Which of your dependencies are end-of-life, deprecated or vulnerable? Get a ranked fix list.
Send one repo's manifest. We check every package and runtime against public advisory and end-of-life data, and a person sends you what to upgrade first, to which version, and why.
- One report
- 99 USD per repo
- Weekly report
- 49 USD per month
- Delivery
- within 48 hours of the deposit
- Payment
- escrow on Upwork or Deel
Opens the quote form with this offer filled in. We confirm the fixed price within 1 business day, and the platform holds the payment until you approve the result.
What you get
- Every runtime and framework in the repo checked for its end-of-life date, such as Node.js, Python, Django or Rails, from endoflife.date.
- Every dependency at the exact version you use checked for known vulnerabilities in OSV.dev, with the severity, whether CISA lists it as exploited, and its EPSS score.
- Deprecated and stale packages flagged: the npm or PyPI deprecation notice and the last release date.
- One ranked fix list: what to fix first and what can wait, with the exact version to upgrade to on each line and the reason, read and checked by a person.
- Weekly plan: the same check every week, with what changed since the last report on top.
How it works
- Send the quote form and say one-off or weekly. It takes a minute.
- We confirm the fixed price by email within 1 business day. You fund it on Upwork or Deel, whichever you prefer.
- You reply with the lock file. The report arrives within 48 hours: a short document with the fix list as a table.
- After you upgrade, send the new lock file within 14 days and we check it again at no cost.
What we need
One lock file or manifest: package-lock.json or package.json, requirements.txt, go.mod, Cargo.lock, Gemfile.lock, composer.lock, pom.xml or packages.lock.json. A repo with several lock files counts as one repo per lock file. We read only package names and versions. We never ask for source code, tokens or access to your repo.
Good to know
The report says what the public advisory data says about the versions you use. It cannot show whether your code reaches the vulnerable part. Not included: making the upgrades, fixing tests that break after an upgrade, or a code audit.
Want to look first? Ask your AI agent to run the free CVE Risk Check on your lock file.
Questions before you order: email support@openkrill.app.