Monitor every ecosystem in your stack
The problem
Source: IBM Cost of a Data Breach Report 2024
Outrightly closes the known-CVE awareness gap in minutes.
Source: Ponemon Institute, State of Vulnerability Response 2023
Only CVEs that match your stack and version.
Source: CISA KEV analysis, Kenna Security 2022
CISA KEV and PoC signals in real time.
Full lock-file parsing covers direct and transitive deps.
Outrightly monitors and alerts — it does not remediate. Patching, dependency upgrades, and pipeline gating remain your team's responsibility. Outrightly complements tools like Dependabot and Renovate; it does not replace them.
How it works
Upload a manifest file, add packages manually, or connect a GitHub repo. Done in under 60 seconds.
NVD, OSV, CISA KEV, and GitHub Advisories are continuously ingested and version-matched against your exact package versions.
An alert fires the moment there is a match. Email, Slack, or webhook. CVSS score, exploit status, and patch version included.
New CVEs are ingested every 15 minutes. When a new vulnerability matches any package in any of your stacks, an alert fires immediately — no manual re-scan required.
Capabilities
Register technologies across npm, PyPI, Go, Maven, Cargo, RubyGems, and NuGet. Version-aware matching means zero false positives from packages you've already patched.
Every alert includes CVSS score, CISA KEV status, public PoC repository links with star counts, and active exploitation signals sourced from trusted threat intelligence feeds.
Upload package-lock.json, poetry.lock, Cargo.lock, Gemfile.lock, or any lock file. We parse the full resolved dependency tree — every transitive package at its exact installed version.
Browsable database of 500k+ vulnerabilities with filters by severity, ecosystem, and type. Full-text search. No login required - free forever for teams exploring the threat landscape.
Configure delivery to email, Slack webhook, or any custom HTTP endpoint. Set per-stack alert frequency and minimum severity thresholds so you only get what genuinely requires action.
Full alert history, severity breakdown charts, and a timeline of every vulnerability matched against your stacks. Export-ready for compliance reviews, security audits, and board reporting.
CISA's Known Exploited Vulnerabilities catalog is monitored with a dedicated watcher. When a CVE affecting your stack is added to KEV — confirming active exploitation — you're alerted in under 2 minutes.
Connect a repo and Outrightly reads your dependency files daily. Every push that adds or updates a package is automatically reflected in your monitored stack — no manual uploads needed.
Real incidents
Three documented breaches. Three different blind spots no scanner was built to catch.
Pricing
No seat pricing. One subscription covers your whole team.
Need more? Talk to us about Enterprise.
Unlimited stacks · Custom DPA · SSO (roadmap) · Dedicated support · Priority SLA
All prices in USD · No seat pricing · One subscription covers your entire team · Cancel anytime
Package limits: if you exceed your plan's package cap, we alert you and continue monitoring all packages — we never silently drop coverage. Upgrade to remove the cap.