Known vulnerabilities for one package version from OSV.dev, with CISA exploited-
Known vulnerabilities for one package version from OSV.dev, with CISA exploited-in-the-wild flag and the fixed version. Should I install this? Pass ?package=lodash&ecosystem=npm&version=4.17.15 (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex, Pub) and get every known advisory for that exact version from OSV.dev (GitHub, PyPA, Go and RustSec databases), whether any of them is on CISA's Known Exploited Vulnerabilities list, severity, and the version that fixes each.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
GET https://apexfaucet.xyz/api/x402/software-risk
| Category | Everything else |
|---|---|
| Provider host | apexfaucet.xyz |
| Networks | eip155:5042, eip155:8453, solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
| Day | Result | HTTP | Asked | Time |
|---|---|---|---|---|
| 2026-09-30 | valid payment request | 402 | $0.003 | 372 ms |
Example input (from the provider)
{
"discoverable": true,
"method": "GET",
"queryParams": {
"ecosystem": "npm",
"package": "lodash",
"version": "4.17.15"
},
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"properties": {
"method": {
"enum": [
"GET"
],
"type": "string"
},
"queryParams": {
"properties": {
"ecosystem": {
"description": "Package ecosystem.",
"enum": [
"npm",
"PyPI",
"Go",
"crates.io",
"Maven",
"NuGet",
"RubyGems",
"Packagist",
"Hex",
"Pub"
],
"type": "string"
},
"package": {
"description": "Package name exactly as the registry has it (Maven: group:artifact).",
"maxLength": 214,
"minLength": 1,
"type": "string"
},
"version": {
"description": "The exact version to check.",
"maxLength": 64,
"minLength": 1,
"type": "string"
}
},
"required": [
"package",
"ecosystem",
"version"
],
"type": "object"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"queryParams"
],
"type": "object"
},
"output": {
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}