✍️Writing & Content31🎨Image Generation36🎬Video & Animation72🎵Audio & Music58💬Chatbots & Assistants49💻Coding & Development236📈Marketing & SEO78Productivity192🎯Design & UI/UX63📊Data & Analytics59📚Education & Research29💼Business & Finance71🏥Healthcare & Wellness18🔍Search & Knowledge16🤖AI Agent Infrastructure100🛡️AI Security & Testing12🧊3D & Spatial21🔎SEO Tools26🏡Real Estate4🗃️Data Extraction24🧠ADHD & Focus Tools9
💡

Complete Your AI Tool Stack

attestd users also rely on these tools to enhance their workflow:

💰 Affiliate disclosure: We may earn a commission if you sign up through these links at no extra cost to you.

Part of 1362+ curated AI tools on AISO
attestd logo

attestd

One API call returns three independent software-risk signals — CVE risk state, supply-chain compromise, and package-name integrity including AI-hallucinated names.

freemiumFree forever at 1,000 API calls/month and 60 calls/minute. Solo is $19.99/month for up to 10,000 calls with no per-minute limit and no overage billing. Team is $99.99/month for up to 100,000 calls and adds supply-chain compromise webhooks and scoped API keys. Platform is a custom contract for commercial embedding or resale. The full response schema including cve_ids is available on every tier — the company states there is no field gating.View full pricing →

Visit attestd

https://www.attestd.io

About attestd

attestd is a software-risk API designed to be called by CI/CD pipelines and by AI coding agents, which is a narrower and more interesting brief than a general vulnerability scanner. One request against a package name and version returns three signals that the company insists are independent by design: risk_state, an NVD-derived vulnerability classification with values from none through critical; supply_chain.compromised, a malicious-publish flag that is deliberately not derived from CVE history, so a package can return no known vulnerabilities and still be flagged as compromised; and typosquat, a package-name integrity check that catches both classic typosquats and names an LLM invented that never existed. That third signal is the one built specifically for the agent era — a coding agent that hallucinates a dependency name will happily install whatever squatter registered it, and a scanner that only scores known-good packages misses the failure mode entirely. The design principle stated throughout is determinism: NVD, CISA KEV and OSV all publish machine-readable data, but none of them yield a single condition a pipeline can branch on without interpretation, so attestd does the normalisation and returns something a script can act on. No repository or code access is required, there is a Python SDK, and the free tier is genuinely usable for evaluation and personal automation.

Key Features

risk_state: NVD-derived vulnerability classification (none → critical)
supply_chain.compromised: malicious-publish flag independent of CVE history
typosquat: package-name integrity including AI-hallucinated package names
No code or repository access required
Python SDK and a documented curl quickstart
Free tier at 1,000 calls/month with the full response schema

Tags

securityapici-cdsupply-chaindeveloper-tools
🏷️

Is this your tool?

Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.

Claim Now →

ChatGPT already recommends attestd. Does it recommend yours?

If you're building in security, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

📬 Get the best new AI tools delivered weekly

One concise email with fresh launches, trending picks, and featured standouts.

Agent connectivity: not yet verified