AI code generators confidently invent packages that don't exist, suggest deprecated libraries, and miss critical CVEs. DepAudit scans every dependency before it reaches your codebase.
DepAudit runs a comprehensive set of checks so you don't have to manually verify every package an AI assistant suggests.
AI models confidently suggest packages that simply do not exist. DepAudit cross-checks every dependency against the live npm and PyPI registries and flags anything that returns a 404.
Real-time CVE detection powered by the OSV (Open Source Vulnerabilities) database. Catch critical, high, medium, and low severity issues before you ship.
Deprecated packages are security liabilities with no upstream fixes. We surface the official deprecation message and suggest maintained alternatives.
Every scan produces a 0–100 dependency health score weighted by hallucinations, vulnerabilities, deprecation, and download counts so you know exactly where to focus.
No setup, no CLI to install. Just paste and scan.
Drop in your package.json, requirements.txt, or raw AI-generated code. DepAudit auto-detects the format.
We query npm, PyPI, and the OSV database in parallel. Results for 50+ packages arrive in under 10 seconds.
See a full breakdown per package — health score, issues, latest versions, and one-click fix suggestions.
Start free. Upgrade when you need more scans or team features.
Perfect for occasional checks and side projects.
For developers who ship AI-assisted code regularly.
For engineering teams shipping AI-generated features.
We handle dependency maintenance so you focus on shipping.
“ChatGPT hallucinated three npm packages in a row and I nearly deployed them to production. DepAudit caught all three in seconds. Now I run every AI-generated package.json through it before I even run npm install.”
“The health score alone is worth it. I can see at a glance if an AI-generated requirements.txt is a liability. We've made it mandatory in our PR review checklist.”
“Found a package with 47 weekly downloads in a Cursor-generated project. Classic typosquatting target. DepAudit flagged it immediately. This tool is a must for any team using AI coding assistants.”
Free forever for 2 scans a month. No account required to get started.