Alternatives
Products that do what Hook Check does
Scan dependency for suspicious, and vulnerable packages.
- 1

- 2SS
Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…
2022 · socket.dev
- 3

- 4PD
2021 · pickbetterpack.com
- 5

- 6

- 7

- 8GC
2016 · github.com
- 9

- 10
- 11NI
Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware
2022 · github.com
- 12

- 13
Block bad npm and pip packages. Before they download.
May 2026 · veln.sh
- 14

Paste your package.json, get a production-readiness score
Aug 2026 · jsondevtools.org
- 15BT
Apr 2026 · github.com
- 16RU
Hi HN! This is my first open source package. PyCharm used to have a nifty tool to show you requirements.txt packages that needed updates. You could click a button and open the github page, click a button to upgrade, all in the file. It was super convenient. Then it went away. The package was written in a few languages that I have no experience with, but I figured I'd build something that worked for my use case, and maybe it can help you, too. After installing, you point it at your requirements.txt file, and it will spit out something like this: ---- File caching enabled The following…
2025 · github.com
- 17BM
2013 · bundlescout.com
- 18SD
As software engineers we are often confronted with the decision of whether to code something ourselves or to add an existing library that does it for us. Whether we like it or not – we are adding dependencies sooner or later. And it's arguably good practice to check a new dependency beforehand: Is it maintained? By whom? How many issues does it have and how many of those are bugs? Are they being fixed? What's on the roadmap? What's the release frequency and how often do APIs break? One of our favorite solutions that already exist to answer such questions is the OpenSSF Scorecard project…
2025 · shouldiuse.dev
- 19

A tool to help developers stay safe with npm dependencies.
Feb 2026 · package-sentinel.vercel.app
- 20

- 21NF
2014 · vuln.pub
- 22

Find deprecated npm packages before they haunt your prod app
May 2026 · stackgraveyard.dev
- 23

- 24PJ
2015 · package.json.is
Ranked by how close each launch is in meaning, then by votes. Refine with a description →