and the latest release.
The result appears here as JSON.
One free check per tool and IP address per day. Nothing is stored.
What you get
- Advisory ids with CVE and GHSA aliases and a summary
- Severity label and the first fixed version
- The latest published version
Not returned: A full security audit or findings that have no published advisory.
Use it from code or an agent
curl "https://api.ambolt.dev/v1/package-vulnerabilities?ecosystem=npm&name=lodash&version=4.17.20&free=1"Same tool as an MCP tool (package_vulnerabilities, free at 30 requests a minute), as a pay-per-call endpoint ($0.003 a call in USDC) and as an Apify Actor. Reference · Docs
Questions
Is this a security audit?
No. It lists known advisories for the version you ask about.
Which versions are checked?
The exact version you enter; leave it empty to see advisories and the latest release.
What about PyPI?
Use the PyPI vulnerability checker.