Socket
AI supply chain security scanner for npm, PyPI, and Maven packages.
Free / $10/mo Free tier available
About
Socket detects malicious packages, typosquatting, and supply chain attacks in npm, PyPI, Go, and Maven before they reach production. Deep package inspection analyzes behavior, not just CVE databases.
Features
Malicious package detection
Supply chain attack prevention
Deep package behavior analysis
GitHub PR checks
npm, PyPI, Go, Maven support
Real-time threat intelligence
Specifications
| SAST | |
| SCA | |
| Secret Scanning | |
| AI Remediation | |
| Open Source | |
| Starting Price | Free / $10/mo |