PACKAGE INTELLIGENCE

Understand the security risk behind every package

Package Intelligence provides the security context behind a software package—before it is trusted or allowed into the environment.
Security Intelligence
CVE intelligence, security findings and package context.
Explainable Findings
Understand what was detected and why it matters.
Threat Score
Turn package-level findings into a concise security view.

THE PROBLEM

A package name tells you what it is. It doesn't tell you what you should know about it.

Modern software packages carry far more security information than their name and version reveal. Vulnerabilities, dependencies, publisher information, package data and detected indicators all contribute to the package's security context.
Dependencies
Direct and transitive dependencies and their associated risks.
Vulnerabilities
Known CVEs and security issues linked to this package version.

lodash

v4.17.21 • npm

Publisher Information
Publisher identity, reputation and historical behavior.
Package Data
Version history, registry metadata, license, manifests and other attributes.
Behavior & Changes
Recent changes, release activity and other behavioral indicators.

HOW IT WORKS

The Security Engine sits in the middle and makes the decisions.

PexLens analyzes package data using multiple security checks, maps known vulnerabilities, applies detection rules, and decides what it means.

Package Information

What we know about the package

Security Engine

CVE mapping, detection rules and analysis

Findings

What was found, evidence and reasons

Package Intelligence

Complete security understanding

1

Package Input

We collect package information and related context.
  • Name & version
  • Publisher & registry
  • Dependencies
  • Metadata & manifests
2

PexLens Security Engine

Our engine runs multiple checks, correlates signals and makes decisions.
  • Security Checks
  • CVE Mapping
  • Detection Rules
  • Pattern Analysis
3

Engine Decisions

The engine evaluates results and decides what was found and why it matters.
  • Vulnerability identified
  • Suspicious indicator detected
  • Risky dependency detected
  • Policy / rule matched
4

Findings Generated

Decisions are turned into clear findings with evidence and context.

CVE-YYYY-XXXX

Critical

Suspicious Code

High

Outdated Dep

Medium

Info Signal

Low

5

Package Intelligence

Findings are organized into actionable intelligence you can act on.
  • What was found
  • Why it matters
  • Severity / impact
  • Supporting evidence
  • Actionable context

One engine. Multiple checks. Clear decisions.

PexLens Security Engine connects the dots and delivers package intelligence you can trust.
Accurate
Maps CVEs and applies reliable detection rules.
Consistent
Standardized analysis across your ecosystem.
Actionable
Clear reasons and evidence to drive confident action.

FROM INSIGHT TO ACTION

Intelligence that powers better security decisions.

Use Package Intelligence across your SDLC and security workflows to reduce risk and build securely.
Understand the real security risk of every package you use.
Focus on what matters based on impact and evidence.
Apply policies with intelligence and block risky packages.
Continuously monitor changes and stay ahead of emerging risks.

Know the risk before you trust the package.

See the full risk profile behind every package — before it enters your codebase.