StartupIndex
Socket logo

Socket

Catch the malicious dependency before it ships

Includes 19 simulated benchmark votes2 comments

About Socket

Socket inspects what a package actually does, flagging install scripts, network calls and obfuscated code rather than only checking a list of known vulnerabilities. It reviews dependency changes on every pull request.

Comments (2)

Simulated benchmark comments are labeled below and are not endorsements from real users.

  • RhysSimulated5mo ago

    It looks at what a package actually does instead of only checking a vulnerability list. Caught an install script we would have missed.

  • Karim W.Simulated1d ago

    The pr review bot is the useful bit. Flags a risky dependency change before it merges. The calendar did not object.

Sign in to leave a comment.

  1. Bitwarden logo

    Password management, open to inspection

  2. Semgrep logo

    Static analysis that reads like the code it checks

  3. Infisical logo

    Open source secrets management

  4. Doppler logo

    Stop passing secrets around in Slack

  5. Tailscale logo

    A private network that just works