Package Intelligence provides the security context behind a software package—before it is trusted or allowed into the environment.
Security Intelligence
CVE intelligence, security findings and package context.
Explainable Findings
Understand what was detected and why it matters.
Threat Score
Turn package-level findings into a concise security view.
THE PROBLEM
A package name tells you what it is. It doesn't tell you what you should know about it.
Modern software packages carry far more security information than their name and version reveal. Vulnerabilities, dependencies, publisher information, package data and detected indicators all contribute to the package's security context.
Dependencies
Direct and transitive dependencies and their associated risks.
Vulnerabilities
Known CVEs and security issues linked to this package version.
lodash
v4.17.21 • npm
Publisher Information
Publisher identity, reputation and historical behavior.
Package Data
Version history, registry metadata, license, manifests and other attributes.
Behavior & Changes
Recent changes, release activity and other behavioral indicators.
HOW IT WORKS
The Security Engine sits in the middle and makes the decisions.
PexLens analyzes package data using multiple security checks, maps known vulnerabilities, applies detection rules, and decides what it means.
Package Information
What we know about the package
Security Engine
CVE mapping, detection rules and analysis
Findings
What was found, evidence and reasons
Package Intelligence
Complete security understanding
1
Package Input
We collect package information and related context.
Name & version
Publisher & registry
Dependencies
Metadata & manifests
2
PexLens Security Engine
Our engine runs multiple checks, correlates signals and makes decisions.
Security Checks
CVE Mapping
Detection Rules
Pattern Analysis
3
Engine Decisions
The engine evaluates results and decides what was found and why it matters.
Vulnerability identified
Suspicious indicator detected
Risky dependency detected
Policy / rule matched
4
Findings Generated
Decisions are turned into clear findings with evidence and context.
CVE-YYYY-XXXX
Critical
Suspicious Code
High
Outdated Dep
Medium
Info Signal
Low
5
Package Intelligence
Findings are organized into actionable intelligence you can act on.
What was found
Why it matters
Severity / impact
Supporting evidence
Actionable context
One engine. Multiple checks. Clear decisions.
PexLens Security Engine connects the dots and delivers package intelligence you can trust.
Accurate
Maps CVEs and applies reliable detection rules.
Consistent
Standardized analysis across your ecosystem.
Actionable
Clear reasons and evidence to drive confident action.
FROM INSIGHT TO ACTION
Intelligence that powers better security decisions.
Use Package Intelligence across your SDLC and security workflows to reduce risk and build securely.
Assess Risk
Understand the real security risk of every package you use.
Prioritize Fixes
Focus on what matters based on impact and evidence.
Enforce Policy
Apply policies with intelligence and block risky packages.
Drive Continuous Security
Continuously monitor changes and stay ahead
of emerging risks.
Know the risk before you trust the package.
See the full risk profile behind every package — before it enters your codebase.