Vekt - Supply Chain Security

See vulnerabilities, maintainers, and trust data on npm, PyPI, crates.io, and 6 more registries.

As of June 2026, Vekt - Supply Chain Security has 1 users in the Developer Tools category.

Usersno change0%
1
1
Ratingno change0%
— reviews
Reviewsno change0%
Version
0.1.0
Manifest V3

History

6 snapshots

Tracking since Apr 3, 2026.

2.081.50.9199999999999999Apr 3, 2026Jun 11, 2026
View as table
DateUsersRatingReviewsVersion
Apr 3, 20260.1.0
Apr 17, 20260.1.0
Apr 23, 202610.1.0
Apr 27, 20260.1.0
May 5, 202610.1.0
Jun 11, 202620.1.0
Now10.1.0

Permissions & access

Permissions
storageactiveTab
Host access
https://api.osv.dev/*, https://api.deps.dev/*

Screenshots

Vekt - Supply Chain Security screenshot 1Vekt - Supply Chain Security screenshot 2Vekt - Supply Chain Security screenshot 3

About

Vekt shows you what package registries don't -- vulnerability data, maintainer history, and trust signals -- right on the page where you're evaluating a package.

WHAT IT DOES

When you visit a package page on any supported registry, Vekt adds a trust bar at the bottom of the screen showing:

  - Traffic light indicator (green/yellow/red) for instant risk assessment
  - Package name, version, and ecosystem
  - Click "Details" to expand the full trust panel

The trust panel shows:

  - OpenSSF Scorecard score
  - Vulnerability count from OSV.dev (CVEs, GHSAs, MAL-* malicious flags)
  - Weekly download count
  - Maintainer list with GitHub profile links and star counts
  - Dependency count
  - License information
  - Package publish date and version history
  - Provenance/SLSA attestation status
  - Warnings for abandoned packages, single maintainers, and large dependency trees

SUPPORTED REGISTRIES (9)

  - npm (npmjs.com)
  - PyPI (pypi.org)
  - And More!

PRIVACY

Vekt only sends the package ecosystem, name, and version to check for vulnerabilities. It never transmits your browsing history, page content, cookies, or any other data. Works in incognito without storing state. Full privacy policy: https://kief.dev/privacy

DATA SOURCES

  - OSV.dev (Google) for vulnerabilities and malicious package advisories
  - deps.dev (Google) for dependency graphs and OpenSSF Scorecard scores
  - Registry APIs (npm, PyPI, crates.io, RubyGems) for metadata and maintainers
  - GitHub API for maintainer profiles and star counts

FREE TO USE

The extension works without an account. Optional API key (free at kief.dev/vekt/signup) enables trust scoring and enriched data.

Built by Kief Studio (kief.studio). Source and documentation at kief.dev/vekt.

Category: Developer Tools

Language: English

Website: https://kief.dev/vekt

Privacy Policy URL: https://kief.dev/privacy

Technical

Version
0.1.0
Manifest
V3
Size
36.19KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
fkhdbbbhignkhicjadpjpapkepcmpdjb
Developer ID
u64ddf2ddb8f8df745734e8b2ed01fe82
Developer Email
[email protected]
Created
Apr 2, 2026
Last Updated (Store)
Apr 2, 2026
Last Scraped
Jun 11, 2026
Website
kief.dev

Data sourced from the Chrome Web Store · last verified Jun 11, 2026.