Run SBOM-generating scripts via NPM, Bash, or PowerShell. Software is automatically sent to SecAlerts for vulnerability matching.


Run our lightweight scripts without installing agents or software on your endpoints.

Support for Windows (PowerShell), Linux/macOS (Bash), and Node.js environments.

Scanned software is automatically sent to SecAlerts and matched against vulnerabilities.

All scanner code is open and easy to read. Audit it before running.
Select from NPM script, curl | bash, or PowerShell based on your environment.
Copy and paste the command into your terminal. No installation required.
The scanner identifies installed packages, applications, and dependencies.
Your software inventory is automatically uploaded and matched against CVEs.
Detect all npm packages in your Node.js projects
Find installed packages on Linux, macOS, and Windows
Identify installed applications and their versions
Set up automated recurring scans
Add scanning to your build pipeline
Review and audit all scanner code
Run a one-time scan to quickly assess the security posture of a system or project.
Schedule regular scans to keep your software inventory up to date automatically.
Integrate scanning into your deployment pipeline to catch vulnerabilities before production.
Start your free 30-day trial today. No credit card required.