PatchRadar

Built for agencies and dev shops running many codebases

Know the moment a dependency in any of your projects turns risky.

Upload a package.json or pnpm-lock.yaml, and PatchRadar checks every dependency against the same advisory data behind npm audit, flags Node.js versions past end of life, and keeps watching after you leave — across every client project you maintain.

Free for up to 3 projects. No credit card, no repo access required.

Your projects · 4 tracked

  • acme-storefront

    package.json · audited 3h ago

    2 critical5 moderate
  • northwind-api

    Node 16 · past end-of-life

    EOL warning
  • harbour-cms

    pnpm-lock.yaml · audited yesterday

    1 high3 low
  • fenwick-blog

    package.json · audited yesterday

    All clear

1 source

Powered by the same advisory data npm audit uses

100%

Of your dependency tree, checked from a single manifest

< 24h

From a new advisory being published to landing in your inbox

Everything you need to stay ahead of a vulnerability

One manifest upload gives you a full picture — today, and every day after.

Vulnerability auditing

Every dependency checked against the npm advisory database and ranked by severity — critical, high, moderate, low.

Node.js EOL tracking

See which projects are running a Node.js version that's approaching or past end of life, before it becomes an incident.

Multi-project dashboard

Every client and every codebase in one grid, sorted by what actually needs your attention today.

Email alerts

Get told when a new advisory affects one of your projects. Alerts are deduplicated into a single digest, not a flood.

Latest-version tracking

See exactly how far behind each dependency is against its latest release, so upgrade decisions are informed, not guesswork.

Zero agents, zero integrations

Just upload a manifest. No CI hooks, no installed agent, no repository access — ever.

How it works

No agent to install, no pipeline to configure. Three steps, and you're done.

  1. Step 1

    Upload your manifest

    Drag in a package.json or pnpm-lock.yaml. That's the only file we ever need.

  2. Step 2

    We run the audit

    Every dependency is checked against the npm advisory database and cross-referenced with the Node.js EOL calendar.

  3. Step 3

    Get your report, then get alerts

    A colour-coded breakdown lands immediately, followed by email alerts whenever a new advisory affects your projects.

Simple pricing, per organisation

Start free, upgrade when you're watching more than a few projects.

Free

For a first project, or a handful of side projects.

$0forever

  • Up to 3 projects
  • Vulnerability + EOL reports
  • Manual re-checks whenever you like
Start free
Most popular

Pro

For agencies and freelancers managing client work.

$9per month

  • Unlimited projects
  • Daily automated re-audits
  • Email alerts for new advisories
  • Latest-version tracking
Start Pro trial
Coming soon

Team

For teams who need to share visibility across seats.

$29per month

  • Everything in Pro
  • Shared workspaces
  • Multiple seats
  • Slack alerts
Coming soon

Prices in USD. Cancel anytime — no minimum term.

Frequently asked questions

Where does the vulnerability data come from?

The same public npm advisory database that powers npm audit. We don't run a separate scanner or maintain our own feed — if npm audit would flag it, PatchRadar will too.

Do you need access to my code or repository?

No. You upload a package.json or pnpm-lock.yaml file directly. We never ask for repository access, an installed agent, or CI credentials — your source code never leaves your machine.

What file formats are supported?

package.json and pnpm-lock.yaml today. A lockfile gives a more precise, deduplicated audit because it records the exact versions actually installed; a plain package.json still works, using its declared version ranges.

What counts as a project?

Any single manifest you upload. Most teams create one project per repository, or per client engagement — however you already split up the work.

Can I cancel anytime?

Yes. Downgrade to Free or cancel a paid plan whenever you like. There's no minimum term and no lock-in.

Stop finding out about a vulnerability from a client's IT team.

Start free, and have your first project audited in under a minute.