Open Source · MIT License

GardWatch

Dependency Intelligence

Scores your dependencies on trust, security, and quality — catching supply chain threats that vulnerability scanners miss.

Get Started
$ |

Scanning 12 packages...

[98/100] requests - Well maintained, high trust
[42/100] colorlib - Low downloads, no repo link
[ 0/100] req-uests - TYPOSQUAT DETECTED
🛡️

Trust Scoring

Every package gets a 0–100 score based on age, downloads, security practices, and metadata quality.

🔍

Threat Detection

Catches typosquatting, namespace squatting, homoglyph attacks, and known malware before they hit production.

📦

Deep Code Scan

Optionally download and analyze source code for obfuscated payloads, suspicious network calls, and hidden scripts.

📋

SBOM Support

Parse CycloneDX SBOMs, requirements.txt, package.json, go.mod, Cargo.toml, pom.xml, and more.

📊

OpenSSF Scorecard

Integrates security best practice data from the OpenSSF Scorecard project for deeper risk assessment.

Quick Scan

Check any single package before you install it. One command, instant trust report.

Built for Your Workflow

GardWatch meets you where you code — in your editor and alongside your AI assistant.

    "version": "==1.31.5"
  },
  "setuptools" GardWatch 95/100 SAFE: {
    "version": "==82.0.1"
  },
  "unittest2" GardWatch 35/100 CRITICAL: {
    "version": "==1.1.0"
  },
  "watchfiles" GardWatch 85/100 SAFE: {

VS Code Extension

Inline scores right next to each dependency in your lockfile. Critical packages are highlighted so you can spot risks at a glance.

add unit tests to manage.py
Let me check unittest2 before adding it...
gardwatch_check_package
  └ CRITICAL (20/100) Abandoned 10 yrs
Using pytest instead.

MCP Server

AI assistants auto-check packages before installing and scan lockfiles after every dependency change. Zero manual effort.

Claude Code
Cursor
Windsurf
Cline
MCP

Works With Your Tools

One-click setup for all major AI coding assistants. Standard MCP protocol — no plugins or agents to configure.

Multi-Ecosystem Support

Analyze packages across all major ecosystems.

PyPI (Python) npm (JavaScript) Go Modules Cargo (Rust) Maven (Java) NuGet (.NET)