Alternatives
Products that do what PackSage does
Project dependency analysis
- 1

- 2

- 3

- 4

Scan dependency for suspicious, and vulnerable packages.
Apr 2026 · hookcheckv2.vercel.app
- 5

- 6SW
2016 · npmdiscover.com
- 7

- 8PD
2021 · pickbetterpack.com
- 9

- 10IB
Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)
2023 · github.com
- 11

Scan and auto-fix GitHub vulnerabilities in seconds
Apr 2026 · package-helper.up.railway.app
- 12
React Native & Expo Dependency Insights
May 2026 · package-intelligence.vercel.app
- 13SD
As software engineers we are often confronted with the decision of whether to code something ourselves or to add an existing library that does it for us. Whether we like it or not – we are adding dependencies sooner or later. And it's arguably good practice to check a new dependency beforehand: Is it maintained? By whom? How many issues does it have and how many of those are bugs? Are they being fixed? What's on the roadmap? What's the release frequency and how often do APIs break? One of our favorite solutions that already exist to answer such questions is the OpenSSF Scorecard project…
2025 · shouldiuse.dev
- 14

- 15

- 16PP
2020 · packagr.app
- 17OS
Hi HN, I made OSS Sustain Guard. After every high-profile OSS incident, I wonder about the packages I rely on right now. I can skim issues/PRs and activity on GitHub, but that doesn’t scale when you have tens or hundreds of dependencies. I built this to surface sustainability signals (maintainer redundancy, activity trends, funding links, etc.) and create awareness. It’s meant to start a respectful conversation, not to judge projects. These are signals, not truth; everything is inferred from public data (internal mirrors/private work won’t show up). Quick start: pip install…
Jan 2026 · onukura.github.io
- 18
Block bad npm and pip packages. Before they download.
May 2026 · veln.sh
- 19

- 20DD
2020 · github.com
- 21CV
2023 · github.com
- 22

Paste your package.json, get a production-readiness score
Aug 2026 · jsondevtools.org
- 23

- 24

Turn any GitHub profile into a recruiter-ready story
Jul 2026 · devdossier.lovable.app
Ranked by how close each launch is in meaning, then by votes. Refine with a description →