Built for agencies and dev shops running many codebases
Know the moment a dependency in any of your projects turns risky.
Upload a package.json or pnpm-lock.yaml, and PatchRadar checks every dependency against the same advisory data behind npm audit, flags Node.js versions past end of life, and keeps watching after you leave — across every client project you maintain.
Free for up to 3 projects. No credit card, no repo access required.
Your projects · 4 tracked
acme-storefront
package.json · audited 3h ago
2 critical5 moderate- EOL warning
northwind-api
Node 16 · past end-of-life
harbour-cms
pnpm-lock.yaml · audited yesterday
1 high3 low- All clear
fenwick-blog
package.json · audited yesterday
1 source
Powered by the same advisory data npm audit uses
100%
Of your dependency tree, checked from a single manifest
< 24h
From a new advisory being published to landing in your inbox
Everything you need to stay ahead of a vulnerability
One manifest upload gives you a full picture — today, and every day after.
Vulnerability auditing
Every dependency checked against the npm advisory database and ranked by severity — critical, high, moderate, low.
Node.js EOL tracking
See which projects are running a Node.js version that's approaching or past end of life, before it becomes an incident.
Multi-project dashboard
Every client and every codebase in one grid, sorted by what actually needs your attention today.
Email alerts
Get told when a new advisory affects one of your projects. Alerts are deduplicated into a single digest, not a flood.
Latest-version tracking
See exactly how far behind each dependency is against its latest release, so upgrade decisions are informed, not guesswork.
Zero agents, zero integrations
Just upload a manifest. No CI hooks, no installed agent, no repository access — ever.
How it works
No agent to install, no pipeline to configure. Three steps, and you're done.
- Step 1
Upload your manifest
Drag in a package.json or pnpm-lock.yaml. That's the only file we ever need.
- Step 2
We run the audit
Every dependency is checked against the npm advisory database and cross-referenced with the Node.js EOL calendar.
- Step 3
Get your report, then get alerts
A colour-coded breakdown lands immediately, followed by email alerts whenever a new advisory affects your projects.
Simple pricing, per organisation
Start free, upgrade when you're watching more than a few projects.
Free
For a first project, or a handful of side projects.
$0forever
- Up to 3 projects
- Vulnerability + EOL reports
- Manual re-checks whenever you like
Pro
For agencies and freelancers managing client work.
$9per month
- Unlimited projects
- Daily automated re-audits
- Email alerts for new advisories
- Latest-version tracking
Team
For teams who need to share visibility across seats.
$29per month
- Everything in Pro
- Shared workspaces
- Multiple seats
- Slack alerts
Prices in USD. Cancel anytime — no minimum term.
Frequently asked questions
Where does the vulnerability data come from?
The same public npm advisory database that powers npm audit. We don't run a separate scanner or maintain our own feed — if npm audit would flag it, PatchRadar will too.
Do you need access to my code or repository?
No. You upload a package.json or pnpm-lock.yaml file directly. We never ask for repository access, an installed agent, or CI credentials — your source code never leaves your machine.
What file formats are supported?
package.json and pnpm-lock.yaml today. A lockfile gives a more precise, deduplicated audit because it records the exact versions actually installed; a plain package.json still works, using its declared version ranges.
What counts as a project?
Any single manifest you upload. Most teams create one project per repository, or per client engagement — however you already split up the work.
Can I cancel anytime?
Yes. Downgrade to Free or cancel a paid plan whenever you like. There's no minimum term and no lock-in.
Stop finding out about a vulnerability from a client's IT team.
Start free, and have your first project audited in under a minute.