MIT-licensed ยท free forever for individuals

Your AI just suggested
a package that doesn't exist.

Attackers register the exact names AI coding assistants hallucinate, betting you'll install them anyway. wary checks before you do.

$ wary check requsts --ecosystem pypi ๐Ÿ’€ requsts [pypi] โ€” nonexistent โ†’ does not exist on pypi. If an AI assistant suggested this, it's a hallucinated name โ€” do not install it. 1 packages checked โ€” 0 ok, 0 suspicious, 0 likely squats, 1 nonexistent RESULT: FAIL

This isn't hypothetical

2026 alone has seen a steady drumbeat of real supply-chain compromises built on exactly this failure mode:

March 2026 โ€” Axios (100M+ weekly downloads) hijacked via maintainer account takeover, attributed to a North Korea-linked actor
March 2026 โ€” LiteLLM PyPI package poisoned in the same attack wave
May 2026 โ€” 14 typosquatted OpenSearch/DevOps npm packages harvest AWS and CI/CD credentials
June 2026 โ€” 32 packages compromised in the @redhat-cloud-services npm namespace

Built for the gap Socket.dev leaves open

Socket is excellent โ€” and its paid tier has a 5-developer minimum ($125/month floor). If you're a 2-3 person team, you're stuck on the free tier with no path to the features you'd want.

No seat minimum

$15/month flat, up to 5 developers. Not $25/seat with a 5-seat floor.

Built for AI coding

The specific check for the moment your AI assistant suggests something new.

Diff-only CI checks

Only flags what's new in each PR โ€” quiet otherwise, loud when it matters.

Pricing

FreeTeamOrg
Checks/month200UnlimitedUnlimited
DevelopersUnlimitedUp to 5Unlimited
Slack alertsโ€”โ€”โœ“
Price$0$15/mo$49/mo