pkgdrift

PkgDrift — an autonomous LLM refinement pipeline that continuously analyzes open-source packages for drift, vulnerabilities, and supply-chain risk. Machine-readable trust decisions for CI/CD, security tooling, and AI agents.

Live Package Index — npm · PyPI · Cargo · RubyGems · Go · Maven · NuGet · Hex · Pub · JSR · CRAN · Hackage · Packagist · Zig · SwiftPM · Debian · Ubuntu · Alpine
alpine/busyboxcargo/actix-webcargo/base64go/github.com/dgrijalva/jwt-gogo/github.com/dgrijalva/jwt-go/v4cargo/nomcargo/ringcargo/serdecran/shinygo/github.com/go-chi/chigo/github.com/go-chi/chi/v2go/github.com/go-chi/chi/v3go/github.com/go-chi/chi/v4go/github.com/golang-jwt/jwtgo/github.com/golang-jwt/jwt/v4go/github.com/gorilla/muxgo/github.com/grpc-ecosystem/grpc-gatewaygo/github.com/hashicorp/go-retryablehttpgo/github.com/jackc/pgxgo/github.com/jackc/pgx/v4go/golang.org/x/cryptogo/golang.org/x/netgo/gorm.io/gormhaskell/aeson
5 high-risk · 84 low risk · 133 clean
High risk — active CVE or exploit Low severity — drift, no critical CVE Clean — no known issues

Intelligence Endpoint

Unified composite assessment — decision, risk score, reputation, remediation, and dependency shocks in a single response shaped for CI/CD and AI agents.

Bulk Analysis

Send a full dependency manifest in one request. Unknown packages do not fail the batch. Per-package rate-limit accounting preserved across all results.

Risk Graph

BFS transitive dependency risk propagation up to depth 5. Identifies risky transitive dependencies invisible to shallow scans — up to 200 nodes per call.

Checking…

API Endpoints

MethodPathDescription
GET/v1/intelligence/{eco}/{name}Composite assessment: decision, risk score, reputation, shocks, remediation
POST/v1/intelligence/bulkBatch assessment — up to 50 packages per request
GET/v1/package/{eco}/{name}Full package record — risk score, confidence, maintainers, CVEs
GET/v1/package/{eco}/{name}/dependenciesDeclared dependency list
GET/v1/package/{eco}/{name}/vulnerabilitiesKnown CVEs and advisories
GET/v1/package/{eco}/{name}/reputationReputation composite (6-signal model)
GET/v1/package/{eco}/{name}/shockShock event timeline
GET/v1/package/{eco}/{name}/remediationActionable remediation plan with urgency level
GET/v1/package/{eco}/{name}/risk-graphBFS dependency risk graph (up to 200 nodes)
GET/v1/packagesBrowse all indexed packages
GET/v1/advisoriesBrowse all advisory records
GET/v1/nvdBrowse NVD vulnerability data
GET/healthServer health check

Pricing

PlanPriceMonthly QuotaOverageHourly Limit
BasicFree5,000 / moHard stop100 / hr
Pro$9.99 / mo50,000 / mo$0.25 / 1,000500 / hr
Ultra$29.99 / mo250,000 / mo$0.15 / 1,0001,000 / hr
Mega$99.99 / mo1,000,000 / mo$0.08 / 1,0005,000 / hr
Get API Key on RapidAPI Terms of Service
Terms of Service

Last updated: 2026-05-31

Operator

The OpenClaw API and related services are operated under the trade name "pkgdrift" ("we", "us", or "our").

No Professional Advice

The Service provides informational, analytical, and automated decision-support outputs only. We do not provide legal, security, compliance, investment, accounting, engineering, or professional advice. Users are solely responsible for independently evaluating all outputs before relying on them.

No Warranty

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, RELIABILITY, AVAILABILITY, SECURITY, AND ERROR-FREE OPERATION.

AI Output Disclaimer

We may generate automated recommendations, classifications, risk scores, summaries, analyses, or other machine-generated outputs. Such outputs may be inaccurate, incomplete, outdated, or unsuitable for a particular purpose. Users assume all risks associated with reliance upon any output generated by the Service.

Third-Party Data Disclaimer

We rely on information provided by third parties, including package registries, vulnerability databases, security advisories, source-code repositories, and public data sources. We do not guarantee the completeness, accuracy, availability, or timeliness of any third-party information.

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, OR MULTIPLE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, LOST BUSINESS OPPORTUNITIES, BUSINESS INTERRUPTION, LOSS OF GOODWILL, LOSS OF DATA, OR COST OF SUBSTITUTE SERVICES.

Liability Cap

For free users: OUR TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED ONE HUNDRED CANADIAN DOLLARS (CAD $100).

For paying customers: OUR TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED THE GREATER OF (A) CAD $100 OR (B) THE FEES PAID BY THE CUSTOMER DURING THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

Security and Vulnerability Disclaimer

We do not warrant that use of the Service will identify all vulnerabilities, security risks, malicious packages, supply-chain attacks, compliance issues, or software defects. The absence of a warning, advisory, recommendation, or detection does not imply the absence of risk.

Customer Indemnification

The customer shall defend, indemnify, and hold harmless us, our officers, directors, employees, contractors, and affiliates from any claims, damages, liabilities, losses, costs, and expenses arising from:

API Abuse Protection

We may suspend, throttle, restrict, or terminate access at any time, with or without notice, to protect the Service, infrastructure, users, or third parties. You may not use this API to:

Force Majeure

We shall not be liable for failures caused by events beyond our reasonable control, including internet outages, cloud provider failures, cyberattacks, denial-of-service attacks, labor disputes, natural disasters, government actions, or third-party service disruptions.

Governing Law

These Terms shall be governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein.

Arbitration and Dispute Resolution

Any dispute arising from these Terms shall be resolved through binding arbitration in Ontario, Canada, to the extent permitted by applicable law.

Deployment and Operational Decisions

We expressly disclaim liability for software deployment decisions, package upgrades, dependency updates, security remediation actions, vulnerability management decisions, CI/CD pipeline actions, automated workflows, AI-agent actions, or any operational decisions made based on Service outputs.

By accessing this API you agree to these terms.