Skip to main content

[Tool] fad-checker – Air-gapped, multi-ecosystem dependency auditor made for real code audits (NO Maven required)

0
Medium
Published: 09/23/2026 (09/23/2026, 06:50:46 UTC)
Source: Reddit Cybersecurity

Description

fad-checker is a standalone, air-gapped dependency auditing tool designed for professional code audits across multiple ecosystems without requiring build tools or network access. It supports scanning Maven, Gradle, npm, PyPI, NuGet, Go, Ruby, and more, identifying vulnerabilities, deprecated packages, private/internal dependencies, and committed cryptographic material. The tool produces detailed reports including CVE prioritization, license information, and supply chain risk indicators. It is intended to simplify and improve the accuracy of audits in complex, multi-module, polyglot codebases.

Reddit Discussion

r/cybersecurity·posted by u/n8tz
00

Hi !

After years of doing code audits, existing SCA tools were just frying my brain with their need for a full build environment, their struggles with big multi-module Maven projects, and those messy, monstrous polyglot monorepos.

So I wrote fad-checker a dependency auditor designed specifically for real-world professional code audits:

• One-shot scan of multiples Maven / Gradle / npm / PHP / PyPI / NuGet / Go / Ruby projects
• + vendored JS, committed binaries, certificates & private keys
• No build tools, no Docker, no package manager
• True air-gapped mode
• Private/internal package detection
• CVE prioritization (KEV → EPSS → CVSS) + EOL + licenses
• The HTML report that code auditors dream of, with one-click “Copy for Word” on charts, summary & tables
• Word / CycloneDX / SARIF / JSON outputs + CI bindings / outputs
• Cross-platform standalone binaries

Battle tested and compared to leading (partial) alternatives

Repo : https://github.com/9pings/fad-checker

Looking for feedback (and criticism) from people who actually do source code audits.

Links cited in this discussion

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 07:17:45 UTC

Technical Analysis

fad-checker is an air-gapped, multi-ecosystem dependency auditor that scans various package ecosystems and committed artifacts without requiring build environments or network connectivity. It reads manifests and lockfiles directly from disk, supports multiple output formats including HTML and Word, and prioritizes CVEs using CISA KEV, EPSS, and CVSS scores. The tool also detects private/internal packages, deprecated or abandoned dependencies, and cryptographic material such as certificates and keys. It is designed for real-world professional code audits, enabling one-shot scans of large polyglot monorepos and producing audit-grade reports with provenance and delta comparisons.

Potential Impact

fad-checker itself is a security tool that helps identify vulnerabilities, deprecated dependencies, private/internal packages, and cryptographic risks in source code repositories. It does not introduce a vulnerability or threat but rather mitigates risk by improving visibility and prioritization of security issues in dependencies and committed artifacts. There is no indication of any security flaw or exploit associated with fad-checker.

Defensive Guidance

No remediation or patching is required as fad-checker is a security auditing tool, not a vulnerability. Users should consider adopting it to improve dependency auditing and supply chain risk management in air-gapped or complex environments.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6ab37d13f7a7c541066e5dd4

Added to database: 09/23/2026, 07:17:39 UTC

Last enriched: 09/23/2026, 07:17:45 UTC

Last updated: 09/24/2026, 04:17:36 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses