See your 24-hour exposure before the clock starts

Paste a dependency manifest. You'll see your scope verdict, how many dependencies are on the known-exploited list or abandoned, and exactly what you'd have to file — with no email and nothing stored. Filing to ENISA is manual; there is no API (CRA Article 14 (opens the primary source in a new tab)).

…or give a public repo URL instead

Your dependency file is processed in memory and never stored. No email required to see your result.