Presend for teams
Dependency checks for npm and PyPI whose false-positive rate is measured and published. Nothing is for sale yet: we are testing whether teams want this before building it. This page is a waitlist.
What the checks do today
These checks already exist and are free through the API and the MCP server (per-minute rate limits apply). Last measured on 1 October 2026: full results, method and blind spots; the code and test sets are public.
- Typosquats (npm and PyPI). On the top 15,000 PyPI packages, 11 are flagged, each one reviewed and left flagged deliberately. On about 17,000 high-impact npm packages, 1 is flagged. All 27 known typosquats in our test set are detected.
- New publisher after a dormant period (npm only). The pattern behind the event-stream attack. Evaluated on the 200 most depended-upon npm packages at 9 dates over two years: 1 package flagged. It cannot see a hijacked account that keeps the same publisher name.
- Known vulnerabilities of the exact version you use, from OSV.dev, rather than of the package as a whole.
What they do not do
There is no behavioural analysis of package code and no malware detection. Use these checks alongside a malware scanner such as Socket or Aikido, not instead of one.
What teams would get (planned, not built)
- A check on every pull request that adds or changes a dependency (GitHub).
- The same check for AI coding agents before they install a package (MCP).
- API keys with higher limits than the free tier.
- The measurements re-run and published with every release of the checks.
The price we are testing
$29 per month per organisation, flat, whatever the number of developers. What is free today stays free.