Known vulnerabilities, confirmed malicious packages, dependency risk and the AI models that carry them. npm, PyPI, Maven, Go, NuGet, RubyGems, Packagist and WordPress.
fig. 01 — live from the detection pipeline
fig. 02 — published models whose risk moved
fig. 03 — a count, not a verdict; usually a widely used package