[Tool] fad-checker – Air-gapped, multi-ecosystem dependency auditor made for real code audits (NO Maven required)
fad-checker is a standalone, air-gapped dependency auditing tool designed for professional code audits across multiple ecosystems without requiring build tools or network access. It supports scanning Maven, Gradle, npm, PyPI, NuGet, Go, Ruby, and more, identifying vulnerabilities, deprecated packages, private/internal dependencies, and committed cryptographic material. The tool produces detailed reports including CVE prioritization, license information, and supply chain risk indicators. It is intended to simplify and improve the accuracy of audits in complex, multi-module, polyglot codebases.
AI Analysis
Technical Summary
fad-checker is an air-gapped, multi-ecosystem dependency auditor that scans various package ecosystems and committed artifacts without requiring build environments or network connectivity. It reads manifests and lockfiles directly from disk, supports multiple output formats including HTML and Word, and prioritizes CVEs using CISA KEV, EPSS, and CVSS scores. The tool also detects private/internal packages, deprecated or abandoned dependencies, and cryptographic material such as certificates and keys. It is designed for real-world professional code audits, enabling one-shot scans of large polyglot monorepos and producing audit-grade reports with provenance and delta comparisons.
Potential Impact
fad-checker itself is a security tool that helps identify vulnerabilities, deprecated dependencies, private/internal packages, and cryptographic risks in source code repositories. It does not introduce a vulnerability or threat but rather mitigates risk by improving visibility and prioritization of security issues in dependencies and committed artifacts. There is no indication of any security flaw or exploit associated with fad-checker.
Mitigation Recommendations
No remediation or patching is required as fad-checker is a security auditing tool, not a vulnerability. Users should consider adopting it to improve dependency auditing and supply chain risk management in air-gapped or complex environments.
[Tool] fad-checker – Air-gapped, multi-ecosystem dependency auditor made for real code audits (NO Maven required)
Description
fad-checker is a standalone, air-gapped dependency auditing tool designed for professional code audits across multiple ecosystems without requiring build tools or network access. It supports scanning Maven, Gradle, npm, PyPI, NuGet, Go, Ruby, and more, identifying vulnerabilities, deprecated packages, private/internal dependencies, and committed cryptographic material. The tool produces detailed reports including CVE prioritization, license information, and supply chain risk indicators. It is intended to simplify and improve the accuracy of audits in complex, multi-module, polyglot codebases.
Reddit Discussion
Hi !
After years of doing code audits, existing SCA tools were just frying my brain with their need for a full build environment, their struggles with big multi-module Maven projects, and those messy, monstrous polyglot monorepos.
So I wrote fad-checker a dependency auditor designed specifically for real-world professional code audits:
• One-shot scan of multiples Maven / Gradle / npm / PHP / PyPI / NuGet / Go / Ruby projects
• + vendored JS, committed binaries, certificates & private keys
• No build tools, no Docker, no package manager
• True air-gapped mode
• Private/internal package detection
• CVE prioritization (KEV → EPSS → CVSS) + EOL + licenses
• The HTML report that code auditors dream of, with one-click “Copy for Word” on charts, summary & tables
• Word / CycloneDX / SARIF / JSON outputs + CI bindings / outputs
• Cross-platform standalone binaries
Battle tested and compared to leading (partial) alternatives
Repo : https://github.com/9pings/fad-checker
Looking for feedback (and criticism) from people who actually do source code audits.
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
fad-checker is an air-gapped, multi-ecosystem dependency auditor that scans various package ecosystems and committed artifacts without requiring build environments or network connectivity. It reads manifests and lockfiles directly from disk, supports multiple output formats including HTML and Word, and prioritizes CVEs using CISA KEV, EPSS, and CVSS scores. The tool also detects private/internal packages, deprecated or abandoned dependencies, and cryptographic material such as certificates and keys. It is designed for real-world professional code audits, enabling one-shot scans of large polyglot monorepos and producing audit-grade reports with provenance and delta comparisons.
Potential Impact
fad-checker itself is a security tool that helps identify vulnerabilities, deprecated dependencies, private/internal packages, and cryptographic risks in source code repositories. It does not introduce a vulnerability or threat but rather mitigates risk by improving visibility and prioritization of security issues in dependencies and committed artifacts. There is no indication of any security flaw or exploit associated with fad-checker.
Defensive Guidance
No remediation or patching is required as fad-checker is a security auditing tool, not a vulnerability. Users should consider adopting it to improve dependency auditing and supply chain risk management in air-gapped or complex environments.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6ab37d13f7a7c541066e5dd4
Added to database: 09/23/2026, 07:17:39 UTC
Last enriched: 09/23/2026, 07:17:45 UTC
Last updated: 09/24/2026, 04:17:36 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.