Skip to content

About

Scan dependencies, URLs and IPs for vulnerabilities using 5 free security APIs. No cost, zero setup. Python.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

API Security Scanner 🔒

Scan your project dependencies for known vulnerabilities using 5 free security APIs. Zero cost, zero setup.

What It Does

Combines multiple free security databases to give you a comprehensive security check:

  1. OSV.dev — Google's vulnerability database (40+ ecosystems)
  2. Have I Been Pwned — Check credentials against 13B+ breached records
  3. URLhaus — Detect malware distribution URLs
  4. Shodan InternetDB — Quick IP/port reconnaissance
  5. VirusTotal — Scan files and URLs (free tier)

Quick Start

pip install requests
python scanner.py --check-deps requirements.txt

Features

Dependency Scanner

import requests

def scan_dependencies(requirements_file):
    """Scan Python dependencies for known vulnerabilities"""
    vulns_found = 0
    
    with open(requirements_file) as f:
        for line in f:
            line = line.strip()
            if not line or line.startswith('#'):
                continue
            
            parts = line.split('==')
            if len(parts) != 2:
                continue
            
            package, version = parts
            resp = requests.post('https://api.osv.dev/v1/query', json={
                'package': {'name': package, 'ecosystem': 'PyPI'},
                'version': version
            })
            
            vulns = resp.json().get('vulns', [])
            if vulns:
                vulns_found += len(vulns)
                print(f"⚠️  {package}=={version}: {len(vulns)} vulnerabilities")
                for v in vulns[:3]:
                    print(f"    [{v['id']}] {v.get('summary', '')[:80]}")
            else:
                print(f"✅ {package}=={version}: clean")
    
    return vulns_found

# Usage
total = scan_dependencies('requirements.txt')
print(f"\nTotal vulnerabilities found: {total}")

URL Safety Check

def check_urls(urls):
    """Check if URLs are in malware databases"""
    for url in urls:
        resp = requests.post(
            'https://urlhaus-api.abuse.ch/v1/url/',
            data={'url': url}
        )
        status = resp.json().get('query_status')
        if status == 'no_results':
            print(f"✅ {url}")
        else:
            print(f"⚠️  {url} — FLAGGED as malicious!")

IP Reconnaissance

def scan_ip(ip):
    """Quick port/vuln scan using Shodan InternetDB"""
    resp = requests.get(f'https://internetdb.shodan.io/{ip}')
    data = resp.json()
    print(f"IP: {ip}")
    print(f"  Open ports: {data.get('ports', [])}")
    print(f"  Known vulns: {data.get('vulns', [])}")
    print(f"  Services: {', '.join(data.get('tags', []))}")

Why Free APIs?

API Cost Rate Limit No Key?
OSV.dev Free Generous ✅
Have I Been Pwned Free 1/1.5s ✅ (passwords)
URLhaus Free Unlimited ✅
Shodan InternetDB Free Generous ✅
VirusTotal Free tier 4/min ❌ (free key)

Use Cases

  • CI/CD pipeline: Add dependency scanning to your build
  • Security audit: Quick assessment of a new project
  • Monitoring: Regular checks for new vulnerabilities
  • Incident response: Fast triage of suspicious URLs/IPs

Related Projects


Author

Built by Alex Spinov — I build production-grade web scrapers and data tools.

License

MIT


Built by Aleksej Spinov — making security tools accessible to everyone.

About

Scan dependencies, URLs and IPs for vulnerabilities using 5 free security APIs. No cost, zero setup. Python.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages