Socket
Supply chain security that detects malicious behaviour in dependencies, not just known CVEs.
why this verdict
Keep paying — Anthropic has not replaced it
Anthropic's version overlaps, but does not finish the security job, so this one still earns its $8/mo.
- A named launch, not a vibe named, unlinked
- GitHub Dependabot and native package registry scanning covering basic dependency risk free. Anthropic, July 29, 2025 — no announcement link recorded yet.
- How much of the job it covers not the job editorial call
- Parts of it. The job still needs the tool to get finished.
- Is there a free way to do it? yes
- 2 of 3 listed replacements have a usable free tier: Snyk and Dependabot.
- What the call is worth $96/yr
- $8/mo at the entry paid tier — $96 a year per seat.
- Threatened by
- Anthropic
- Since
- July 29, 2025
- List price
- $8/mo
- Per year
- $96
The backstory
Socket looks at what a package actually does, install scripts, network calls, filesystem access, rather than only checking it against a database of disclosed vulnerabilities, which is the only way to catch a dependency that turned malicious yesterday. That distinction became urgent as AI coding agents install packages autonomously, sometimes hallucinating names that attackers have helpfully registered. Free scanners catch known issues; behavioural analysis of new ones is a different and harder product.
Escape hatches
Broader application security with a large ecosystem
snyk.io open_in_newFree known-vulnerability alerts inside GitHub
github.com open_in_newHardened minimal container images
chainguard.dev open_in_new2 of 3 replacements have a usable free tier.