DepWarden
Combines SCA and SAST to scan dependencies and source code for vulnerabilities, supply-chain risks, licenses and secrets
A software composition and static analysis workspace that scans dependencies and source code for vulnerabilities, supply-chain risks, license obligations and leaked secrets. It is for individual developers, open-source maintainers, security engineers and teams that need CI gates or SBOM/VEX compliance without connecting repositories. It is delivered as a free, anonymous, session-isolated web workspace where users paste manifests or upload lockfiles and source zips with no account or binary upload required.
Key features
- SCA dependency vulnerability scanning
- OSV, CISA KEV and EPSS enrichment
- CVSS and exploitability ranking
- SAST pattern and taint analysis
- 14-15 language static analysis
- 300+ security rules
- Typosquatting detection
- Dependency confusion detection
- Install-script abuse detection
- OpenSSF Scorecard health signals
- Deprecation and abandonment flags
- SPDX license categorization
- NOTICE attribution file generation
- CycloneDX 1.7 SBOM export
- Embedded VEX and OpenVEX export
- SBOM ingest (CycloneDX/SPDX)
- Secret scanning for leaked credentials
- Dependency graph visualization
- Transitive dependency tracing
- One-command fix generation
- Zero-day blast radius search
Social posts
- No social media activity detected
GTM channels
- Blog
ICP
- Software developers
- Security teams
- Engineering teams