Privacy
This website sets no cookies, runs no analytics and loads nothing from third parties except the two vulnerability APIs below, and only when you run the scanner. Fonts, images and scripts are served from this site.
The in-browser scanner
- The lockfile you drop is read and parsed in your browser. It is never uploaded.
- Package names and versions (as package URLs, for example
pkg:npm/lodash@4.17.20) are sent to OSV.dev, run by Google, to find advisories for those exact versions. - CVE ids from those advisories are sent to FIRST's EPSS API to get exploitation probabilities.
- Those services receive your IP address and browser details like any web request, under their own privacy policies.
The KEV mirror
The page reads /kev.json from this site. That is a copy of the CVE ids in CISA's Known Exploited Vulnerabilities catalog, plus the public catalog fields (CVE id, vendor, product, date added and whether ransomware use is known) of the newest entries shown on the live board. It is fetched by our server (a Cloudflare Worker) and cached for up to six hours, because cisa.gov does not allow browsers to fetch it directly. Nothing about your visit or your scan is sent to it.
The station clock
The clock on the home page shows your device's local time, read in your browser. It is not sent anywhere.
Hosting
The site is served by Cloudflare, which processes standard request data (such as IP addresses) to deliver and protect it. The site's own code adds no logging or tracking.
The GitHub Action
The Action runs in your own CI. It sends package URLs to OSV.dev, CVE ids to FIRST EPSS, and downloads the CISA KEV catalog. Your source code and lockfile contents are not sent anywhere, and nothing is sent to us.