DepSec
Decommissioned dependency analyzer that scored package.json security from 0 to 100

Dependency security analyzer for Node.js projects. Upload a package.json (and optionally package-lock.json) and get a weighted security score from 0 to 100 across six dimensions: known vulnerabilities via OSV, dependency hygiene, license risk, maintainer health, download popularity, and typosquatting detection.
When a lockfile is provided, the full transitive dependency tree is scanned with depth-weighted scoring, so direct dependencies hit harder than deeply nested ones. Includes remediation hints showing which version patches each CVE and which direct dependency to upgrade for transitive issues.
Shipped with a CLI mode for CI/CD pipelines, a GitHub Action, and CycloneDX SBOM export. The web UI featured a force-directed dependency graph visualization and a retro-cyberpunk CRT aesthetic.
The hosted service was decommissioned on 1 September 2026. The source repository and this project record remain available for reference.