BETA Shoulder is in beta — Findings may sometimes be wrong. Your feedback shapes what we fix next. Share feedback
Ecosystem Intelligence

Is this vulnerability real, exploited, or noise?

Paste a package, CVE, or security concern. We prove it, explain it, and show the fix.

Try searching for

Accepts: package names, package@version, CVE IDs, CWE IDs, npm/PyPI/crates.io URLs, or prefix syntax (pypi:requests)

Live Security Alerts

View all →

Notable Vulnerabilities

Updated 37m ago

Weaknesses You Should Know About

View all →

Package Security Status

Scan from your terminal

Run Shoulder locally to analyze packages before installing them, or scan your entire project for vulnerabilities.

npx @shoulderdev/cli check <package>
npx @shoulderdev/cli trust .