Detect and block software supply chain attacks

Continuously evaluate open source packages for malicious code and risky behaviors, and block malware before it enters your codebase.
Loved by security teams, painless for developers at:

How it works

Evaluate dependency health
Easily review the security and health of any open source package using 150+ factors.
Detect malicious dependencies
Go beyond CVEs by scanning the actual code of dependencies for malware or risky behavior.
Block malware at the source
Prevent malicious code and dependencies from entering your codebase.
Endor Labs catches malicious dependencies before we even hear about a CVE. Their security research team goes beyond automated detection to help us verify the threat so we can act early and decisively.”
Aman Sirohi
SVP - Chief Security Officer & Platform, People.ai
Evaluate
Research and compare millions of packages
Endor Labs evaluates every open source package and AI model for 150+ signals of supply chain risk. Quickly research any package using our database of more than 4.5 million open source dependencies.
Security risks: Identify known vulnerabilities, malicious code, risky security practices, and more.
License compliance: Identify license policy violations, unidentified licenses, license conflicts, and more.
Project activity: Identify unmaintained libraries, libraries with single maintainers, rarely used libraries, and more.Code quality: Identify libraries that may not follow best practices, like pinning dependencies, which can increase supply chain risk.
Code quality: Identify libraries that may not follow best practices, like pinning dependencies, which can increase supply chain risk.
Detect
Detect supply chain attacks early
Endor Labs scans the actual code of your open source dependencies to protect against zero day supply chain attacks.
Block known malware: Endor Labs blocks known malicious packages from entering your codebase.
Identify suspicious behavior: Endor Labs scans each package for suspicious code and flags risks such as typosquatting and dependency confusion.
Expert verification: The Endor Labs security research team reviews and verifies suspected findings, escalating and notifying you when malware is detected.
Enforce
Block malware before it enters your codebase
Endor Labs lets you create and enforce policies aligned with your risk tolerance—whether that’s breaking builds with suspected malware or granting an exception for a library with a single maintainer.
Flexible policies: Policies can be tuned by severity, ecosystem, or project for granular control.
Enforce controls: Decide when—and how—you enforce policies, whether warning developers or breaking builds.
Get notified instantly: Decide when and where to receive critical alerts so you can stay on top of emerging risks.
Flowchart showing integration paths from GitHub, GitLab, and PHP to Slack and Microsoft platforms, with a C# icon connected to Slack.

Your Tools, Your Languages
All Secured

Lean how Endor Labs fits into your ecosystem.
Flow diagram connecting software development tools and platforms including .NET, JetBrains, GitHub, Google, and Vercel.

FAQs

What is the Developer Edition?

Developer Edition is a free tier that gives individual developers access to the AURI MCP Server and CLI. It includes SAST, SCA, secrets detection, and malicious open source package detection — the core scanning capabilities you need to write secure code from day one.

What does the MCP Server actually do?

The MCP Server connects AURI's security intelligence to your AI coding assistant. When you or your AI writes code, the server scans for vulnerabilities, insecure patterns, hardcoded secrets, and risky dependencies in real time — then helps fix them inline, right where you're working.

Which editors and tools are supported?

The MCP server works with Cursor, VS Code, Windsurf, Claude Code, and any MCP-compatible client. It also integrates with asynchronous AI tools like GitHub Copilot and OpenAI Codex for agent-driven workflows.

Is Developer Edition really free?

Yes. Developer Edition requires no credit card and no paid subscription. You authenticate once via GitHub, GitLab, or Google and you're up and running. There's no trial period — it's free to use, forever.

What kinds of scans does it run?

Developer Edition includes four core scan types: static application security testing (SAST) for code-level issues, software composition analysis (SCA) for dependency vulnerabilities, secrets detection for exposed credentials, and malicious package detection to catch supply chain attacks before they reach your environment.

Does my code leave my machine?

No. All scans run locally. The MCP Server accesses AURI's vulnerability database for intelligence (read-only), but your source code stays on your machine and is never uploaded to Endor Labs' platform.

How is this different from other free security MCP servers?

Most free MCP servers focus on code scanning alone. The AURI Developer Edition is the only free offering that combines code scanning (SAST and secrets) with full supply chain security — including CVE detection and malicious open source package identification in your dependencies.

Do I need to install anything besides the MCP Server?

No. The MCP Server fetches everything it needs on demand, including the Endor Labs CLI. There's no separate installation step, no pre-configuration, and no dependency management required to get started.

Can I use Developer Edition with my team?

Developer Edition is designed for individual developers. If your team needs shared policies, centralized reporting, or platform-level visibility, Endor Labs offers team and enterprise tiers that build on the same scanning engine with collaboration and governance features.

What's the difference between Developer Edition and the full Endor Labs platform?

Developer Edition gives you the core scanning tools — MCP Server and CLI — with default security policies and local-only results. The full platform adds a web UI, custom policies, centralized reporting, team management, and integrations with SIEM and vulnerability management tools for organization-wide security programs.