DevHorrors mascot
⚠ LIVE THREAT MONITOR6 critical active

YOUR AI
HALLUCINATED
A BACKDOOR.

// Slopsquatted packages in your manifest.
// Scan them. Roast the AI. Don't get pwned.

Live Activity
NEW THREATcrypt0-utilsnpmCRITICAL
devhorrors v2.0
12345678
Free Tool

Roast My Code.

Paste your package.json, requirements.txt, or source code and let Spectre — our security ghost — tear into your dependencies, then tell you exactly how to fix them.

Darkly humorous. Technically accurate. Free with login.

Roast My Code
Spectre the security ghost
Community

Horror Stories

All Stories

Got a horror story?

Share your slopsquatting encounter. Warn other devs. Earn your badge.

Submit Story
Live Intelligence

Threat Detection Trends

Last 14 days
● LIVE

New slopsquatting threats and encyclopedia entries detected by DevHorrors.

Aug 28Aug 29Aug 30Aug 31Sep 1Sep 2Sep 3Sep 4Sep 5Sep 6Sep 7Sep 8Sep 9Sep 1005101520
Roast Engine

Paste any code → instant security roast + shareable horror report.

Try Free →
GitHub PR Bot

Install once. Block slopsquatted packages from every pull request automatically.

See Plans →
CI/CD Integration

Drop our GitHub Actions step into any pipeline. Fail builds on critical threats.

View Docs →
Uptime Monitoring

Know the second
your site goes dark.

Add any URL and DevHorrors watches it around the clock. The moment it goes down — or recovers — you get a branded email alert with response codes, timestamps, and a one-click link to your dashboard.

Continuous checks
Every few minutes, 24/7
Instant email alerts
Branded & visual
Up & down alerts
Recovery notices too
Zero setup
No agent, no install
Start Monitoring
Status Board
Live
api.acme.io
Operational · 142ms
99.98%
30d uptime
checkout.acme.io
Degraded · 1.8s
99.71%
30d uptime
status.acme.io
Operational · 88ms
100%
30d uptime
Alert → you@company.com the instant a status flips.
Developer-First Security

Built by devs, for devs.
No enterprise sales calls.

Snyk is great for enterprises. DevHorrors is great for developers. Scan for free, integrate in minutes, and only pay when you need automation at scale.

Instant scan — no signup required for first 50 packages
CLI + API access on every plan, including free
GitHub PR bot auto-blocks malicious PRs
AI-powered hallucination detection for unknown packages
devhorrors-cli
# Install the DevHorrors CLI
npx devhorrors scan

# Or scan a specific manifest
npx devhorrors scan package.json

# Scan a code snippet
npx devhorrors scan --snippet import("crypto-utils")
// Output
⚡ Scanning package.json...
📦 12 packages found
☠ 2 threats detected:
crypt0-utils (CRITICAL · slopsquat)
react-fast-loader (HIGH · typosquat · AI-detected)
✓ Scan complete in 3.2s
Free Tool

Is Your Project Safe?

Paste your package.json, requirements.txt, go.mod, or Gemfile. We'll check every dependency instantly.