✍️Writing & Content58🎨Image Generation71🎬Video & Animation120🎵Audio & Music100💬Chatbots & Assistants109💻Coding & Development444📈Marketing & SEO197Productivity401🎯Design & UI/UX120📊Data & Analytics126📚Education & Research55💼Business & Finance174🏥Healthcare & Wellness22🔍Search & Knowledge20🤖AI Agent Infrastructure208🛡️AI Security & Testing32🧊3D & Spatial22🔎SEO Tools113🏡Real Estate7🗃️Data Extraction104🧠ADHD & Focus Tools11🔬Research & Academia45🧩LLM APIs & Models34⚙️Automation & Workflows45🔐Security & Privacy31📊Analytics & BI55⚖️Legal & Contracts14
Listed in Security & Privacy with 33 other toolsPart of 3473+ curated AI tools on AISO
attestd logo

attestd

One API call returns three independent software-risk signals — CVE risk state, supply-chain compromise, and package-name integrity including AI-hallucinated names.

freemiumDR 2Free forever at 1,000 API calls/month and 60 calls/minute. Solo is $19.99/month for up to 10,000 calls with no per-minute limit and no overage billing. Team is $99.99/month for up to 100,000 calls and adds supply-chain compromise webhooks and scoped API keys. Platform is a custom contract for commercial embedding or resale. The full response schema including cve_ids is available on every tier — the company states there is no field gating.View full pricing →

About attestd

attestd is a software-risk API designed to be called by CI/CD pipelines and by AI coding agents, which is a narrower and more interesting brief than a general vulnerability scanner. One request against a package name and version returns three signals that the company insists are independent by design: risk_state, an NVD-derived vulnerability classification with values from none through critical; supply_chain.compromised, a malicious-publish flag that is deliberately not derived from CVE history, so a package can return no known vulnerabilities and still be flagged as compromised; and typosquat, a package-name integrity check that catches both classic typosquats and names an LLM invented that never existed. That third signal is the one built specifically for the agent era — a coding agent that hallucinates a dependency name will happily install whatever squatter registered it, and a scanner that only scores known-good packages misses the failure mode entirely. The design principle stated throughout is determinism: NVD, CISA KEV and OSV all publish machine-readable data, but none of them yield a single condition a pipeline can branch on without interpretation, so attestd does the normalisation and returns something a script can act on. No repository or code access is required, there is a Python SDK, and the free tier is genuinely usable for evaluation and personal automation.

Does ChatGPT recommend your AI tool?

If you're building in Security & Privacy, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Key Features

risk_state: NVD-derived vulnerability classification (none → critical)
supply_chain.compromised: malicious-publish flag independent of CVE history
typosquat: package-name integrity including AI-hallucinated package names
No code or repository access required
Python SDK and a documented curl quickstart
Free tier at 1,000 calls/month with the full response schema

Tags

securityapici-cdsupply-chaindeveloper-tools
🏷️

Is attestd your tool?

This is the page buyers and AI assistants read when they look up attestd. Claim your listing for $19 one-time — no subscription, nothing to cancel — and get a Featured badge, top placement in your category, and a permanent dofollow backlink. Prefer it ongoing? Monthly is one click away on the next page.

Stay updated on Security & Privacy tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Alternatives to attestd

View all attestd alternatives →

More Security & Privacy tools

Agent connectivity: not yet verified