Predict abandonment risk
Health scores computed daily from GitHub commit activity, bus factor, download trends, and CVE counts. Know what will break before it does.
DepGraph gives every npm package a real-time health score — maintenance activity, bus factor, download trend, known CVEs — so you can fix risks before they become production emergencies.
Unlike reactive tools that only alert after a CVE is published, DepGraph is predictive — surfacing risk before it becomes a production emergency.
Health scores computed daily from GitHub commit activity, bus factor, download trends, and CVE counts. Know what will break before it does.
Score drops, new CVEs, and abandonment flags trigger real-time alerts. Stay informed without constantly checking.
Every at-risk package includes migration path suggestions, alternative libraries, and effort estimates.
The free tier is genuinely useful — not crippled. Upgrade to Pro when you need private repos, real-time alerts, or 365-day history.
Everything you need to get started.
For developers serious about dependency health.
For small engineering teams.
| Feature | Free | Pro | Team |
|---|---|---|---|
| CLI scanner | ✓ | ✓ | ✓ |
| Saved projects | 3 | Unlimited | Unlimited |
| Private repos | ✗ | ✓ | ✓ |
| Score history | 30 days | 365 days | 365 days |
| Real-time alerts | ✗ | ✓ | ✓ |
| On-demand re-scan | ✗ | ✓ | ✓ |
| SBOM export | ✗ | JSON | CycloneDX |
| Migration suggestions | ✗ | ✓ | ✓ |
| Org dashboard | ✗ | ✗ | ✓ |
| Custom risk policies | ✗ | ✗ | ✓ |
| Priority support | ✗ | ✗ | ✓ |