VULNINTEL · LIBRARY SCANNER

Know every open-source library running in production.

Library Scanner fingerprints the OSS packages behind your public services, matches them against CVE and GHSA feeds, and surfaces exposed dependencies — without ever seeing your source code.

AGENTLESSSOURCE-FREESBOM-READY
RELATED CAPABILITIES

You can't patch what you can't see

Modern services depend on hundreds of transitive open-source libraries. Most teams don't know which versions ship to production. Library Scanner rebuilds the SBOM from the outside — fingerprinting frameworks, JS bundles, server signatures, and error responses — then matches every package against public vulnerability feeds.

SCA PROCESS

How External Software Composition Analysis Works

01

FINGERPRINT

Detect frameworks (React, Vue, Next.js, Rails, Spring), server versions, JS bundle contents, and error fingerprints.

02

MATCH

Every detected package is cross-checked against NVD, GHSA, and ecosystem advisories hourly.

03

ALERT

Vulnerable dependencies surface with fix versions and CVE evidence.

CAPABILITIES

Key Features & Core Architecture

Multi-ecosystem

npm, PyPI, RubyGems, Maven, NuGet, Go modules, Debian/Ubuntu packages.

Bundle-aware

Reconstructs JS bundle library versions even when they aren't in a manifest.

Transitive coverage

Not just direct deps — flags vulnerable transitives too.

Exportable SBOM

CycloneDX and SPDX exports for supplier and regulator handoff.

Ticketing integration

One deduped ticket per vulnerable package per service.

LIVE PREVIEW

Detected libraries with known CVEs

https://asm.aadhyaaradhya.com/client/dashboard
Sr. No.ServicePackageVersionFix versionCVESeverity
1api.example.comlodash4.17.154.17.21CVE-2021-23337High
2web.example.comreact18.1.0Clean
3checkout.example.comopenssl1.1.1t1.1.1wCVE-2023-5678Critical
INTEGRATIONS

Seamless Output Destinations

Stream threat signals directly into your existing security workflow and ticketing systems.

Jira

Automated ticket routing

Webhook / SIEM

Event webhooks

CycloneDX / SPDX

Standard SBOM formats

Slack

Critical vulnerability alerts

USE CASES

Built for Every Security Role

AppSec Engineer

SBOM validation

Prove the SBOM your build system produces matches what's actually deployed.

Procurement

Vendor risk

Get a per-vendor SBOM without asking the vendor.

Regulatory Response

Log4Shell drills

Answer 'are we exposed to X?' in minutes, not a company-wide audit.

FREQUENTLY ASKED QUESTIONS

Frequently Asked Questions

No. Library Scanner works from external observation only.

Every library, every version, every CVE.

Get a Library Scanner report on your production services without touching a single repo.