package reports

Is that package safe to install?

Known vulnerabilities, confirmed malicious packages, dependency risk and the AI models that carry them. npm, PyPI, Maven, Go, NuGet, RubyGems, Packagist and WordPress.

// recently confirmed malicious

fig. 01 — live from the detection pipeline

// ai models, what changed

fig. 02 — published models whose risk moved

// longest advisory record

fig. 03 — a count, not a verdict; usually a widely used package