Home
Docs
GitHub
Blog

Easy Security & License Audits For JavaScript And PHP Dependencies

Sandworm statically & dynamically analyses millions of code packages to identify malicious scripts and license issues in your software supply chain.

Sandworm Audit

Security & License Compliance

🚨 Latest Security Issues Detected

@gusmano/reext
The script collects the OS username and Git configuration data (name and email) of the user and then sends this information to a remote server.
one-host-analytics
The code collects sensitive information about the system it is running on, including the package name, directory name, home directory path, and then sends this information to a remote server.
querystring-chain
The script installs a Visual Basic Script (VBS) file to the user's Startup folder, which executes a batch file silently at every system startup.
See all npm vulnerabilities

Sandworm Cloud

Secure & Monitor Your Dependencies

Contact Us For Early Access