OWASP Dependency-Check

Also known as
owasp-dependency-check

What is OWASP Dependency-Check?

A tool that scans software dependencies to identify publicly known vulnerabilities by cross-referencing them with vulnerability databases. It generates reports that link discovered issues to relevant security advisories.

Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Self-hosted

Security & compliance

Known vulnerabilities: 2 (0 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality

OWASP Dependency-Check alternatives

Other dependency management we track, ranked by the same independent score.

All OWASP Dependency-Check alternatives, ranked →

Compare OWASP Dependency-Check

Side by side against other dependency management, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for OWASP Dependency-Check, not the verdict.

Balanced composite 58 / 100
low · 10%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Development activity550.095.2
Release cadence840.054.4
Dependent projects350.062.2
Stars730.031.9
Price level00.050.0-
Reliability00.070.0-
Capabilities00.080.0-
Integrations00.090.0-
Security posture00.070.0-
Package downloads00.140.0-
Security score00.040.0-
Pricing transparency00.080.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d55mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars7,672highsource · 2026-08-26 · 90%
Dependent repos121highsource · 2026-08-26 · 85%

Language

AttributeValueEvidence
PrimaryJavahighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Pricing

AttributeValueEvidence
Modelcommerciallowsource · 2026-08-26 · 48%

Release

AttributeValueEvidence
Cadence days28mediumsource · 2026-08-26 · 70%
History20 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
VulnerabilitiesCount: 2 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.owasp%3Adependency-check-maven&per_page=100 · Last 12m: 0 · Max severity: HIGHhighsource · 2026-08-26 · 90%