Skip to content

attestd — Cybersecurity

from $19.99/mo (free plan available)

attestd (Cybersecurity): attestd is a Software Risk API delivering deterministic security signals for CI/CD and AI agents. Pricing: from $19.99/mo (free plan available). (data verified August 2026)

Transparency: if you buy through our links we may earn a commission, at no extra cost to you. Rankings cannot be bought. How we rate tools

About attestd

What is attestd?

attestd is a Software Risk API that gives your CI/CD pipelines and AI agents three deterministic, branch-ready security signals in a single call: risk_state (NVD-derived vulnerability risk), supply_chain.compromised (malicious publish status), and typosquat (package name integrity, including AI-hallucinated names). No code or repository access is required—just an API key.

What problem does it solve?

AI agents and automated infrastructure make software decisions at machine speed—deploying services, patching systems, exposing endpoints. They often invent package names, and traditional scanners miss that failure mode. Public sources like NVD and CVE give you raw data but not a unified, deterministic condition your system can branch on. attestd simplifies this into actionable signals your code can act on.

Who is it for?

attestd is built for developers and engineering teams integrating security checks into CI/CD pipelines, local agents, or AI coding tools like Claude Code, Cursor, and Windsurf. It's ideal for those needing fast, reliable security context without complexity. It is not designed for end-users seeking a manual vulnerability scanner.

Real use cases

  • Block deployment if a package has a critical vulnerability or is actively exploited.
  • Prevent AI agents from installing typosquatted or hallucinated package names.
  • Automate security checks in CI/CD workflows with a simple API call.

Key features

  • risk_state — Get a deterministic vulnerability risk classification (critical, high, elevated, low, none) from NVD data.
  • supply_chain.compromised — Detect malicious package publish status independent of CVE history.
  • typosquat detection — Identify classic misspellings and AI-hallucinated package names with confidence scores.
  • One-call API — Single request returns all three signals, simple to integrate.
  • Branch-ready output — Signals are designed for deterministic branching in automation.
  • No code/repo access — Works with just an API key, no repository scanning setup.
  • Broad coverage — Monitors 356 CVE-covered products and 27,459 PyPI + 237,601 npm packages.

SaaSpartout Score

7.5 /10
Ease of use 8.5
Features depth 7.5
Value for money 7.0
Support quality 6.5
Integrations 7.0
Scalability 8.0
Documentation 7.5
Onboarding speed 8.0

Editorial score from our review methodology — not user ratings.

◆ AI advisor — 30 seconds, no signup
Why are you looking at Data & Api Tools tools today?

Prefer the full AI advisor? Open it here →

attestd Pricing

attestd pricing: from $19.99/mo (free plan available). Billing model: Freemium.

For comparison: the median starting price in Cybersecurity is $9.99/month, measured across 116 tools we track. See the full SaaS Pricing Index →

Free — $0/month

1,000 API calls/month, 60 calls/minute, full response schema, Python SDK, community support, direct use only.

Solo — $19.99/month

Up to 10,000 calls/month, no per-minute limit, no overage billing, email support, direct use only.

Team — $99.99/month

Up to 100,000 calls/month, supply chain compromise webhooks, scoped API keys, priority support, direct use only.

Platform — Custom

Unlimited calls under contract, embed or resell in your product, custom terms, invoicing, SLA by arrangement.

All tiers include package name integrity and full response schema. Free trial available—no credit card required.

Find the right tool for you with our AI advisor →

Frequently asked questions

How much does attestd cost?
attestd offers a free plan (1,000 calls/month) and paid plans starting at $19.99/month for Solo (up to 10,000 calls) and $99.99/month for Team (up to 100,000 calls). Platform pricing is custom.
Is there a free trial?
Yes, attestd has a free plan that includes 1,000 API calls per month, forever. You can sign up at api.attestd.io with no credit card required.
What is attestd used for?
attestd provides three security signals (risk_state, supply_chain.compromised, typosquat) to help CI/CD pipelines and AI agents make safe software decisions—like blocking vulnerable packages or detecting hallucinated package names.
Who is attestd best for?
It's ideal for developers and engineering teams integrating security checks into automation—especially those working with AI coding tools like Claude Code, Cursor, and Windsurf.
What are top attestd alternatives?
Alternatives include Snyk, Sonatype, and Socket for vulnerability scanning, but attestd's differentiator is its deterministic, branch-ready signals and typosquat detection specifically designed for AI agents.
What is the main limitation of attestd?
The biggest limitation is that it only covers a specific set of products and packages (356 CVE-covered products and 27,459 PyPI + 237,601 npm packages), so it may not cover every package in your stack.

Don’t take our word for it — ask your AI about attestd

Gemini ChatGPT Claude Perplexity Grok
Get the shortlist + exclusive deals
We'll email you these picks and the occasional hand-picked SaaS deal. No spam.