Matchboxmatchbox

package-doctor

Scans Python dependencies for exploited CVEs and abandoned packages

Desktopfreeglobal

package-doctor scans Python dependencies for exploited CVEs and abandoned packages handling untrusted input, prioritizing risk by CISA's Known Exploited Vulnerabilities catalog and EPSS exploit-probability scores, running in CI or as a Claude Code hook. It's built for developers who want dependency security prioritized by real-world exploitation data instead of an undifferentiated list of every known CVE.

Categories
securitysupply-chain

Full match profile

Behind the summary, Matchbox keeps a richer profile of package-doctor - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Something wrong with this listing — dead link, not a real product, wrong info?

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether package-doctor (or something else) actually fits.