Scan your project dependencies for known vulnerabilities using 5 free security APIs. Zero cost, zero setup.
Combines multiple free security databases to give you a comprehensive security check:
- OSV.dev — Google's vulnerability database (40+ ecosystems)
- Have I Been Pwned — Check credentials against 13B+ breached records
- URLhaus — Detect malware distribution URLs
- Shodan InternetDB — Quick IP/port reconnaissance
- VirusTotal — Scan files and URLs (free tier)
pip install requests
python scanner.py --check-deps requirements.txtimport requests
def scan_dependencies(requirements_file):
"""Scan Python dependencies for known vulnerabilities"""
vulns_found = 0
with open(requirements_file) as f:
for line in f:
line = line.strip()
if not line or line.startswith('#'):
continue
parts = line.split('==')
if len(parts) != 2:
continue
package, version = parts
resp = requests.post('https://api.osv.dev/v1/query', json={
'package': {'name': package, 'ecosystem': 'PyPI'},
'version': version
})
vulns = resp.json().get('vulns', [])
if vulns:
vulns_found += len(vulns)
print(f"⚠️ {package}=={version}: {len(vulns)} vulnerabilities")
for v in vulns[:3]:
print(f" [{v['id']}] {v.get('summary', '')[:80]}")
else:
print(f"✅ {package}=={version}: clean")
return vulns_found
# Usage
total = scan_dependencies('requirements.txt')
print(f"\nTotal vulnerabilities found: {total}")def check_urls(urls):
"""Check if URLs are in malware databases"""
for url in urls:
resp = requests.post(
'https://urlhaus-api.abuse.ch/v1/url/',
data={'url': url}
)
status = resp.json().get('query_status')
if status == 'no_results':
print(f"✅ {url}")
else:
print(f"⚠️ {url} — FLAGGED as malicious!")def scan_ip(ip):
"""Quick port/vuln scan using Shodan InternetDB"""
resp = requests.get(f'https://internetdb.shodan.io/{ip}')
data = resp.json()
print(f"IP: {ip}")
print(f" Open ports: {data.get('ports', [])}")
print(f" Known vulns: {data.get('vulns', [])}")
print(f" Services: {', '.join(data.get('tags', []))}")| API | Cost | Rate Limit | No Key? |
|---|---|---|---|
| OSV.dev | Free | Generous | ✅ |
| Have I Been Pwned | Free | 1/1.5s | ✅ (passwords) |
| URLhaus | Free | Unlimited | ✅ |
| Shodan InternetDB | Free | Generous | ✅ |
| VirusTotal | Free tier | 4/min | ❌ (free key) |
- CI/CD pipeline: Add dependency scanning to your build
- Security audit: Quick assessment of a new project
- Monitoring: Regular checks for new vulnerabilities
- Incident response: Fast triage of suspicious URLs/IPs
- awesome-free-research-apis — 30+ free API toolkits
- Apify scrapers — 88+ web scraping tools
- GitHub Projects — 440+ tutorials
Built by Alex Spinov — I build production-grade web scrapers and data tools.
- 88+ ready-made scrapers on Apify — Reddit, YouTube, HN, Trustpilot, and more
- Custom scraper or API integration in 24-48h
- Email: spinov001@gmail.com
MIT
Built by Aleksej Spinov — making security tools accessible to everyone.