A continuously updated database of CVEs enriched with reachability and exploitability context, not just CVSS scores. Know which vulnerabilities actually matter in your codebase.
Evaluate open source packages and AI models for security, license, and operational risks.
How secure is AI-generated code? We benchmark popular coding agents across 200 real-world tasks and 77 CWE classes — independently, with no vendor involvement.
In-depth research reports from the Endor Labs team. Original data and analysis on the state of open source security, AI code risk, and dependency management.
Explore interactive research on software supply chain attack patterns, threat relationships, and real-world exploit paths.
A practical framework highlighting the most critical open source software security risks and dependency management challenges.