Install with review
Go package reads env vars + network egress + (eval / obfuscation / install) — credential-exfil shape
Shoulder shows what a package can do, not just whether a CVE has been published. We inspect install behavior, runtime capabilities, provenance, and trust signals to show where a package may be risky in your environment.
Release History
Recent releases with risk verdicts. A sudden risk spike across versions may indicate account compromise.
Package Intelligence
Publishing patterns and maintainer signals across the package lifecycle.
Publisher Intelligence
Maintainer Stability
Changes (30d)
0
Changes (90d)
Unique Publishers (30d)
0
Timeline Intelligence
Avg Release Cadence
every Today
Releases (30d)
39
Releases (7d)
4
Download Trend
Scan your own dependencies
Check every package in your project for install scripts, unusual capabilities, and supply chain risk.