OK to install
Dependency github.com/ugorji/go/codec has an unconfirmed info alert — Go package reads env vars + network egress + (eval / obfuscation / install) — credential-exfil.
Shoulder shows what a package can do, not just whether a CVE has been published. We inspect install behavior, runtime capabilities, provenance, and trust signals to show where a package may be risky in your environment.
Release History
Recent releases with risk verdicts. A sudden risk spike across versions may indicate account compromise.
Package Intelligence
Publishing patterns and maintainer signals across the package lifecycle.
Publisher Intelligence
Timeline Intelligence
Avg Release Cadence
every 7 days
Releases (30d)
1
Releases (7d)
0
Download Trend
Scan your own dependencies
Check every package in your project for install scripts, unusual capabilities, and supply chain risk.