No account, no source upload — paste a manifest/lockfile and get OSV+KEV+EPSS-prioritized findings in a session-isolated workspace. Also ran a typosquat study: checked every single-char typo of the 30 most popular npm/PyPI packages against the real registries and OSV's malicious-package DB — 32.7% of registered npm look-alikes are already confirmed malicious. Data/methodology:
https://depwarden.in/blog/npm-pypi-typosquatting-2026-report