Measured false-positive rates

A dependency check that flags popular, legitimate packages gets ignored. So we measure how often ours do, on the most-used packages, and publish the result, the method and the blind spots. Last run: 1 October 2026.

Want these checks on every pull request and for your AI coding agents? Presend for teams is a waitlist while we test demand.

Typosquat check (npm and PyPI)

The popular-package lists move. On 1 October, four packages that had recently entered the top 15,000 PyPI (djongo, tmol, orgparse, webp) were flagged; we checked each repository and added them to the reviewed list the same day.

Blind spot: only names close to a list of popular targets are checked. A name that an AI model invents and that resembles no real package (slopsquatting) is not caught by name similarity.

Publisher-change check (npm only)

Blind spots: it cannot see a hijacked account that keeps the same publisher name (as with ua-parser-js) or a malicious release by the original maintainer (as with colors.js). An attacker who has already taken over a popular package would pass the established-publisher rule. When the npm search API rate-limits us, the publisher check is reported as unavailable and the event stays flagged.

Vulnerability check

Not a heuristic: it reports the OSV.dev advisories for the exact version you give. Without a version it reports advisories across all versions, which overstates the risk, so give the version you use.

Reproduce it

The code and test sets are in the public presend-source repository (Node.js, no dependencies):

node tests/typosquat/run.mjs                 # offline test set
node tests/typosquat/top-pypi.mjs            # top 15,000 PyPI (network)
node tests/typosquat/top-npm.mjs             # npm-high-impact (network)
node tests/maintainer-change/top-npm.mjs 200 # about 3 minutes (network)

Each script fails if a popular package is flagged without having been reviewed.

Contributions to other tools

Want the same measurement for your tool?

If you maintain a dependency-security tool and want its false-positive and detection rates measured the same way, write to presendapp@gmail.com.