{"uid":"cap_33In7gEDPnuTlLhvbvzqV","slug":"2s-security-package-vulnerability-scorecard-lookup-29a60f1a","name":"2s Security Package Vulnerability & Scorecard Lookup","description":"Security and provenance for an open-source package, composed live from three authoritative sources in one call. Pass ecosystem (npm, pypi, go, maven, cargo, nuget) + name (+ optional version; defaults to latest). Returns: known vulnerabilities from OSV (osv.dev — aggregates GitHub Security Advisories, PyPA, RustSec, Go vuln DB, etc.) each with its id, CVE aliases, summary, severity, and references; the resolved license and deprecation status (deps.dev); and the source repo's OpenSSF Scorecard health score (overall + per-check) plus stars/forks/open-issues. All live — newly-disclosed advisories appear within hours. Distinct from registry.npm-lookup / pypi-lookup (metadata only): this answers \"is this dependency safe to add, what license does it carry, and how well-maintained is it.\"","url":"https://2s.io/api/security/package","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","queryParams"],"properties":{"type":{"const":"http"},"method":{"const":"GET"},"queryParams":{"required":["ecosystem","name"],"properties":{"name":{"type":"string","description":"Package name (e.g. lodash, requests)."},"version":{"type":"string","description":"Version (defaults to latest)."},"ecosystem":{"type":"string","description":"Package ecosystem: npm, pypi, go, maven, cargo, or nuget."}}}}}}},"responseSchema":null,"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"name":"lodash","version":"4.17.21","ecosystem":"npm"}}},"response":{"data":{"ok":true,"meta":{"sources":["OSV","deps.dev","OpenSSF Scorecard"]},"items":[{"repo":{"forks":7171,"stars":61235,"openIssues":152},"license":"MIT","package":{"name":"lodash","version":"4.17.21","ecosystem":"npm"},"scorecard":{"date":"2026-06-08T00:00:00Z","checks":[{"name":"Maintained","score":10},{"name":"Dangerous-Workflow","score":10},{"name":"Security-Policy","score":10},{"name":"Code-Review","score":8},{"name":"Binary-Artifacts","score":10},{"name":"Packaging","score":-1},{"name":"CII-Best-Practices","score":0},{"name":"Token-Permissions","score":0},{"name":"Pinned-Dependencies","score":4},{"name":"License","score":9},{"name":"Branch-Protection","score":-1},{"name":"Signed-Releases","score":-1},{"name":"Fuzzing","score":10},{"name":"SAST","score":9}],"overallScore":7.7},"deprecated":false,"sourceRepo":"github.com/lodash/lodash","publishedAt":"2021-02-20T15:42:16Z","vulnerabilities":[{"id":"GHSA-f23m-r3pf-42rh","aliases":["CVE-2026-2950"],"summary":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","modified":"2026-04-02T17:29:51.565211556Z","severity":"MODERATE","published":"2026-04-01T23:50:27Z","references":["https://github.com/lodash/lodash/security/advisories/GHSA-f23m-r3pf-42rh","https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg","https://nvd.nist.gov/vuln/detail/CVE-2026-2950","https://github.com/lodash/lodash"]},{"id":"GHSA-r5fr-rjxr-66jc","aliases":["CVE-2026-4800"],"summary":"lodash vulnerable to Code Injection via `_.template` imports key names","modified":"2026-04-02T17:29:57.498155673Z","severity":"HIGH","published":"2026-04-01T23:51:12Z","references":["https://github.com/lodash/lodash/security/advisories/GHSA-r5fr-rjxr-66jc","https://nvd.nist.gov/vuln/detail/CVE-2026-4800","https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c","https://cna.openjsf.org/security-advisories.html","https://github.com/advisories/GHSA-35jh-r3h4-6jhm","https://github.com/lodash/lodash"]},{"id":"GHSA-xxjr-mmjv-4gpg","aliases":["CVE-2025-13465"],"summary":"Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions","modified":"2026-06-09T11:15:10.330415235Z","severity":"MODERATE","published":"2026-01-21T23:01:22Z","references":["https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg","https://nvd.nist.gov/vuln/detail/CVE-2025-13465","https://github.com/lodash/lodash/commit/edadd452146f7e4bad4ea684e955708931d84d81","https://cert-portal.siemens.com/productcert/html/ssa-253495.html","https://github.com/lodash/lodash"]}],"deprecatedReason":null,"vulnerabilityCount":3}],"total":1,"source":{"url":"https://osv.dev","license":"OSV CC-BY-4.0; deps.dev + OpenSSF Scorecard Apache-2.0. Live-wrapped, not redistributed.","provider":"OSV (osv.dev) + deps.dev + OpenSSF Scorecard"}},"meta":{"cost":{"usd":0.00216,"tier":0},"caller":"x402","version":null,"endpoint":"security.package","settlement":{"txHash":"0x09d834e13f4094445a80c7b897ac10d834c249b561a6666646f76141ff7f6987","network":"eip155:8453","success":true}}}},"exampleRequest":{"name":"lodash","version":"4.17.21","ecosystem":"npm"},"tags":["x402"],"displayCostAmount":"0.00216","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.00216/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.0054","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.0054","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_B_l1ruGO1dX__xsbtdfYP","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.0054","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns vulnerability data, OpenSSF Scorecard, license, and repo stats for a given open-source package across npm, PyPI, Go, Maven, Cargo, or NuGet ecosystems.","exampleAgentPrompt":"Check if the npm package lodash version 4.17.20 has any known vulnerabilities, and what's its OpenSSF security scorecard score?","exampleUseCases":null,"resultDescription":"Returns a JSON object with ok status, an items array containing: package metadata (name, version, ecosystem), list of vulnerabilities with CVE IDs/aliases/summaries/severities/published dates, total vulnerability count, deprecation flag, source repository URL, repository stats (stars, forks, open issues), license, and OpenSSF Scorecard with per-check scores and an overall score. Data sourced from OSV, deps.dev, and OpenSSF Scorecard.","failureModes":["Package not found in the specified ecosystem — empty items array or ok:false","Unsupported ecosystem value — validation error","Missing required parameters (name or ecosystem) — 400-level error","Version not found — may fall back to latest or return empty","Upstream data source unavailable — partial or empty response"],"whenToPreferThis":"Use this endpoint when you need ground-truth security intelligence for an open-source package across major ecosystems (npm, PyPI, Go, Maven, Cargo, NuGet) — especially when you need CVE/vulnerability data, OpenSSF Scorecard, license info, and repo health all in one call. Prefer this over manual OSV or deps.dev queries when you want aggregated, structured output without signup or API keys, paying only per call via USDC.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-13T12:57:00.878Z","isFirstParty":false}