# Depmoor (by CyberMax) > Dependency vulnerability scanner ranked by real-world risk. Drop a lockfile and get every known vulnerable package (OSV.dev advisories), ranked by CISA KEV (exploited in the wild) and FIRST EPSS (probability of exploitation in 30 days), with the version that fixes it and one upgrade list per package. Lockfiles are read in the browser. - App: https://depmoor.cybermaxtools.com/ - Lockfiles: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt (pinned), poetry.lock, uv.lock, Pipfile.lock, Cargo.lock, go.sum, composer.lock, Gemfile.lock, gradle.lockfile, packages.lock.json - Free: 5 scans a day, every finding shown. No account. - Pro monthly: $9 https://depmoor.cybermaxtools.com/buy/pro-monthly?s=llms - Pro yearly: $90 https://depmoor.cybermaxtools.com/buy/pro-yearly?s=llms - Team monthly: $29 https://depmoor.cybermaxtools.com/buy/team-monthly?s=llms - CI API (Pro 100/day, Team 2000/day): POST https://depmoor.cybermaxtools.com/api/scan?format=json|sarif|csv|md&fail_on=fix-now with "Authorization: Bearer " and JSON {"filename":"package-lock.json","lockfile":"..."} - CISA KEV as compact JSON with CORS: https://depmoor.cybermaxtools.com/api/kev - Machine-readable pricing: https://depmoor.cybermaxtools.com/pricing.json ## Pay per scan (x402, USDC on Base): for AI agents, no key - POST https://depmoor.cybermaxtools.com/api/scan without a key: $0.05 per scan in USDC on Base. An unpaid call returns HTTP 402 with the payment requirements; resend with X-PAYMENT (v1) or PAYMENT-SIGNATURE (v2). Failed scans are not charged. OpenAPI: https://depmoor.cybermaxtools.com/openapi.json