# DepVet > Pre-install dependency vetting for AI agents. Check an npm or PyPI package and get an OK/REVIEW/AVOID verdict with reasons: OSV vulnerabilities, malware advisories, license risk, deprecation, maintenance, OpenSSF Scorecard, typosquat hints. Pay per call in USDC on Base via x402. No API key. ## Endpoints (GET query params or POST JSON; ecosystem = npm | pypi) - GET https://depvet.imac2014ville.workers.dev/check?ecosystem=npm&name=express[&version=] : $0.005, light check - GET https://depvet.imac2014ville.workers.dev/report?ecosystem=npm&name=express[&version=] : $0.02, full report - GET https://depvet.imac2014ville.workers.dev/batch?ecosystem=npm&packages=express,lodash@4.17.20 : $0.05, up to 20 packages - Invalid input returns 400 and unknown packages 404 before payment; you are not charged. - Unpaid requests return HTTP 402 with x402 payment requirements; use @x402/fetch or any x402 client. ## Developer guides - Check an npm package for malware before you install it: https://depvet.imac2014ville.workers.dev/guides/check-npm-package-malware-before-install - Detect typosquatting in package.json dependencies: https://depvet.imac2014ville.workers.dev/guides/detect-typosquatting-in-package-json - Scan a lockfile for vulnerable dependencies in CI or agents: https://depvet.imac2014ville.workers.dev/guides/scan-lockfile-for-vulnerable-dependencies-ci ## Links - OpenAPI: https://depvet.imac2014ville.workers.dev/openapi.json - Docs (JSON): fetch https://depvet.imac2014ville.workers.dev/ with Accept: application/json - Source: https://github.com/Imac2014Ville/depvet - Sister service: https://baselens.imac2014ville.workers.dev