Looking for a dependency checker alternative?
These tools shut down. PackageFix fills the gap — free, browser-based, no login required.
⚠ Snyk Advisor shut down January 2026.
If you relied on it for package health scores, CVE checking, or
manifest scanning — PackageFix is the direct free replacement.
No signup. No CLI. Paste your manifest and download the fix.
| Tool | Status | Browser? | Fix output? | No signup? |
|---|---|---|---|---|
| PackageFix | ✅ Live | ✅ Yes | ✅ Fixed manifest + .zip | ✅ Yes |
| Snyk Advisor | Shut down Jan 2026 | ✅ Was browser | ❌ No fix output | ❌ Required signup |
| Socket.dev | Active | ✅ Browser | ❌ No fix output | ❌ Requires signup |
| Dependabot | Active | ❌ GitHub bot only | ⚠ Opens PRs only | ❌ Requires GitHub |
| OSV Scanner | Active | ❌ CLI only | ❌ No fix output | ✅ Yes |
| Trivy | Active | ❌ CLI only | ❌ No fix output | ✅ Yes |
| npm audit | Active | ❌ CLI only | ⚠ npm audit fix only | ✅ Yes |
| pip-audit | Active | ❌ CLI only | ❌ No fix output | ✅ Yes |
| cargo-audit | Active | ❌ CLI only | ❌ No fix output | ✅ Yes |
| Mend.io | Active | ✅ Browser | ⚠ Enterprise only | ❌ Requires account |
| Endor Labs | Active | ✅ Browser | ⚠ Enterprise only | ❌ Requires account |
| david-dm | Unmaintained 2022 | ✅ Was browser | ❌ No fix output | ✅ Yes |
| Greenkeeper | Shut down 2020 | ❌ GitHub bot | ⚠ PRs only | ❌ Required GitHub |
| Gemnasium | Shut down 2018 | ✅ Was browser | ❌ No fix output | ❌ Required signup |
| requires.io | Went dark 2022 | ✅ Was browser | ❌ No fix output | ✅ Yes |
| bundle-audit | Active | ❌ CLI only | ❌ No fix output | ✅ Yes |
What PackageFix does that they never did
🌐 Browser-based
No CLI install. No GitHub connection.
Works behind corporate firewalls where Snyk and Socket are blocked.
⬇ Download the fix
Fixed manifest + changelog .zip
in one click. Every alternative gives you a report.
Only PackageFix gives you the fixed file.
🔴 CISA KEV Alerts
Flags vulnerabilities actively
exploited in real attacks right now. No other browser tool
surfaces CISA KEV data.
🔒 No signup ever
Your manifest never leaves
your browser. Only package names and versions are sent to
public APIs — the same requests any package manager makes.