Your dependencies deserve a health check

Scan. Score. Decide. One platform to audit every package you use.

deptools.io/dashboard/deptools-io/Demo
DepTools Dashboard Preview
Connect with
GitHub
Languages
Java
Kotlin
Build systems
Gradle
Maven
Package registries
Maven Central
Android
On the roadmap
npm
PyPI
The Hidden Risk

Your biggest blind spot

~90% is deps
of your attack surface is code you don't control
84% ship vulnerable
of teams ship known vulnerabilities to production
91% outdated
of codebases carry critical update debt
67 days to patch
average exposure window after a CVE is published
53% license risk
of codebases carry undetected license violations
42% time wasted
of engineering time is spent on dependency maintenance, not features
The Solution

Complete dependency control — from risk to remediation

  • Map your entire dependency surface — direct and transitive
    DepTools generates a full, interactive dependency graph — direct and transitive. Instantly spot high-risk nodes and hidden exposure across your entire stack.
  • Detect and remediate vulnerabilities — at scale
    Every dependency is checked against the latest security advisories. You get the severity, the scope across transitives, and clear remediation guidance — not just a list.
  • Eliminate update drift before it becomes a crisis
    Track how outdated your dependencies are, detect version conflicts, and understand the real maintenance burden — so your team focuses on features, not drift.
  • Automated license compliance — before legal flags it
    Every license is categorized and checked for compatibility. Copyleft and commercial risks are flagged automatically — and your SBOM is one click away.

Full-stack dependency intelligence

Eight specialized analyzers. One unified dashboard.

Security

  • Surface CVEs across direct and transitive dependencies instantly
  • Get actionable remediation paths — not just alerts
  • Quantify your full attack surface, including hidden transitive risk
  • Stay ahead of new advisories with continuous monitoring
CRITICALCVE-2021-44228
HIGHCVE-2021-44832
MODERATECVE-2021-45105
Patch Available
v1.5.8v2.2.6· latest: v4.0.4
2 / 2 CVEs fixed

Pricing

Start free. Scale as you grow. No hidden fees.

14-day free trial on all paid plans
Free

Get started with dependency analysis on public repositories.

$0
forever free
Get Started Free
  • All features
  • Up to 10 public projects
  • 3-hour scan cooldown per project
Most Popular
Open Source Max

Unlimited dependency analysis for open-source maintainers and organizations.

$19/mo
billed monthly
Start Free 14-Day Trial
  • Unlimited public projects
  • Unlimited scans
  • Community support
Pro

Advanced dependency analysis for private repositories, teams, and companies.

$39/mo
billed monthly
Start Free 14-Day Trial
  • 3 private repositories included, +$5/mo per extra
  • Unlimited public projects
  • Unlimited scans
  • Priority commercial support

Prices shown exclude applicable taxes.

Frequently asked questions

Get clarity before you commit.

DepTools connects to your GitHub repositories and scans your manifest files (pom.xml, build.gradle, etc.) to build a complete dependency graph enriched with security metrics, version data, and ecosystem intelligence. Connect your account, click Scan, and get actionable results in minutes.

No. DepTools only reads your dependency manifest files (e.g. pom.xml, build.gradle) via the GitHub API. Your actual source code is never transmitted or stored on our servers. All analysis is performed on metadata and publicly available package information.

CVE data is refreshed continuously from the National Vulnerability Database (NVD) and multiple security advisory feeds. Ecosystem signals — such as new releases, dependent counts or GitHub stars — are refreshed weekly.

DepTools currently supports Maven Central and Google's Maven Repository, covering Java, Kotlin, and Android projects. Analysis requires manifest files (pom.xml, build.gradle, etc.). Support for npm (Node.js / JavaScript / TypeScript) and PyPI (Python) is on the roadmap — check the Integrations section for the latest status.

Yes. Reach us at support@deptools.io. Response time is prioritized based on your plan — Pro users receive faster, dedicated support.

Each repository you scan becomes a project in DepTools. For multi-module repositories, you can create one project per module. Free plan: up to 10 public projects, with one scan per project every 3 hours. Open-Source Max: no limits on public projects or scan frequency. Pro: adds support for private repositories.

Stop guessing, start scoring

Audit your stack free
Connected in minutes Full-featured trial No credit card required