What it covers
- What you ship: the exact packages and versions in production, not what the manifest suggests.
- What it pulls in: the dependencies of your dependencies, which are most of the tree.
- What is unmaintained: packages with no recent releases or an abandoned maintainer, which stop receiving security fixes.
- Known vulnerabilities: which of those versions have published advisories, and whether the vulnerable code is actually reachable.
Why it matters
A compromised or abandoned package reaches every application that installs it, which makes the dependency tree a shared attack surface. An app can be carefully written and still exposed through something it imported.
What comes out of it
Ranked findings: what to upgrade now, what to replace, what to pin and watch. It is one part of an application security review, alongside access, secrets, deployments and tested backups — see what a first security review covers.