How DevHorrors
Protects Your Stack.
DevHorrors is not a hobby scanner. It is a full-spectrum software supply chain security platform — built to meet the operational demands of enterprise engineering teams, DevSecOps pipelines, and compliance-driven organisations.
From manifest to mitigation in seconds.
Ingest & Index Threat Intelligence
DevHorrors continuously ingests reports from security researchers, community submissions, automated registry scans, and NVD/OSV cross-references. Every hallucinated, slopsquatted, or typosquatted package is catalogued with full provenance, AI model attribution, and ecosystem metadata.
Static Manifest Analysis
Submit any dependency manifest — package.json, requirements.txt, go.mod, Gemfile, pom.xml — or paste raw code. Our engine parses every declared dependency, resolves transitive relationships, and cross-references the full threat encyclopedia in milliseconds.
Multi-Layer Threat Detection
Detection runs four independent layers: exact match against the encyclopedia, heuristic analysis for hallucination patterns, homoglyph detection for Unicode substitution attacks, and dependency confusion fingerprinting for internal package name shadowing.
Automated Remediation Suggestions
For every flagged package, DevHorrors automatically queries the upstream registry to identify the legitimate package it mimics. You get a drop-in replacement with verified download counts, GitHub presence, and licence compatibility — not just a warning, a fix.
CI/CD Gate & GitHub PR Bot
Integrate once via GitHub Actions or our native PR bot. Every pull request that touches a manifest is automatically scanned. Builds fail on configurable severity thresholds. Comments are posted inline with threat details, remediation steps, and encyclopedia links.
Real-Time Monitoring & Alerts
Register your project's dependency list for continuous monitoring. When a new threat is added to the encyclopedia that matches any of your tracked packages, DevHorrors fires an immediate alert via Slack, Discord, or webhook — before your next deployment.
Beyond slopsquatting.
DevHorrors addresses the full surface area of modern software supply chain attacks — not just the AI hallucination problem, but every attack vector that exploits the gap between what a package claims to be and what it actually does.
Identify AI-hallucinated package names that have been maliciously registered on public registries.
Detect compromised-post-publish packages where legitimate code has been replaced with malicious payloads.
Catch Unicode substitution attacks — packages using 'ехpress' (Cyrillic е) instead of 'express'.
Identify internal package names that could be hijacked via public registry shadowing.
Verify your lockfiles haven't been tampered with between commits — a common lateral movement vector.
Every dependency is cross-referenced against the NVD and OSV databases in real time.
Built for security teams.
Trusted by engineering leads.
DevHorrors is designed from the ground up to integrate into enterprise security programmes. Our threat data feeds directly into SIEMs, our CI/CD gates support shift-left security policies, and our compliance exports satisfy audit requirements across SOC 2, ISO 27001, and internal information security frameworks.
Talk to Our Security TeamStart protecting your dependencies today.
Free scanner. No account required. Enterprise plans start at $19/month.