One sentence. One fix.
Paste a package name, get a plain-English verdict and a copy-paste fix command. No log diving, no CVE databases, no graph theory.
Paste a package name. Meridian walks your dependency graph six hops deep and tells you which services are exposed, in plain English, in seconds.
Paste a package name, get a plain-English verdict and a copy-paste fix command. No log diving, no CVE databases, no graph theory.
Six deterministic queries walk your actual dependency tree — transitive exposure, lockfile snapshots, typosquat neighbours. Answers in seconds.
Apache-2.0 source on GitHub. Run it on your laptop behind your firewall. No seat counts, no cloud dependency, no tracking.
Type any npm or PyPI package name. e.g. tanstack/react-virtual or ua-parser-js.
Six tiles light up: exposed services, compromised lockfiles, typosquat neighbours, and more.
One shell command at the top of the page. Paste it into your terminal. Done.
Graph-native dependency traversal. Not vector search — real Cypher over your actual dependency tree.
Read every query in src/lib/cypher.ts. Fork it, self-host it, audit it. No black boxes.
No package names sent, no analytics, no cookies. Your dependency graph stays on your machine.
Known compromises you can scan right now. Each one lights up the six tiles and produces a verdict in under 300ms.
Any npm or PyPI package. The engine walks the full transitive dependency tree — not just direct imports.
No. The hosted version at meridian.sithunyein.com works in your browser. For air-gapped environments, run it locally with Docker.
No telemetry, no analytics, no package names logged. The engine is Apache-2.0 — you can read the source.
npm audit checks direct advisories. Meridian walks the full transitive graph — 6 hops deep — to find services that are exposed but don't appear in any audit output.
Paste a package name above, or try a pre-built scan of a known compromise.