x402 census · relay402.georgespring.workers.dev · ad0b26eb1d77 · JSON
GET /api/package-vulns
live
Known-vulnerability check for a software dependency before installing it: queries the OSV.dev database (Google Open Source Vulnerabilities) for npm, PyPI, Go, Maven, crates.io, RubyGems, NuGet or Packagist packages. Returns advisories with CVE aliases, severity, summary, fixed versions and reference links. Optional version narrows results to vulnerabilities affecting that exact version. Built for…
Verdict: live. The unpaid GET reached a valid 402 (confirmed by the re-probe of 2026-10-03).
Facts from the catalogs
| Field | Value |
|---|---|
| URL | https://relay402.georgespring.workers.dev/api/package-vulns |
| Method | GET |
| Price | $0.01 USDC = 10000 atomic units of 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 |
| Network | eip155:8453 (base) |
| payTo | 0x73fc43d426a89577c7b58f5fee50ec95d4396079 |
| Seller | relay402.georgespring.workers.dev |
| Catalogs | payai (row updated 2026-09-30) |
| Listed since (lower bound) | 2026-09-30 (earliest catalog timestamp; catalogs report last-update times only) |
| Last catalog update | 2026-09-30 |
| CDP quality counters | not in the CDP catalog |
| Category (keyword rule) | research/reports |
| Templated path | no |
| x402Version in catalog | 2 |
| Service name / tags | Package vulnerability check · security, dependencies, supply-chain, dev, vulnerabilities |
Unpaid probe (census of )
| Field | Value |
|---|---|
| Probe | not probed in this build |
Latest re-probe
| Field | Value |
|---|---|
| Re-probed at | 2026-10-03T04:13:27.000Z (cron) |
| Verdict now | live changed from unprobed |
| HEAD / GET | 402 / 402 |
| accepts[0] | {"scheme":"exact","network":"eip155:8453","amount":"10000","payTo":"0x73fc43d426a89577c7b58f5fee50ec95d4396079","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","maxTimeoutSeconds":120,"extra":{"name":"USD Coin","version":"2"}} |
| Live amount equals catalog price | yes |
| Latency | 1,304 ms |
| Error | none |
On-chain facts for the payTo (public address)
| Field | Value |
|---|---|
| Distinct payers | 2 |
| Payments | 50 |
| USDC volume | $1.74 |
| Median payment | n/a |
| First / last payment | 2026-09-13 / 2026-09-30 |
| Sampler-shaped share of payments | n/a |
| Payers that are not samplers | n/a |
| Source | blockscout-sample — newest page of inbound ERC-20 transfers only (<=50); counts are a floor, not a total |
| Address | 0x73fc43d426a89577c7b58f5fee50ec95d4396079 |
Declared input and output (extensions.bazaar)
{
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"name": "lodash",
"version": "4.17.15",
"ecosystem": "npm"
}
}
}
Try it (unpaid: shows the 402)
curl -si -X GET 'https://relay402.georgespring.workers.dev/api/package-vulns' -H 'accept: application/json'
The catalog declares GET. A 402 answer carries the payment requirements in the JSON body and, for x402 v2, base64 in the PAYMENT-REQUIRED header. This page never sends a payment.
Paid checks (x402, USDC on Base)
GET https://bazaar.agentexchange.work/r/ad0b26eb1d77/probe.json re-runs this probe right now for $0.01 and writes the result here. POST https://bazaar.agentexchange.work/featured with {"id":"ad0b26eb1d77"} places this resource at the top of the report and search pages for 30 days for $1.00, labelled. Unpaid requests answer 402 with the terms. Pricing.
Catalog references: PayAI listing status · this record as JSON · all resources on relay402.georgespring.workers.dev.