nowfound

Alternatives

Products that do what ThreatScoped does

Know if software is actually safe — before you install it

  1. 1
    Koidex387

    Know if a package, extension, or AI model is actually safe

    Feb 2026 · dex.koi.security

  2. 2
    Scopey378

    Quote work in minutes, capture change requests instantly

    2024

  3. 3

    Stop bots, fraud, and abuse with industry-leading accuracy

    2024

  4. 4TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev

  5. 5

    Scan any website for security vulnerabilities

    Jul 2026 · threatscope.arytech.in

  6. 6SI

    Hey HN, TL;DR: We’ve launched a free version of our Shadow IT scanner to identify which SaaS apps are used in your company, who uses them, and if they have high-risk OAuth scopes. Philip and I went through YC with AccessOwl in 2022. We started the company because, in our previous roles, we struggled to track all the SaaS apps, users, and granted OAuth scopes. The Shadow IT scanner started as a small feature within AccessOwl, which manages SaaS vendors and user accounts centrally. But a standalone scanner would have made our lives so much easier in our previous roles. So, we thought, why not…

    2024 · accessowl.io

  7. 7NI

    Our package registry ecosystem has a serious problem... and not just npm. People are aware of this but maybe this will make them a bit more aware

    2022 · github.com

  8. 8TT

    Hi everyone, given the recent increase of attacks on the NPM supply chain, I've put together a list of tips and tricks to help developers stay secure on this specific topic: https://github.com/bodadotsh/npm-security-best-practices I'd love for you to check it out, and contribute your own insights and best practices to make this a comprehensive resource for the community. Cheers!

    Sep 2025 · github.com

  9. 9VD

    Did you know that VSCode extensions run with full access to your system—including file system, network, and credentials? Worse, dozens of malicious extensions have already made it into the marketplace, silently compromising devices. I am a security researcher and student developer who ran into this problem myself. To help tackle this, I built a 100% free tool (no login required) that scans VSCode (and Cursor/Windsurf) extensions for: - Hidden malware and obfuscated code - Dangerous permissions and API misuse - Vulnerable dependencies and suspicious network connections Users have already…

    2025 · vscan.dev

  10. 10IB

    2025 · scamchecknow.com

  11. 11IB

    I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD. I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink. Feedback is appreciated. The app, PRevent - https://github.com/apiiro/PRevent The ruleset: https://github.com/apiiro/malicious-code-ruleset The research:…

    2025 · github.com

  12. 12

    Python security scanner that eliminates false positives

    Feb 2026 · vulscan.nexorium.io

  13. 13VN

    If you are worried about the recent Lazarus group software supply chain attack, you should consider having guard rails that is more than conventional SCA. `vet` detects the package (version) published in the report as malware. Try out vet, its free and open source: https://github.com/safedep/vet More details on the attack: https://www.nodejs-security.com/blog/north-korea-malware-on-...

    2023 · github.com

  14. 14

    Find GDPR risks on your live site before regulators do

    Feb 2026 · securespells.com

  15. 15

    Find your web app's vulnerabilities before attackers do

    Jul 2026 · sensagraph.com

  16. 16

    Instantly check if a website is safe and trustworthy [free].

    Oct 2025

  17. 17SI

    In light of the ongoing npm supply chain compromises, I built safe-install: https://www.npmjs.com/package/@gkiely/safe-install It brings a couple of protections I wanted from npm but are not built in. Similar to Bun’s trusted dependencies, it lets you disable install scripts by default and define a list of dependencies that are allowed to run build/install scripts: https://bun.com/docs/guides/install/trusted It also supports blocking exotic sub-dependencies, similar to pnpm’s `blockExoticSubdeps` setting:…

    May 2026 · npmjs.com

  18. 18

    Proves vulnerabilities before reporting them.

    9d ago · dashboard-seven-self-13.vercel.app

  19. 19

    Block bad npm and pip packages. Before they download.

    May 2026 · veln.sh

  20. 20
    VScanX11

    Deterministic security scanner with zero false positives

    May 2026 · vscanx.vercel.app

  21. 21

    Think you're too small to be hacked?

    Nov 2025

  22. 22

    Know your Attack Surface before attackers do.

    May 2026 · threatport.com

  23. 23IB

    Linux Foundation survey says 70-90% of modern software constitute OSS code. Yet we are stuck with tools that scan only for vulnerabilities in 3rd party libraries and that too with high degree of false positives. I built `vet` for policy and data driven analysis of 3rd party packages that goes beyond only vulnerability and allows codifying organisational policies related to OSS consumption. https://github.com/safedep/vet Looking forward to feedback and suggestions from HN :)

    2023 · github.com

  24. 24

    Automated github dependency security scanner

    Nov 2025

Ranked by how close each launch is in meaning, then by votes. Refine with a description →